Latest Cybersecurity News and Articles


UK school hit by ransomware attack

28 April 2023
A school in Wiltshire was hit by a ransomware attack last weekend. Hardenhuish School, a mixed secondary academy in Chippenham, sent texts to parents and guardians of its 1,623 pupils notifying them of the attack.

South Carolina's Spartanburg County Suffers Ransomware Attack

28 April 2023
A ransomware attack has been reported in Spartanburg County. WYFF News 4 reached out to Spartanburg County officials and the South Carolina Judicial Branch after hearing about a possible computer issue.

New DHS task force will use AI to mitigate threats

28 April 2023
The DHS announced an artificial intelligence task force designed to use the technology to address emerging threats to national security.

Critical Vulnerability in Zyxel Firewalls Leads to Command Execution

28 April 2023
Taiwanese network equipment manufacturer Zyxel this week announced patches for a critical-severity vulnerability impacting its ATP, USG FLEX, VPN, and ZyWALL/USG firewalls.

DHS pushes Congress to formally establish Cyber Safety Review Board

28 April 2023
A senior Department of Homeland Security official confirmed Wednesday that DHS is working with Congress and the White House on a bill that would codify the Cyber Safety Review Board (CSRB) — a new effort to examine major cybersecurity incidents.

Magecart Attacks Conducted via Sleek, Modern Looking Fake Payment Screens

28 April 2023
The latest iteration, as observed by Malwarebytes on a Parisian travel accessory store running on the PrestaShop CMS, involved the injection of a skimmer called Kritec to intercept the checkout process and display a fake payment dialog to victims.

Ukrainian man arrested for selling data on 300 million people to Russians

28 April 2023
A 36-year-old Ukrainian citizen was arrested this week for allegedly selling the personal data of over 300 million people to Russia, the Ukrainian cyber police said in a statement.

Alloy Taurus APT Spotted Using PingPull and a New Backdoor to Target Linux Users

28 April 2023
Unit 42 discovered a new version of the PingPull malware, designed by Alloy Taurus (aka Gallium), to cripple Linux systems. It is essentially an ELF file that only 3 out of 62 antivirus vendors flagged as malicious. During the investigation, the threat actor's infrastructure also blurted out the evidence of another backdoor used in the attack known as Sword2033.

Report: Ransomware attacks see resurgence in 2023

28 April 2023
A report released this week reveals manufacturing as the top targeted industry for ransomware attacks.

New Atomic macOS Malware Steals Keychain Passwords and Crypto Wallets

28 April 2023
Threat actors are advertising a new information stealer for the Apple macOS operating system called Atomic macOS Stealer (or AMOS) on Telegram for $1,000 per month, joining the likes of MacStealer. "The Atomic macOS Stealer can steal various types of information from the victim's machine, including Keychain passwords, complete system information, files from the desktop and documents folder, and

NSA cyber director warns of ransomware attacks on Ukraine, Western supply chains

28 April 2023
Russian hackers are attempting to inject ransomware into Ukraine's logistics supply chain and those of the Western countries that back Kyiv in its fight against Moscow, a senior National Security Agency official said on Wednesday.

Why Your Detection-First Security Approach Isn't Working

28 April 2023
Stopping new and evasive threats is one of the greatest challenges in cybersecurity. This is among the biggest reasons why attacks increased dramatically in the past year yet again, despite the estimated $172 billion spent on global cybersecurity in 2022. Armed with cloud-based tools and backed by sophisticated affiliate networks, threat actors can develop new and evasive malware more quickly

Zyxel Firewall Devices Vulnerable to Remote Code Execution Attacks — Patch Now

28 April 2023
Networking equipment maker Zyxel has released patches for a critical security flaw in its firewall devices that could be exploited to achieve remote code execution on affected systems. The issue, tracked as CVE-2023-28771, is rated 9.8 on the CVSS scoring system. Researchers from TRAPA Security have been credited with reporting the flaw. "Improper error message handling in some firewall versions

Hackers Steal Emails, Private Messages From Two Hookup Websites

28 April 2023
Hackers have stolen email addresses, direct messages, and other personal data from users of two dating websites, according to Troy Hunt, the founder and maintainer of Have I Been Pwned.

ViperSoftX InfoStealer Adopts Sophisticated Techniques to Avoid Detection

28 April 2023
A significant number of victims in the consumer and enterprise sectors located across Australia, Japan, the U.S., and India have been affected by an evasive information-stealing malware called ViperSoftX. ViperSoftX was first documented in 2020, with cybersecurity company Avast detailing a campaign in November 2022 that leveraged the malware to distribute a malicious Google Chrome extension

The double-edged sword of generative AI

28 April 2023
While there have been many laudable applications of these technologies in healthcare, education, and even art, it’s essential to understand the broader way in which these technologies could be used and the potential risks they pose.

Google banned 173K developer accounts to block malware, fraud rings

28 April 2023
The company revealed in its "bad apps" yearly report that it also prevented almost 1.5 million apps linked to various policy violations from reaching the Google Play Store.

FIN7 Exploits Vulnerabilities in Veeam Backup Software

28 April 2023
A Veeam Backup process was seen carrying out a shell command to download and implement a PowerShell script abusing the Veeam Backup & Replication vulnerability, CVE-2023-27532. Further analysis revealed that the script was in fact the Powertrash in-memory dropper, a tool that has been previously used by FIN7. Consequently, the group deployed Diceloader, a backdoor also referred to as Lizar.

Password reset woes could cost FTSE 100 companies $156 million each month

28 April 2023
According to a study by MyCena Security Solutions, there is an opportunity for businesses to learn how to eradicate password resets from their processes to improve both their security and bottom line.

Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean Institutions

28 April 2023
South Korean education, construction, diplomatic, and political institutions are at the receiving end of new attacks perpetrated by a China-aligned threat actor known as the Tonto Team.