Latest Cybersecurity News and Articles


Linux Malware Strengthens Links Between Lazarus APT and the 3CX Supply Chain Attack

21 April 2023
Researchers were able to reconstruct the full chain, from the ZIP file that delivers a fake HSBC job offer as a decoy, up until the final payload: the SimplexTea Linux backdoor distributed through an OpenDrive cloud storage account.

Tight budgets and burnout push enterprises to outsource cybersecurity

21 April 2023
With cybersecurity teams struggling to manage the remediation process and monitor for vulnerabilities, organizations are at a higher risk for security breaches, according to Cobalt.

GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

21 April 2023
Cybersecurity researchers have disclosed details of a now-patched zero-day flaw in Google Cloud Platform (GCP) that could have enabled threat actors to conceal an unremovable, malicious application inside a victim's Google account. Israeli cybersecurity startup Astrix Security, which discovered and reported the issue to Google on June 19, 2022, dubbed the shortcoming GhostToken. The issue

14 Kubernetes and Cloud Security Challenges and How to Solve Them

21 April 2023
Recently, Andrew Martin, founder and CEO of ControlPlane, released a report entitled Cloud Native and Kubernetes Security Predictions 2023. These predictions underscore the rapidly evolving landscape of Kubernetes and cloud security, emphasizing the need for organizations to stay informed and adopt comprehensive security solutions to protect their digital assets. In response, Uptycs, the first

Small Business Interest in Cyber-Hygiene Wanes

21 April 2023
Security breaches and cyberattacks remain a significant threat for UK businesses, but many smaller firms appear to be prioritizing matters other than cybersecurity, the British government has warned.

New 'EvilExtractor' Tool Targets Windows Systems via Modules Controlled Through FTP Service

21 April 2023
EvilExtractor (sometimes spelled Evil Extractor) is an attack tool designed to target Windows operating systems and extract data and files from endpoint devices. It includes several modules that all work via an FTP service.

5 free online cybersecurity resources for small businesses

21 April 2023
As cyberattacks increase in frequency and sophistication, SMBs become more vulnerable to cyber threats. Fortunately, several free online cybersecurity resources can help small businesses protect themselves from cyberattacks.

Nurse Call Systems, Infusion Pumps Riskiest Connected Medical Devices

21 April 2023
Nurse call systems and infusion pumps have been found to be the riskiest connected medical devices, suggests a new report by asset visibility and cybersecurity company Armis.

Update: Capita confirms hackers stole data in recent cyberattack

21 April 2023
London-based professional outsourcing giant Capita has published an update on the cyber-incident that impacted it at the start of the month, now admitting that hackers exfiltrated data from its systems.

N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

21 April 2023
The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophistication with North Korean threat actors. Google-owned Mandiant, which is tracking the attack event under the moniker UNC4736, said the incident marks the first time it has seen a "software supply chain attack lead to another software

Cisco Patches Critical Vulnerabilities in Industrial Network Director, Modeling Labs

21 April 2023
On Wednesday, Cisco released fixes for a critical-severity flaw in the web interface of IND that could be exploited remotely to execute commands on the underlying operating system.

APT43: An investigation into the North Korean group’s cybercrime operations

21 April 2023
Microsoft Word documents (docx) are the most common file format among the samples we analyzed. This suggests that APT43 relies heavily on Microsoft Word documents as a vector for delivering malicious payloads or exploiting vulnerabilities.

Phishing Links via Linktree

21 April 2023
In this attack, end-users get an email with a spoofed Microsoft OneDrive or Sharepoint notification that a file has been shared with them, instructing them to open the file.

Two Critical Flaws Found in Alibaba Cloud's PostgreSQL Databases

21 April 2023
A chain of two critical flaws has been disclosed in Alibaba Cloud's ApsaraDB RDS for PostgreSQL and AnalyticDB for PostgreSQL that could be exploited to breach tenant isolation protections and access sensitive data belonging to other customers.

Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products

21 April 2023
Cisco and VMware have released security updates to address critical security flaws in their products that could be exploited by malicious actors to execute arbitrary code on affected systems. The most severe of the vulnerabilities is a command injection flaw in Cisco Industrial Network Director (CVE-2023-20036, CVSS score: 9.9), which resides in the web UI component and arises as a result of

3CX Breach Was a Double Supply Chain Compromise

20 April 2023
We learned some remarkable new details this week about the recent supply-chain attack on VoIP software provider 3CX, a complex, lengthy intrusion that has the makings of a cyberpunk spy novel: North Korean hackers using legions of fake executive accounts on LinkedIn to lure people into opening malware disguised as a job offer; malware targeting Mac and Linux users working at defense and cryptocurrency firms; and software supply-chain attacks nested within earlier supply chain attacks.

Phishing Scams Abusing Microsoft Teams and More

20 April 2023
Cybercriminals have become increasingly adept at designing new phishing tactics. Lately, a scam was found camouflaging as the legitimate Microsoft Teams login with the goal of tricking users into entering their login credentials.

APT28 Uses Vulnerability in Cisco Routers to Deploy Malware

20 April 2023
Government agencies in the U.S. and the U.K. issued a joint advisory to warn organizations about attacks exploiting an old vulnerability in Cisco routers. The attacks are attributed to the Fancy Bear threat group and the flaw in question is CVE-2017-6742. The attackers are exploiting the vulnerability to deploy a custom malware, named Jaguar Tooth.

LockBit Eyes macOS; Test Version of macOS Encryptor Revealed

20 April 2023
MalwareHunterTeam discovered a ZIP archive—belonging to the LockBit ransomware group—uploaded to VirusTotal containing previously unknown encryptors for macOS, ARM, FreeBSD, MIPS, and SPARC. Security analysts from BleepingComputer assert that the discovered builds could have been created for testing purposes.

Tax-Themed Phishing Attacks Proliferate During Tax Filing Season

20 April 2023
With the tax reason around, the frequency of campaigns related to taxes and accounting has increased with threats like Remcos RAT, Emotet, and GuLoader hovering to scam users. The IRS issued an advisory, urging taxpayers to be wary and vigilant of new tax-related scams.