Latest Cybersecurity News and Articles


‘Invalid Printer’ Loader Spreads Aurora Stealer

24 April 2023
Morphisec found a campaign using a highly evasive loader, named in2al5d p3in4er, disseminating the Aurora info-stealer via links in YouTube video descriptions. It is compiled using Embarcadero RAD Studio which allows attackers to create executables for multiple platforms, with multiple configuration options.

Federal office probes GMH network breach

24 April 2023
The “unauthorized access” that prompted the Guam Memorial Hospital to shut down its network in March is now being investigated by the U.S. Department of Health and Human Services, according to an acceptance letter addressed to a whistleblower.

The staying power of shadow IT, and how to combat risks related to it

24 April 2023
Organizations today are very aware that shadow IT exists in their “backyard”, and that the more unknown apps and uncontrolled access they have, the bigger their attack surface is.

Multifunctional and Sophisticated DevOpt Backdoor Discovered

24 April 2023
A new backdoor, named DevOpt, was discovered that uses hard-coded names for persistence and provides various features such as keylogging, stealing browser credentials, and clipper. Multifunctional malware such as DevOpt are increasingly becoming common. Organizations must make continuous improvements in their defense approaches, and implement multi-layered defense architecture.

Trojanized Installers Used to Distribute Bumblebee Malware

24 April 2023
Secureworks analyzed the findings in a report published on Thursday, saying the infection chain for several of these attacks relied on a malicious Google Ad that sent users to a fake download page via a compromised WordPress site.

MIT and Stanford researchers develop operating system with the promise of resisting ransomware

24 April 2023
The system is structured around databases that save and track all events and changes occurring within the OS. That should mean recovering from ransomware simply means rolling back a machine to the previously safe state within minutes.

New Credential-Stealer Zaraza Bot Targets 38 Browsers

24 April 2023
Uptycs found a new credential stealer, named Zaraza bot, being advertised on Telegram and simultaneously using the messaging service as C2 server. It can target 38 web browsers. Zaraza bot is a lightweight malware with just a 64-bit binary file. Some codes and logs are written in Russian. As a precaution, users should be wary of the links received over social media and downloading anything from unknown sources.

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers

24 April 2023
Print management software provider PaperCut said that it has "evidence to suggest that unpatched servers are being exploited in the wild," citing two vulnerability reports from cybersecurity company Trend Micro.

Semgrep Raises $53M in Series C Funding

24 April 2023
The round, which brought the total amount to $93M, was led by Lightspeed Venture Partners with participation from previous investors Felicis Ventures, Redpoint Ventures, and Sequoia Capital.

APT41 Uses Open-source Red Teaming Tool - GC2

24 April 2023
Chinese nation-state group APT41 targeted an unnamed Taiwanese media firm to deploy Google Command and Control (GC2), an open-source red teaming tool - revealed Google’s TAG. To initiate the attack, the attackers sent phishing emails with links to password-protected files hosted on Google Drive. 

GitHub now allows enabling private vulnerability reporting at scale

24 April 2023
During the public beta, the option to report private vulnerabilities could be activated by maintainers and repository owners only on single repositories. Starting this week, they can now enable this for all repositories within their organization.

Medtronic latest to reveal health data disclosure via pixel tracking tools

24 April 2023
Medtronic MiniMed has joined the long list of healthcare entities to report unintentional disclosures to third parties without authorization due to the use of tracking or pixel technology.

New All-in-One "EvilExtractor" Stealer for Windows Systems Surfaces on the Dark Web

24 April 2023
A new "all-in-one" stealer malware named EvilExtractor (also spelled Evil Extractor) is being marketed for sale for other threat actors to steal data and files from Windows systems. "It includes several modules that all work via an FTP service," Fortinet FortiGuard Labs researcher Cara Lin said. "It also contains environment checking and Anti-VM functions. Its primary purpose seems to be to

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers

24 April 2023
Print management software provider PaperCut said that it has "evidence to suggest that unpatched servers are being exploited in the wild," citing two vulnerability reports from cybersecurity company Trend Micro. "PaperCut has conducted analysis on all customer reports, and the earliest signature of suspicious activity on a customer server potentially linked to this vulnerability is 14th April 01

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

22 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws in MinIO, PaperCut, and Google Chrome, respectively, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

22 April 2023
"The attackers also deployed DaemonSets to take over and hijack resources of the K8s clusters they attack," cloud security firm Aqua said in a report shared with The Hacker News.

Cyware to Power Accenture’s Next-Generation Threat Intelligence Services

22 April 2023
While the Cyware team is thrilled with this significant opportunity, it also represents another step forward in its mission to enable Collective Defense across a wide range of communities.

CFPB says employee sent confidential data of 256,000 consumers to personal email

22 April 2023
An employee at the Consumer Financial Protection Bureau sent confidential data about hundreds of thousands of consumer accounts to their personal email, the agency told CNN on Thursday.

Lazarus X_TRADER Hack Impacts Critical Infrastructure Beyond 3CX Breach

22 April 2023
Lazarus, the prolific North Korean hacking group behind the cascading supply chain attack targeting 3CX, also breached two critical infrastructure organizations in the power and energy sector and two other businesses involved in financial trading using the trojanized X_TRADER application. The new findings, which come courtesy of Symantec's Threat Hunter Team, confirm earlier suspicions that the

Google: Ukraine targeted by 60% of Russian phishing attacks in 2023

22 April 2023
In most cases, the campaign goals include intelligence collection, operational disruptions, and leaking sensitive data through Telegram channels dedicated to causing information damage to Ukraine.