Latest Cybersecurity News and Articles


Organizations are stepping up their game against cyber threats

25 April 2023
Global median dwell time drops to just over two weeks, reflecting the essential role partnerships and the exchange of information play in building a more resilient cybersecurity ecosystem, according to Mandiant.

TP-Link Archer WiFi router flaw exploited by Mirai malware

25 April 2023
The Mirai malware botnet is actively exploiting a TP-Link Archer A21 (AX1800) WiFi router vulnerability tracked as CVE-2023-1389 to incorporate devices into DDoS (distributed denial of service) swarms.

The U.S., U.K. and Germany rank top in ransomware attacks

25 April 2023
Cyberattacks have increased over the past few years. Ransomware attacks from April 2022 to March 2023 were analyzed in a recent report by Black Kite.

Adult content malvertising scheme leads to clickjacking

25 April 2023
Visitors are lured to several fake blogs about topics they might find interesting. The original blog, however, is hidden by an overlay showing blurred explicit content and a button asking the visitor to confirm they are 18+ to enter the website.

VirusTotal now has an AI-powered malware analysis feature

25 April 2023
VirusTotal Code Insight analyzes potentially harmful files to explain their (malicious) behavior, and it will improve the ability to identify which of them pose actual threats.

Peugeot Leaks Access to User Information, Application Secrets in South America

25 April 2023
Peugeot has leaked access to its user data in Peru. On February 3rd, the Cybernews research team discovered an exposed environment file (.env) hosted on the official Peugeot store for Peru.

AI tools help attackers develop sophisticated phishing campaigns

25 April 2023
Phishing scams are a growing threat, and cybercriminals’ methods are becoming increasingly sophisticated, making them harder to detect and block, according to a Zscaler report.

50 percent of organizations fell victim to ransomware in 2022

25 April 2023
New research revealed a large disconnect between an organizations’ level of preparedness and their ability to stop a ransomware attack.

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

25 April 2023
Details have emerged about a high-severity security vulnerability impacting Service Location Protocol (SLP) that could be weaponized to launch volumetric denial-of-service attacks against targets. "Attackers exploiting this vulnerability could leverage vulnerable instances to launch massive Denial-of-Service (DoS) amplification attacks with a factor as high as 2200 times, potentially making it

Iranian Hackers Launch Sophisticated Attacks Targeting Israel with Powerless Backdoor

25 April 2023
An Iranian nation-state threat actor has been linked to a new wave of phishing attacks targeting Israel that's designed to deploy an updated version of a backdoor called PowerLess. Cybersecurity firm Check Point is tracking the activity cluster under its mythical creature handle Educated Manticore, which exhibits "strong overlaps" with a hacking crew known as APT35, Charming Kitten, Cobalt

Scammers Impersonate Meta in Credential Harvesting Campaign With 3200 Fake Profiles

25 April 2023
According to experts, the ultimate goal of this campaign is to gain access to the Facebook accounts of public figures, celebrities, businesses, and sports teams, among others, to steal sensitive information and use it to access additional accounts.

To combat cybercrime, US law enforcement increasingly prioritizes disruption

25 April 2023
Rather than carrying out traditional investigations aimed at building cases, arresting suspects, convicting them, and sending them to jail, U.S. law enforcement is increasingly focused on disrupting online crime.

55% say cyber/IT assessment is as hard as renewing driver’s license

25 April 2023
Of the biggest challenges faced when implementing an effective cyber/IT risk management program, 49% of respondents say an increase in the quantity of cyber threats.

EvilExtractor: An Educational Tool or Info-stealer?

25 April 2023
FortiGuard Labs laid bare EvilExtractor - an attack tool developed to target Windows systems and extract data and files from devices. While its creator firm claimed that it is an educational tool, research revealed that it was being actively used as an info-stealer. Typically, it masquerades as an authentic file, such as a Dropbox file or an Adobe PDF document, but upon execution, it initiates malicious actions using PowerShell.

Intel CPUs Vulnerable to New Transient Execution Side-Channel Attack

25 April 2023
The new attack was discovered by researchers at Tsinghua University, the University of Maryland, and a computer lab (BUPT) run by the Chinese Ministry of Education and is different than most other side-channel attacks.

Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

25 April 2023
Search giant Google on Monday unveiled a major update to its 12-year-old Authenticator app for Android and iOS with an account synchronization option that allows users to back up their time-based one-time passwords (TOTPs) codes to the cloud.

Modernizing Vulnerability Management: The Move Toward Exposure Management

25 April 2023
Managing vulnerabilities in the constantly evolving technological landscape is a difficult task. Although vulnerabilities emerge regularly, not all vulnerabilities present the same level of risk. Traditional metrics such as CVSS score or the number of vulnerabilities are insufficient for effective vulnerability management as they lack business context, prioritization, and understanding of

US Navy Contractor Fincantieri Marine Group Hit by Cyberattack

25 April 2023
“Fincantieri Marine Group experienced a cybersecurity incident last week that is causing a temporary disruption to certain computer systems on its network,” reads the statement.

Lazarus Subgroup Targeting Apple Devices with New RustBucket macOS Malware

25 April 2023
A financially-motivated North Korean threat actor is suspected to be behind a new Apple macOS malware strain called RustBucket. "[RustBucket] communicates with command and control (C2) servers to download and execute various payloads," Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said in a technical report published last week.  The Apple device management company attributed it

The double-edged sword of open-source software

25 April 2023
The lack of visibility into the software supply chain creates an unsustainable cycle of discovering vulnerabilities and weaknesses in software and IT systems, overwhelming organizations, according to Lineaje.