Latest Cybersecurity News and Articles


CSC 2.0 Report: Space Systems Should Be Designated Critical Infrastructure

19 April 2023
Most of today’s space systems were developed under the premise that space was a sanctuary from conflict, but according to the CSC 2.0 commission, this is no longer the case.

Twenty-six percent of IT workers saw a decrease in morale

19 April 2023
With hybrid and remote work, security leaders are tracking employee productivity. New research analyzed the effect that monitoring had on employees.

Blind Eagle Cyber Espionage Group Strikes Again: New Attack Chain Uncovered

19 April 2023
The cyber espionage actor tracked as Blind Eagle has been linked to a new multi-stage attack chain that leads to the deployment of the NjRAT remote access trojan on compromised systems.

Dasera Scores $12M Funding for Cloud Data Security

19 April 2023
The Silicon Valley startup has banked $12 million in venture capital funding to drive innovation in the data security and governance space. The Series A funding round was led by Storm Ventures and brings the total raised by Dasera to $20 million.

Action1 RMM Abused by Threat Actors for Ransomware Attacks

19 April 2023
A rising trend has been identified among cybercriminals; they are using Action1 remote access software for reconnaissance activity and to run code with system privileges on network hosts. In fact, it was observed in at least three ransomware attacks by threat actor groups.

Ukraine Facing Phishing Attacks, Information Operations

19 April 2023
The Russian government continues to use an array of phishing attacks and information operations, including hack-and-leak efforts, to support its invasion of Ukraine, researchers reported.

Google TAG Warns of Russian Hackers Conducting Phishing Attacks in Ukraine

19 April 2023
Elite hackers associated with Russia's military intelligence service have been linked to large-volume phishing campaigns aimed at hundreds of users in Ukraine to extract intelligence and influence public discourse related to the war. Google's Threat Analysis Group (TAG), which is monitoring the activities of the actor under the name FROZENLAKE, said the attacks continue the "group's 2022 focus

Oracle Releases 433 New Security Patches With April 2023 CPU

19 April 2023
Oracle on Tuesday announced the release of 433 new patches as part of its quarterly set of security updates, including more than 70 fixes for critical-severity vulnerabilities.

Blind Eagle Cyber Espionage Group Strikes Again: New Attack Chain Uncovered

19 April 2023
The cyber espionage actor tracked as Blind Eagle has been linked to a new multi-stage attack chain that leads to the deployment of the NjRAT remote access trojan on compromised systems. "The group is known for using a variety of sophisticated attack techniques, including custom malware, social engineering tactics, and spear-phishing attacks," ThreatMon said in a Tuesday report. Blind Eagle, also

Misconfiguration leaves thousands of servers vulnerable to attack, researchers find

19 April 2023
Misconfigured web servers remain a “major problem” with thousands left exposed online waiting for hackers to gain access to valuable information that’s left up for grabs, according to a recent report from the security company Censys.

Goldoson Library Infects Popular Apps with Adware

19 April 2023
A recently detected Android malware named 'Goldoson' has made its way into Google Play and has been found in 60 legitimate applications, which have been downloaded a total of 100 million times. Users are suggested to always perform due diligence, especially for new apps without good reviews.

Google Patches Second Chrome Zero-Day Vulnerability of 2023

19 April 2023
Tracked as CVE-2023-2136, the security defect is described as a high-severity integer overflow issue in Skia. The bug was reported by Google Threat Analysis Group researcher Clement Lecigne and, as per Google's policy, no monetary reward was issued.

Akamai to Buy Startup Neosec for API Detection and Response

19 April 2023
The Boston-area vendor said its proposed acquisition of Silicon Valley-based Neosec will make it easier for customers to secure their APIs, by helping them discover all their APIs, assess their risk and respond to vulnerabilities and attacks.

Google Chrome Hit by Second Zero-Day Attack - Urgent Patch Update Released

19 April 2023
Google on Tuesday rolled out emergency fixes to address another actively exploited high-severity zero-day flaw in its Chrome web browser. The flaw, tracked as CVE-2023-2136, is described as a case of integer overflow in Skia, an open source 2D graphics library. Clément Lecigne of Google's Threat Analysis Group (TAG) has been credited with discovering and reporting the flaw on April 12, 2023. "

Pakistani Hackers Use Linux Malware Poseidon to Target Indian Government Agencies

19 April 2023
The Pakistan-based advanced persistent threat (APT) actor known as Transparent Tribe used a two-factor authentication (2FA) tool used by Indian government agencies as a ruse to deliver a new Linux backdoor called Poseidon.

Coro Raises $75 Million for Mid-Market Cybersecurity Platform

19 April 2023
With the new funding round, the Israel-based company adds Energy Impact Partners to its list of investors, which also includes Balderton Capital, JVP, and Sound Ventures.

PLAY Ransomware Strengthens Capabilities With New Tools, Researchers Say

19 April 2023
Custom tools also allow for more control over operations, and a decreased likelihood that a group’s particular tooling will be either reverse-engineered or adapted by other groups, the researchers noted.

Luz Mabel del Valle hired as Chief Risk Officer at FV Bank

19 April 2023
Luz Mabel del Valle has been appointed to Chief Risk Officer (CRO) at FV Bank. De Valle has also been appointed Deputy Chief Compliance Officer.

Triple-digit Increase in API and App Attacks on Tech and Retail

19 April 2023
Last year was a record-breaker in terms of API and application-based attacks on the EMEA retail sector, with detected threats surging 189%, according to a report by Akamai.

DoNot APT Hackers Attack Individuals Using Android Malware via Chatting Apps

19 April 2023
Interestingly, the malware samples were disguised as chat apps named Ten Messenger.apk and Link Chat QQ.apk This threat actor has carried out cyberattacks in the South Asian region since 2016 when it was first found to be active.