Latest Cybersecurity News and Articles


Court Records Expose Private Information for Thousands of Missouri Residents

01 May 2023
Documents containing Social Security numbers and other private information for thousands of Missourians are accessible to anyone using the Casenet website, the state’s judicial records system, the Post-Dispatch recently discovered.

Sensitive Data Leaked From Servers Running Salesforce Community Software

01 May 2023
Servers running software sold by Salesforce are leaking sensitive data managed by government agencies, banks, and other organizations, according to a post published Friday by KrebsOnSecurity.

Using multiple solutions adds complexity to your zero trust strategy

01 May 2023
Companies are also now increasingly reliant on their supply chain, which means partners, suppliers, and shippers are now typically directly connected to a company’s systems.

Update: Hackers leak images to taunt Western Digital's cyberattack response

01 May 2023
The ALPHV ransomware crew, aka BlackCat, has published screenshots of internal emails and video conferences stolen from Western Digital, indicating they likely had continued access to the company's systems even as the company responded to the breach.

Cybercriminals use proxies to legitimize fraudulent requests

01 May 2023
Bot attacks were previously seen as a relatively inconsequential type of online fraud, and that mentality has persisted even as threat actors have gained the ability to cause significant damage to revenue and brand reputation, according to HUMAN.

Report shows nearly 600% annual growth in vulnerable cloud attack surface

01 May 2023
A new report reveals security organizations experienced 133% year-over-year growth in cyber assets, resulting in increased security complexity for cloud enterprises.

‘BouldSpy’ Android Malware Used in Iranian Government Surveillance Operations

01 May 2023
On the infected devices, BouldSpy harvests account usernames and associated application/service, a list of installed apps, browser data, call logs, clipboard content, contact lists, device information, a list of files and folders, and SMS messages.

New Decoy Dog Malware Toolkit Uncovered: Targeting Enterprise Networks

01 May 2023
An analysis of over 70 billion DNS records has led to the discovery of a new sophisticated malware toolkit dubbed Decoy Dog targeting enterprise networks. Decoy Dog, as the name implies, is evasive and employs techniques like strategic domain aging and DNS query dribbling, wherein a series of queries are transmitted to the command-and-control (C2) domains so as to not arouse any suspicion. "

Companies Increasingly Hit With Data Breach Lawsuits: Law Firm

01 May 2023
Lawsuits filed against companies that have suffered a data breach are increasingly common, with action being taken more frequently even in cases where the number of impacted individuals is smaller, according to US law firm BakerHostetler.

Russia-linked APT28 Uses Fake Windows Update Instructions to Target Ukrainian Government Bodies

01 May 2023
CERT-UA observed the campaign in April 2023, the malicious e-mails with the subject “Windows Update” were crafted to appear as sent by system administrators of departments of multiple government bodies.

United HealthCare Reports Data Breach That May Have Revealed Customer's Personal Information

01 May 2023
United HealthCare made customers aware of a data breach on Friday, which temporarily allowed access to personal information for those enrolled in the company's healthcare plans.

South Korea, US agree to cooperate on cybersecurity and combating North Korean digital heists

01 May 2023
North Korea has long relied on its government-backed hacking groups to fund its weapons programs, launching audacious attacks on cryptocurrency exchanges and medical facilities.

Wanted Dead or Alive: Real-Time Protection Against Lateral Movement

01 May 2023
Just a few short years ago, lateral movement was a tactic confined to top APT cybercrime organizations and nation-state operators. Today, however, it has become a commoditized tool, well within the skillset of any ransomware threat actor. This makes real-time detection and prevention of lateral movement a necessity to organizations of all sizes and across all industries. But the disturbing truth

Are Qualcomm chips snooping on you? No, not quite

01 May 2023
Recently, security firm Nitrokey published an advisory claiming that "smartphones with Qualcomm chips secretly send personal data to Qualcomm" and do so "without user consent, unencrypted, and even when using a Google-free Android distribution."

Some 'Sensitive Information' Potentially Compromised: Diocese of Las Vegas Reports Cybersecurity Breach

01 May 2023
In response to the breach, the Diocese states it has "reviewed and enhanced its data security policies...in order to help reduce the likelihood of a similar event in the future."

First draft of controversial UN Cybercrime Treaty slated for June

01 May 2023
The UN General Assembly voted in December 2019 to begin negotiating a treaty centered around cybercrime after Russia took issue with a previous agreement – the Budapest Convention – and demanded something new to address the issue.

Amnesty International Australia slow with disclosure after December hack

01 May 2023
In a statement posted to its website on Friday, five days after queries from this masthead, Amnesty said it had detected the attack on December 3, 2022. The charity said it subsequently secured its IT systems and started an investigation.

Vietnamese Threat Actor Infects 500,000 Devices Using 'Malverposting' Tactics

01 May 2023
A Vietnamese threat actor has been attributed as behind a "malverposting" campaign on social media platforms to infect over 500,000 devices worldwide over the past three months to deliver variants of information stealers such as S1deload Stealer and SYS01stealer. Malverposting refers to the use of promoted social media posts on services like Facebook and Twitter to mass propagate malicious

China’s hackers outnumber FBI cyber staff ‘at least 50 to 1,’ Wray tells Congress

01 May 2023
For fiscal 2024, the FBI wants to add 192 positions for fighting cyber threats, “including 31 Special Agents, 8 Intelligence Analysts, and 153 Professional Staff,” according to a summary from the bureau.

APT28 Targets Ukrainian Government Entities with Fake "Windows Update" Emails

01 May 2023
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of cyber attacks perpetrated by Russian nation-state hackers targeting various government bodies in the country. The agency attributed the phishing campaign to APT28, which is also known by the names Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, Sednit, and Sofacy. The email messages come with the subject line "