Latest Cybersecurity News and Articles


UK Criminal Records Office's Customer Portal Offline Amid Cybersecurity Incident

06 April 2023
As the name implies, the government agency manages people's criminal record information, running checks as needed on individuals for any convictions, cautions, or ongoing prosecutions.

Supply Chain Attacks and Critical Infrastructure: How CISA Helps Secure a Nation's Crown Jewels

06 April 2023
Critical infrastructure attacks are a preferred target for cyber criminals. Here's why and what's being done to protect them. What is Critical Infrastructure and Why is It Attacked? Critical infrastructure is the physical and digital assets, systems and networks that are vital to national security, the economy, public health, or safety. It can be government- or privately-owned. According to Etay

New OpcJacker Targets Iranian Individuals via Malvertising Lures

06 April 2023
Several fake websites were erected to advertise genuine software and cryptocurrency-related applications only to drop OpcJacker, an info-stealer, stated Trend Micro. The malware is capable of carrying next-stage payloads such as NetSupport RAT and a remote access-focused version with hidden virtual network computing (hVNC).

CISA JCDC Will Focus on Energy Sector

06 April 2023
Public utilities have been put to the test as attacks by bad actors have risen sharply in recent years. Q3 ‘22 saw a record number of attacks on the energy market, a trend that is not expected to slow down.

Android’s April 2023 Updates Patch Critical Remote Code Execution Vulnerabilities

06 April 2023
The security bulletin describes 26 vulnerabilities resolved in the Framework and System components as part of the 2023-04-01 security patch level. Most of these are high-severity flaws causing elevation of privilege (EoP) or information disclosure.

Google will require Android apps to let you delete your account

06 April 2023
According to the new policy, starting in early 2024, Google Play users will have better control over their data since every store listing will display links in the "Data deletion" area, allowing them to ask for their accounts and data to be deleted.

Twitter's recommendation algorithm opens platform to manipulation, bot attacks, researcher finds

06 April 2023
Just three days after Twitter released a portion of its source code online including its recommendation algorithm, a researcher found that attackers could manipulate the software to effectively silence specific accounts on the social media platform.

Telegram now the go-to place for selling phishing tools and services

06 April 2023
A report from Kasperksy notes that phishers sell all types of phishing material and services to interested buyers, including ready-made kits, fake pages, subscriptions to tools, guides, and technical support.

Cyber threats organizations should keep an eye on in 2023

06 April 2023
Two of the currently most threatening malware are Emotet and SocGholish. Android droppers usually come disguised as benign apps, available on third-party app stores or even on Google Play. MacOS malware is not common, but the threat can't be ignored.

Google TAG Warns of North Korean-linked ARCHIPELAGO Cyberattacks

06 April 2023
Attack chains mounted by ARCHIPELAGO involve the use of phishing emails containing malicious links that, when clicked by the recipients, redirect to fake login pages that are designed to harvest credentials.

FBI Cracks Down on Genesis Market: 119 Arrested in Cybercrime Crackdown

06 April 2023
A coordinated international law enforcement operation has dismantled Genesis Market, an illegal online marketplace that specialized in the sale of stolen credentials associated with email, bank accounts, and social media platforms. Coinciding with the infrastructure seizure, the major crackdown, which involved authorities from 17 countries, culminated in 119 arrests and 208 property searches in

How ChatGPT can be poked into emitting malicious code

06 April 2023
An experiment by a Forcepoint staffer does, to some extent, highlight how the code-suggesting unreliable chatbot, built by OpenAI and pushed by Microsoft, could be used to cut some corners in malware development or automate the process.

3CX Supply Chain Attack by Lazarus also Targets Crypto Firms

06 April 2023
Kaspersky attributed the 3CX supply chain attack to the North Korean Lazarus APT group, owing to the deployment of the Gopuram and AppleJeus backdoors used by the threat actor. Attackers deployed Gopuram on machines mostly belonging to cryptocurrency companies in Brazil, Germany, Italy, and France.

UK Discloses Offensive Cyber Capabilities Principles

06 April 2023
The UK government continues to adjust its cyber response to the growing threat posed by nation-state adversaries, in line with its latest National Cyber Strategy (NCS), published in December 2022.

New CryptoClippy Malware Targeting Portuguese Cryptocurrency Users

06 April 2023
The activity leverages SEO poisoning techniques to entice users searching for "WhatsApp web" to rogue domains hosting the malware, Palo Alto Networks Unit 42 said in a new report published today.

Rilide Info-stealer: A Serious Threat to Cryptocurrency Assets

06 April 2023
Trustwave SpiderLabs laids bare a new malware, dubbed Rilide, that can steal cryptocurrency by abusing multiple Chromium-based browsers, such as Google Chrome, Opera, Microsoft Edge, and Brave. Experts recommend remaining vigilant when opening emails from unknown and untrusted sources.

Google Mandates Android Apps to Offer Easy Account Deletion In-App and Online

05 April 2023
Google is enacting a new data deletion policy for Android apps that allow account creation to also offer users with a setting to delete their accounts in an attempt to provide more transparency and control over their data. "For apps that enable app account creation, developers will soon need to provide an option to initiate account and data deletion from within the app and online," Bethel

New Proxyjacking Attack Exploits Log4j for Initial Access

05 April 2023
Researchers at Sysdig highlight that the new Proxyjacking attack, which is much like cryptojacking, is abusing the infamous Log4j vulnerability to gain initial access to victims’ systems. On a broader scale, researchers note that a modest compromise of 100 IPs can enable attackers to make a profit of nearly $1,000 per month.

Rorschach - New Ransomware with Highest-Ever Encryption Speed

05 April 2023
A new ransomware strain, named Rorschach, was unveiled by Check Point Research. The ransomware boasts an advanced level of customization and fast encryption, which sets it apart from other strains. Furthermore, an in-depth examination of Rorschach's source code indicates similarities with the Babuk ransomware family. Its attacks have been reported in Asia, Europe, and the Middle East.

Exploited Elementor Pro Plugin Under Attack; Affects Over 11 Million Sites

05 April 2023
A security vulnerability in the Elementor Pro website builder plugin for WordPress is under active exploitation by a threat actor. An authenticated user can take advantage of this to take full control over a WordPress site having WooCommerce enabled. The bug in the plugin, roughly deployed on over 12 million sites, impacts versions 3.11.6 and earlier.