Latest Cybersecurity News and Articles


Beware of Movie365 and Similar Sites Offering Free Movies Online

17 April 2023
If you’ve ever searched for free online movie streaming sites, you’ve probably come across Movie365 and other similar sites. While these sites promise access to the latest movies, they’re often not what they seem.

Google Launches New Cybersecurity Initiatives to Strengthen Vulnerability Management

17 April 2023
The company further emphasized that it's committing to publicly disclose incidents when it finds evidence of active exploitation of vulnerabilities across its product portfolio.

Russia accuses NATO of launching 5,000 cyberattacks since 2022

17 April 2023
The FSB claims that despite many of the attacks being presented as activities by the "IT Army of Ukraine," it was able to discern the involvement of pro-west hacker groups like "Anonymous," "Sailens," "Goast clan," "Ji-En-Ji," "SquadZOZ," and others.

Vice Society Ransomware Using Stealthy PowerShell Tool for Data Exfiltration

17 April 2023
Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from compromised networks.

Microsoft shares guidance to detect BlackLotus UEFI bootkit attacks

17 April 2023
Analyzing devices compromised with BlackLotus, the Microsoft Incident Response team identified several points in the malware installation and execution process that allow its detection.

Vice Society Ransomware Using Stealthy PowerShell Tool for Data Exfiltration

17 April 2023
Threat actors associated with the Vice Society ransomware gang have been observed using a bespoke PowerShell-based tool to fly under the radar and automate the process of exfiltrating data from compromised networks. "Threat actors (TAs) using built-in data exfiltration methods like [living off the land binaries and scripts] negate the need to bring in external tools that might be flagged by

New Zaraza Bot Credential-Stealer Sold on Telegram Targeting 38 Web Browsers

17 April 2023
A novel credential-stealing malware called Zaraza bot is being offered for sale on Telegram while also using the popular messaging service as a command-and-control (C2). "Zaraza bot targets a large number of web browsers and is being actively distributed on a Russian Telegram hacker channel popular with threat actors," cybersecurity company Uptycs said in a report published last week. "Once the

Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says

16 April 2023
Australians report record $3.1bn losses to scams, with real amount even higher, ACCC says Investment fraud amounts for biggest share at $1.5bn, followed by remote access and payment redirection rortsFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastAustralians lost a record amount of more than $3.1bn to scams in 2022, up from the $2bn lost in 2021, a new report from the Australian Competition and Consumer Commission has revealed.The Targeting Scams report, which compiles data from Scamwatch, ReportCyber, major banks and money remitters, was based on an analysis of more than 500,000 reports.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

Labour glitch put voting intentions data of millions at risk

16 April 2023
Labour glitch put voting intentions data of millions at risk Exclusive: Experts say sensitive information could potentially have been harvested and used for targeted election interferenceThe voting intentions of millions of Britons in local authority wards across the country could have been at risk of misuse as a result of a glitch in the Labour party’s main phone-banking system, the Guardian understands.Experts had warned that the sensitive data could potentially have been harvested via an automated programme and used for targeted election interference by campaign groups or even hostile states. Continue reading...

RTM Locker Enforces Strict Rules on Affiliates to Avoid Public Attention

15 April 2023
Trellix detected a new private RaaS group, named Read The Manual (RTM) Locker, that has been leveraging affiliates for ransom. Also, it flies under the radar by avoiding high-profile targets. Moreover, the self-destructive nature of RTM Locker and the wipeout of logs make it a tough game to crack for security professionals.

Transparent Tribe Eyes Indian Education Sector

15 April 2023
SentinelLabs identified a campaign by the Transparent Tribe that targets the Indian education sector via education-themed malicious Office documents propagating Crimson RAT. The group has long been targeting different sectors in India. Hence, vigilance and robust cyber defense strategies are necessary.

Forensic Analysis Confirms Involvement of North Korean Attackers in 3CX Supply Chain Attack

15 April 2023
3CX confirmed that the software supply chain attack was the work of a North Korean hacker group, UNC4736. The group used the Taxhaul and Simplesea malware for infecting Windows and macOS, respectively. Attackers used Taxhaul (or TxRLoader) to target Windows machines, which was further used to deploy a second-stage payload called Coldcat.

APT28 Leader’s Email Breached by Ukrainian Hackers

15 April 2023
Ukrainian hacker group Cyber Resistance claimed to have hacked the personal accounts, emails, and social media of a Russian GRU officer, who is also the leader of APT28. The email hack allowed the hackers to extract sensitive documents along with personal information and photos, and then leak them into the public domain.

Legion: A Python-Based Hacking Tool Targets Websites and Web Services

15 April 2023
The cybercriminal group, which goes by the moniker “Forza Tools,” was seen offering Legion - a Python-based credential harvester and SMTP hijacking tool. The malware targets online email services for phishing and spam attacks. Experts suggest it is likely based on the AndroxGhOst malware and has several feature modules. 

iPhones Hacked to Drop QuaDream’s KingsPawn Spyware

15 April 2023
QuaDream, an Israeli company best known for its malware Reign, has launched the new commercial spyware KingsPawn (a Pegasus-like threat). To begin the attack, iCloud calendar invitations with backdated timestamps are sent to targeted iOS devices. Experts recommend following best practices, such as enabling automatic software updates and using reliable anti-malware software to stay protected.

Darktrace: Investigation found no evidence of LockBit breach

15 April 2023
It is now apparent that LockBit messed up, confusing Darktrace with threat intelligence company DarkTracer which tweeted about the gang's leak site being flooded with fake victims.

Massive malvertising campaign targets seniors via fake Weebly sites

15 April 2023
The malvertising campaign is run via Google ads aimed at seniors. The threat actor is creating hundreds of fake websites via Weebly to host decoy content to fool search engines and crawlers while redirecting victims to a fake computer alert.

Vice Society ransomware uses new PowerShell data theft tool in attacks

15 April 2023
The new, rather sophisticated PowerShell script automates data theft from compromised networks. The script uses PowerShell to automate data exfiltration and consists of multiple functions, including Work(), Show(), CreateJobLocal(), and fill().

Google Releases Urgent Chrome Update to Fix Actively Exploited Zero-Day Vulnerability

15 April 2023
Tracked as CVE-2023-2033, the high-severity vulnerability has been described as a type confusion issue in the V8 JavaScript engine. Clement Lecigne of Google's Threat Analysis Group (TAG) has been credited with reporting the issue on April 11, 2023.

Google Releases Urgent Chrome Update to Fix Actively Exploited Zero-Day Vulnerability

14 April 2023
Google on Friday released out-of-band updates to resolve an actively exploited zero-day flaw in its Chrome web browser, making it the first such bug to be addressed since the start of the year. Tracked as CVE-2023-2033, the high-severity vulnerability has been described as a type confusion issue in the V8 JavaScript engine. Clement Lecigne of Google's Threat Analysis Group (TAG) has been