Latest Cybersecurity News and Articles
28 April 2023
A school in Wiltshire was hit by a ransomware attack last weekend. Hardenhuish School, a mixed secondary academy in Chippenham, sent texts to parents and guardians of its 1,623 pupils notifying them of the attack.
28 April 2023
A ransomware attack has been reported in Spartanburg County. WYFF News 4 reached out to Spartanburg County officials and the South Carolina Judicial Branch after hearing about a possible computer issue.
28 April 2023
The DHS announced an artificial intelligence task force designed to use the technology to address emerging threats to national security.
28 April 2023
Taiwanese network equipment manufacturer Zyxel this week announced patches for a critical-severity vulnerability impacting its ATP, USG FLEX, VPN, and ZyWALL/USG firewalls.
28 April 2023
A senior Department of Homeland Security official confirmed Wednesday that DHS is working with Congress and the White House on a bill that would codify the Cyber Safety Review Board (CSRB) — a new effort to examine major cybersecurity incidents.
28 April 2023
The latest iteration, as observed by Malwarebytes on a Parisian travel accessory store running on the PrestaShop CMS, involved the injection of a skimmer called Kritec to intercept the checkout process and display a fake payment dialog to victims.
28 April 2023
A 36-year-old Ukrainian citizen was arrested this week for allegedly selling the personal data of over 300 million people to Russia, the Ukrainian cyber police said in a statement.
28 April 2023
Unit 42 discovered a new version of the PingPull malware, designed by Alloy Taurus (aka Gallium), to cripple Linux systems. It is essentially an ELF file that only 3 out of 62 antivirus vendors flagged as malicious. During the investigation, the threat actor's infrastructure also blurted out the evidence of another backdoor used in the attack known as Sword2033.
28 April 2023
A report released this week reveals manufacturing as the top targeted industry for ransomware attacks.
28 April 2023
Threat actors are advertising a new information stealer for the Apple macOS operating system called Atomic macOS Stealer (or AMOS) on Telegram for $1,000 per month, joining the likes of MacStealer.
"The Atomic macOS Stealer can steal various types of information from the victim's machine, including Keychain passwords, complete system information, files from the desktop and documents folder, and
28 April 2023
Russian hackers are attempting to inject ransomware into Ukraine's logistics supply chain and those of the Western countries that back Kyiv in its fight against Moscow, a senior National Security Agency official said on Wednesday.
28 April 2023
Stopping new and evasive threats is one of the greatest challenges in cybersecurity. This is among the biggest reasons why attacks increased dramatically in the past year yet again, despite the estimated $172 billion spent on global cybersecurity in 2022.
Armed with cloud-based tools and backed by sophisticated affiliate networks, threat actors can develop new and evasive malware more quickly
28 April 2023
Networking equipment maker Zyxel has released patches for a critical security flaw in its firewall devices that could be exploited to achieve remote code execution on affected systems.
The issue, tracked as CVE-2023-28771, is rated 9.8 on the CVSS scoring system. Researchers from TRAPA Security have been credited with reporting the flaw.
"Improper error message handling in some firewall versions
28 April 2023
Hackers have stolen email addresses, direct messages, and other personal data from users of two dating websites, according to Troy Hunt, the founder and maintainer of Have I Been Pwned.
28 April 2023
A significant number of victims in the consumer and enterprise sectors located across Australia, Japan, the U.S., and India have been affected by an evasive information-stealing malware called ViperSoftX.
ViperSoftX was first documented in 2020, with cybersecurity company Avast detailing a campaign in November 2022 that leveraged the malware to distribute a malicious Google Chrome extension
28 April 2023
While there have been many laudable applications of these technologies in healthcare, education, and even art, it’s essential to understand the broader way in which these technologies could be used and the potential risks they pose.
28 April 2023
The company revealed in its "bad apps" yearly report that it also prevented almost 1.5 million apps linked to various policy violations from reaching the Google Play Store.
28 April 2023
A Veeam Backup process was seen carrying out a shell command to download and implement a PowerShell script abusing the Veeam Backup & Replication vulnerability, CVE-2023-27532. Further analysis revealed that the script was in fact the Powertrash in-memory dropper, a tool that has been previously used by FIN7. Consequently, the group deployed Diceloader, a backdoor also referred to as Lizar.
28 April 2023
According to a study by MyCena Security Solutions, there is an opportunity for businesses to learn how to eradicate password resets from their processes to improve both their security and bottom line.
28 April 2023
South Korean education, construction, diplomatic, and political institutions are at the receiving end of new attacks perpetrated by a China-aligned threat actor known as the Tonto Team.