Latest Cybersecurity News and Articles


Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose

17 April 2023
Israeli spyware vendor QuaDream is allegedly shutting down its operations in the coming days, less than a week after its hacking toolset was exposed by Citizen Lab and Microsoft. The development was reported by the Israeli business newspaper Calcalist, citing unnamed sources, adding the company "hasn't been fully active for a while" and that it "has been in a difficult situation for several

Qbot Banking Trojan Increasingly Delivered Via Business Emails

17 April 2023
Discovered by security researchers at Kaspersky, the malicious campaign relied on messages written in different languages, including English, German, Italian, and French.

Cenlar appoints Theodore Mugnier Director of Information Security

17 April 2023
Theodore Mugnier was hired as Director of Information Security for Cenlar FSB. Mugnier is a former Marine with two decades of intelligence experience.

New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware

17 April 2023
A new QBot malware campaign is leveraging hijacked business correspondence to trick unsuspecting victims into installing the malware, new findings from Kaspersky reveal. The latest activity, which commenced on April 4, 2023, has primarily targeted users in Germany, Argentina, Italy, Algeria, Spain, the U.S., Russia, France, the U.K., and Morocco. QBot (aka Qakbot or Pinkslipbot) is a banking

Vixen Panda APT Group suspected of targeting foreign ministry in cyberattack

17 April 2023
A Chinese hacker group, Vixen Panda, is suspected of targeting the Foreign Ministry in a recent cyberattack. As per a new report by Euractiv, the hackers showed a keen interest in policy documents.

German Arms Manufacturer Rheinmetall Targeted in Cyberattack

17 April 2023
Over the weekend, Rheinmetall, a leading German armaments and technology company, was the victim of a cyberattack that targeted all three of its divisions. However, company officials have stated that the attack did not impact operations.

FIN7 and Ex-Conti Cybercrime Gangs Join Forces in Domino Malware Attacks

17 April 2023
A new strain of malware developed by threat actors likely affiliated with the FIN7 cybercrime group has been put to use by the members of the now-defunct Conti ransomware gang, indicating collaboration between the two crews. The malware, dubbed Domino, is primarily designed to facilitate follow-on exploitation on compromised systems, including delivering a lesser-known information stealer that

NCR Says it was hit by BlackCat Ransomware Attack

17 April 2023
NCR is suffering an outage on its Aloha point of sale (PoS) platform since Wednesday after it was hit by a ransomware attack conducted by the BlackCat/ALPHV ransomware group.

What's the Difference Between CSPM & SSPM?

17 April 2023
Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) are frequently confused. The similarity of the acronyms notwithstanding, both security solutions focus on securing data in the cloud. In a world where the terms cloud and SaaS are used interchangeably, this confusion is understandable. This confusion, though, is dangerous to organizations that need to secure

US extradites Nigerian charged over $6m email fraud scam

17 April 2023
They used a technique dubbed Business Email Compromise (BEC). As part of this, it's claimed, the fraudsters broke into people's email accounts, too, and chatted via mobile apps to organize their crimes.

Hackers Start Abusing Action1 RMM in Ransomware Attacks

17 April 2023
Action1 is a remote monitoring and management (RMM) product that is commonly used by managed service providers (MSPs) and the enterprise to remotely manage endpoints on a network.

Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says

17 April 2023
This was found in the Targeting Scams report from the Australian Competition and Consumer Commission, which compiles data from Scamwatch, ReportCyber, major banks, and money remitters, based on an analysis of more than 500,000 reports.

Volvo's Brazil Retailer Exposed Sensitive Database Credentials, Laravel App Key, Git Repository Link

17 April 2023
On February 17, 2023, the Cybernews research team discovered public access to sensitive files hosted on dimasvolvo.com.br website, belonging to an independent Volvo retailer in the Santa Catarina region of Brazil.

What it will look like if China launches cyberattacks in the U.S.

17 April 2023
While much of the cybersecurity world’s attention is on fending off Russian hacks against Ukraine, American officials are increasingly worried about another growing threat: attacks by China on U.S. soil.

Google Uncovers APT41's Use of Open Source GC2 Tool to Target Media and Job Sites

17 April 2023
A Chinese nation-state group targeted an unnamed Taiwanese media organization to deliver an open source red teaming tool known as Google Command and Control (GC2) amid broader abuse of Google's infrastructure for malicious ends. The tech giant's Threat Analysis Group (TAG) attributed the campaign to a threat actor it tracks under the geological and geographical-themed moniker HOODOO, which is

Tour of the Underground: Master the Art of Dark Web Intelligence Gathering

17 April 2023
The Deep, Dark Web – The Underground – is a haven for cybercriminals, teeming with tools and resources to launch attacks for financial gain, political motives, and other causes. But did you know that the underground also offers a goldmine of threat intelligence and information that can be harnessed to bolster your cyber defense strategies? The challenge lies in continuously monitoring the right

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

17 April 2023
"Zaraza bot targets a large number of web browsers and is being actively distributed on a Russian Telegram hacker channel popular with threat actors," cybersecurity company Uptycs said in a report published last week.

CYFIRMA raises an undisclosed amount in Pre-Series B funding for product innovation

17 April 2023
The funds raised will be used for product innovation and entering new global markets in North America, Europe, and MENA region in addition to growing the existing markets in SEA, including India, Singapore, and Japan.

Experts found the first LockBit encryptor that targets macOS systems

17 April 2023
The LockBit group is the first ransomware gang that has created encryptors to target macOS systems, MalwareHunterTeam warns. The researchers discovered the LockBit encryptors in a ZIP archive uploaded to VirusTotal.

Federal, International Agencies Release Principles to Enhance Security of Tech Products

17 April 2023
The authoring agencies urged technology and software manufacturers “to revamp their design and development programs to permit only secure-by-design and -default products to be shipped to customers.”