Security News > 2023 > December

New Malvertising Campaign Distributing PikaBot Disguised as Popular Software
2023-12-19 11:02

The malware loader known as PikaBot is being distributed as part of a malvertising campaign targeting users searching for legitimate software like AnyDesk. "PikaBot was previously only distributed...

Mr. Cooper breach exposes sensitive info of over 14 million customers
2023-12-19 10:33

Mortgage company Mr. Cooper has confirmed that personal information of over 14.6 million customers has been exposed in its October 2023 data breach. "On October 31, 2023, Mr. Cooper detected suspicious activity in certain network systems," the company stated in the data breach notice sent out to affected customers.

SSH vulnerability exploitable in Terrapin attacks (CVE-2023-48795)
2023-12-19 10:11

Security researchers have discovered a vulnerability in the SSH cryptographic network protocol that could allow an attacker to downgrade the connection's security by truncating the extension negotiation message. Terrapin is a prefix truncation attack targeting the SSH protocol.

Qakbot's backbot: FBI-led takedown keeps crims at bay for just 3 months
2023-12-19 09:26

Multiple sources are confirming the resurgence of Qakbot malware mere months after the FBI and other law enforcement agencies shuttered the Windows botnet. Microsoft Threat Intelligence reckons a new Qakbot phishing campaign is active as of December 11 but attack attempts are currently low in volume.

8220 Gang Exploiting Oracle WebLogic Server Vulnerability to Spread Malware
2023-12-19 06:58

The threat actors associated with the 8220 Gang have been observed exploiting a high-severity flaw in Oracle WebLogic Server to propagate their malware. The security shortcoming...

Double-Extortion Play Ransomware Strikes 300 Organizations Worldwide
2023-12-19 05:42

The threat actors behind the Play ransomware are estimated to have impacted approximately 300 entities as of October 2023, according to a new joint cybersecurity advisory from Australia and the...

The impact of prompt injection in LLM agents
2023-12-19 05:30

Malicious actors can leverage prompt injection techniques to generate unintended and potentially harmful outcomes by distorting the reality in which the LLM operates. The road to implementing LLM agents, particularly those interfacing with external tools and systems, is not without challenges.

EMBA: Open-source security analyzer for embedded devices
2023-12-19 05:00

The EMBA open-source security analyzer is tailored as the central firmware analysis tool for penetration testers and product security groups. It assists throughout the security evaluation procedure, extracting firmware, conducting static and dynamic analysis through emulation, and creating a web-based report.

Ransomware trends and recovery strategies companies should know
2023-12-19 04:30

Ransomware attacks continue at a record-breaking pace, with Q3 2023 global ransomware attack frequency up 11% over Q2 and 95% year-over-year, according to Corvus Insurance. Companies scramble to integrate immediate recovery into ransomware plans.

Most cloud transformations are stuck in the middle
2023-12-19 04:00

Cloud transformation is increasingly funded by non-IT stakeholders, emphasizing its place as a broader enterprise transformation rather than solely an IT endeavor. Only 32% of cloud initiatives are funded by IT stakeholders, challenging the perception of cloud transformation solely as an IT-centric journey.