Latest Cybersecurity News and Articles


Western Digital Confirms Customer Data Stolen by Hackers in March Breach

08 May 2023
Digital storage giant Western Digital confirmed that an "unauthorized third party" gained access to its systems and stole personal information belonging to the company's online store customers. "This information included customer names, billing and shipping addresses, email addresses and telephone numbers," the San Jose-based company said in a disclosure last week. "In addition, the database

New Akira Ransomware Operation Targeting the Enterprise

08 May 2023
Launched in March 2023, Akira claims to have already conducted attacks on sixteen companies. These companies are in various industries, including education, finance, real estate, manufacturing, and consulting.

Join Our Webinar: Learn How to Defeat Ransomware with Identity-Focused Protection

08 May 2023
Are you concerned about ransomware attacks? You're not alone. In recent years, these attacks have become increasingly common and can cause significant damage to organizations of all sizes. But there's good news - with the right security measures in place, such as real-time MFA and service account protection, you can effectively protect yourself against these types of attacks. That's why we're

SideCopy Using Action RAT and AllaKore RAT to infiltrate Indian Organizations

08 May 2023
The suspected Pakistan-aligned threat actor known as SideCopy has been observed leveraging themes related to the Indian military research organization as part of an ongoing phishing campaign. This involves using a ZIP archive lure pertaining to India's Defence Research and Development Organization (DRDO) to deliver a malicious payload capable of harvesting sensitive information, Fortinet

Franklin Jackson named new CIO at CyberCatch Holdings, Inc

08 May 2023
This week, CyberCatch Holdings, Inc. announced Franklin Jackson will serve as the company's Vice President, CIO and Head of Global Security Advisory Services.

Australia: Sydney-based cancer center is the latest victim of a cyberattack

08 May 2023
It seems hardly a day goes by without another report of a cybercrime incident. With Medibank still fresh in our minds, the latest attack is on a Sydney-based cancer treatment facility, Crown Princess Mary Cancer Centre in Westmead Hospital.

Twitter Admits to ‘Security Incident’ Involving Circles Tweets

08 May 2023
A privacy breach at Twitter published tweets that were never supposed to be seen by anyone but the poster’s closest friends to the site at large, the company has admitted after weeks of stonewalling reports.

Review your on-prem ADCS infrastructure before attackers do it for you

08 May 2023
Attacks through Active Directory Certificate Services are fairly easy for bad actors to perform but basic vigilance and built-in Windows protections can help mitigate the risk of a breach.

CERT-UA Warns of an Ongoing SmokeLoader Malware Campaign

08 May 2023
SmokeLoader acts as a loader for other malware, once it is executed it will inject malicious code into the currently running explorer process (explorer.exe) and downloads another payload to the system.

How to Set Up a Threat Hunting and Threat Intelligence Program

08 May 2023
Threat hunting is an essential component of your cybersecurity strategy. Whether you're getting started or in an advanced state, this article will help you ramp up your threat intelligence program. What is Threat Hunting? The cybersecurity industry is shifting from a reactive to a proactive approach. Instead of waiting for cybersecurity alerts and then addressing them, security organizations are

New Cactus Ransomware Encrypts Itself to Evade Antivirus

08 May 2023
Researchers at Kroll corporate investigation and risk consulting firm believe that Cactus obtains initial access into the victim network by exploiting known vulnerabilities in Fortinet VPN appliances.

FluHorse: New Android Threat Stealing 2FA Codes and Passwords

08 May 2023
Check Point spotted a new malware strain, named FluHorse, masquerading as popular Android apps from East Asia. Each of these apps has been installed over 100,000 times. FluHorse is created to pilfer personal information such as usernames, passwords, and 2FA codes. Individuals and organizations must take proactive measures to safeguard against these threats. 

New PaperCut RCE exploit created that bypasses existing detections

08 May 2023
VulnCheck explains that Sysmon-based detections relying on process creation analysis are already beaten by existing PoCs that use alternate child process creation pathways.

Universal Data Permissions Scanner: Open-source tool to overcome data authorization blindspots

08 May 2023
Satori released the free, open-source tool that enables companies to understand which employees have access to what data, reducing the risks associated with overprivileged or unauthorized users and streamlining compliance reporting.

Your voice could be your biggest vulnerability

08 May 2023
McAfee surveyed 7,054 people from seven countries and found that a quarter of adults had previously experienced some kind of AI voice scam, with 1 in 10 targeted personally and 15% saying it happened to someone they know.

Update: San Bernardino County Sheriff’s Department paid a $1.1M ransom

08 May 2023
The ransomware attack forced the Police department to temporarily shut down some of its systems to prevent the threat from spreading. Impacted systems include email, in-car computers, and some law enforcement databases.

Ukrainian Forces Shutter Bot Farms and Illicit VPN Provider

08 May 2023
Ukrainian law enforcement agencies dismantled more than half a dozen bot farms and a virtual private network infrastructure spreading disinformation and fake Russian propaganda.

Update: Western Digital says hackers stole customer data in March cyberattack

08 May 2023
Western Digital has taken its store offline and sent customers data breach notifications after confirming that hackers stole sensitive personal information in a March cyberattack.

CERT-UA Warns of SmokeLoader and RoarBAT Malware Attacks Against Ukraine

08 May 2023
An ongoing phishing campaign with invoice-themed lures is being used to distribute the SmokeLoader malware in the form of a polyglot file, according to the Computer Emergency Response Team of Ukraine (CERT-UA). The emails, per the agency, are sent using compromised accounts and come with a ZIP archive that, in reality, is a polyglot file containing a decoy document and a JavaScript file. The

Kimsuky Enhances its BabyShark Recon Tool in a Global Campaign

06 May 2023
North Korean hacking group Kimsuky is distributing a new version of its reconnaissance malware called ReconShark. The cyberespionage campaign involves sending emails containing a link to a password-protected doc hosted on Microsoft OneDrive. The malware can steal sensitive data from the infected system, including running processes, connected batteries, and endpoint threat detection mechanisms.