Latest Cybersecurity News and Articles


Vulnerability Could Have Been Exploited for ‘Unlimited’ Free Credit on OpenAI Accounts

05 May 2023
A vulnerability in OpenAI’s account validation process allowed anyone to obtain virtually unlimited free credit for the company’s services by registering new accounts using the same phone number, application security firm Checkmarx says.

Ex-Uber CSO Joe Sullivan gets probation for breach cover-up

05 May 2023
Joe Sullivan won't serve any serious time behind bars for his role in covering up Uber's 2016 computer security breach and trying to pass off a ransom payment as a bug bounty.

New Android Malware 'FluHorse' Targeting East Asian Markets with Deceptive Tactics

05 May 2023
Various sectors in East Asian markets have been subjected to a new email phishing campaign that distributes a previously undocumented strain of Android malware called FluHorse that abuses the Flutter software development framework. "The malware features several malicious Android applications that mimic legitimate applications, most of which have more than 1,000,000 installs," Check Point said in

Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor

05 May 2023
The latest Android updates patch more than 40 security vulnerabilities in the Framework, System, Kernel, Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components.

Critical Siemens RTU Vulnerability Could Allow Hackers to Destabilize Power Grid

05 May 2023
The vulnerability, tracked as CVE-2023-28489, impacts the CPCI85 firmware of Sicam A8000 CP-8031 and CP-8050 products, and it can be exploited by an unauthenticated attacker for remote code execution.

Organizations urged to incorporate FCC covered list into risk management plans

05 May 2023
CISA has issued an alert to remind critical infrastructure owners to take steps in securing the nation’s critical supply chains.

ScarCruft Deploys RokRAT via LNK File

05 May 2023
ScarCruft, a North Korean threat group, has been attempting to deliver the RokRAT malware since July 2022 using oversized LNK files. The malware is capable of targeting macOS (CloudMensis) and Android (RambleOn). The malware variants are equipped to carry out a range of activities such as credential theft, data exfiltration, command and shellcode execution, file and directory management, and more.

Earth Longzhi Returns, Targets New Regions Using New Tactics

05 May 2023
After more than six months of no activity, Chinese state-sponsored threat group Earth Longzhi is back with new tricks up its sleeves in a new series of attacks. The attackers aim at IIS and Microsoft Exchange servers exposed to the internet to get access to the networks to install the Behinder web shell. Protection against such threats demands a proactive defense strategy.

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign

05 May 2023
SentinelLabs has observed ongoing attacks from Kimsuky, a North Korean state-sponsored APT that has a long history of targeting organizations across Asia, North America, and Europe.

Critical RCE vulnerability in Cisco phone adapters, no update available

05 May 2023
“This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware,” Cisco’s security advisory explains.

Hackers Targeting Italian Corporate Banking Clients with New Web-Inject Toolkit DrIBAN

05 May 2023
Italian corporate banking clients are the target of an ongoing financial fraud campaign that has been leveraging a new web-inject toolkit called drIBAN since at least 2019. "The main goal of drIBAN fraud operations is to infect Windows workstations inside corporate environments trying to alter legitimate banking transfers performed by the victims by changing the beneficiary and transferring

New Fleckpe Android Malware Installed 600,000 Times on Google Play Store

05 May 2023
Kaspersky reveals that Fleckpe is the newest addition to the realm of malware that generates unauthorized charges by subscribing users to premium services, joining the ranks of other malicious Android malware, such as Jocker and Harly.

Sourcepass Raises Additional $65M in Funding

05 May 2023
The company intends to use the funds to support its strategic objectives, including acquiring Proxios, which expands its physical presence in the mid-Atlantic states, while broadening its client base in the healthcare, legal, and non-profit sectors.

Discord leaks ‘demoralizing’ for US intelligence agencies, DNI Haines says

05 May 2023
The leaks of classified documents online by a Massachusetts Air National Guard member have had an emotional impact on the government agencies that produce those products, the director of national intelligence told Congress on Thursday.

N. Korean Kimsuky Hackers Using New Recon Tool ReconShark in Latest Cyberattacks

05 May 2023
The North Korean state-sponsored threat actor known as Kimsuky has been discovered using a new reconnaissance tool called ReconShark as part of an ongoing global campaign. "[ReconShark] is actively delivered to specifically targeted individuals through spear-phishing emails, OneDrive links leading to document downloads, and the execution of malicious macros," SentinelOne researchers Tom Hegel

Lack of Visibility: The Challenge of Protecting Websites from Third-Party Scripts

05 May 2023
Third-party apps such as Google Analytics, Meta Pixel, HotJar, and JQuery have become critical tools for businesses to optimize their website performance and services for a global audience. However, as their importance has grown, so has the threat of cyber incidents involving unmanaged third-party apps and open-source tools. Online businesses increasingly struggle to maintain complete visibility

Three-Quarters of Firms Predict Breach in Coming Year

05 May 2023
Most global organizations anticipate suffering a data breach or cyber-attack in the next 12 months, despite cyber-risk levels falling overall, according to a new report from Trend Micro.

Packagist Repository Hacked: Over a Dozen PHP Packages with 500 Million Compromised

05 May 2023
PHP software package repository Packagist revealed that an "attacker" gained access to four inactive accounts on the platform to hijack over a dozen packages with over 500 million installs to date. "The attacker forked each of the packages and replaced the package description in composer.json with their own message but did not otherwise make any malicious changes," Packagist's Nils Adermann said

Incident response at organizations can run from cool to chaotic

05 May 2023
According to a CyberRisk Alliance Business Intelligence survey, nearly three-quarters (73%) of respondents say their organization has an incident response playbook to guide decision-making during a cybersecurity incident.

Companies need a wakeup call to fix chronic security shortcomings, cyber experts say

05 May 2023
Digital risks confronting organizations remain the same year after year, and the threat and potential damage awaiting unsuspecting victims are abundantly clear. Yet, many organizations still struggle to address the fundamentals of cybersecurity.