Cyber Security News


  • Apria Healthcare says potentially 2M people caught up in IT security breach

    May 23, 2023

    Personal and financial data describing almost 1.9 million Apria Healthcare patients and employees may have been accessed by crooks who breached the company’s networks over a series of months in 2019 and 2021. The home healthcare equipment provider, which says it serves about two million patients from 280 locations across America, said it discovered the intrusion ...

  • Meet the GoldenJackal APT group. Don’t expect any howls

    May 23, 2023

    GoldenJackal is an APT group, active since 2019, that usually targets government and diplomatic entities in the Middle East and South Asia. Despite the fact that they began their activities years ago, this group is generally unknown and, as far as Kaspersky understands, has not been publicly described. Their researchers started monitoring the group in mid-2020 ...

  • Dish confirms 300,000 people’s data was exposed in February’s attack

    May 23, 2023

    Dish Network has admitted that a February cybersecurity incident and associated multi-day outage led to the extraction of data on nearly 300,000 people, while also appearing to indirectly admit it may have paid cybercriminals to delete said data. Dish customers can rest easy, at the very least, as the company said in a sample letter posted ...

  • Ireland’s cyber security agency has been providing ‘non-lethal aid’ to Ukraine

    May 23, 2023

    Ireland’s National Cyber Security Centre (NCSC) has been providing “non-lethal aid” to Ukraine amid the ongoing Russian invasion, TDs and Senators have been told. Dr Richard Browne, the director of the NCSC, said the assistance has been given in “significant volumes” and “helping Ukraine helps us better protect the people of Ireland.” Read more… Source: The Irish Times  

  • CISA Releases Four Industrial Control Systems Advisories

    May 23, 2023

    CISA released four Industrial Control Systems (ICS) advisories on May 23, 2023. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-23-143-01 Hitachi Energy AFS65x, AFS67x, AFR67x and AFF66x Products ICSA-23-143-02 Hitachi Energy RTU500 Read more… Source: U.S. Cybersecurity and Infrastructure Security Agency Related story: CISA Adds Three Known Exploited Vulnerabilities to Catalog   

  • Dorchester school IT system held to ransom in cyber attack

    May 23, 2023

    A school has been left unable to use email or accept payments following a cyber attack. Thomas Hardye School in Dorchester said its screens and systems had been locked since being targeted on Sunday. It said the attack was accompanied by a ransom demand, payable on the dark web. Read more… Source: BBC News  

  • Don’t @ Me: URL Obfuscation Through Schema Abuse

    May 22, 2023

    A technique is being used in the distribution of multiple families of malware that obfuscates the end destination of a URL by abusing the URL schema. Mandiant tracks this adversary methodology as “URL Schema Obfuscation”. The technique could increase the likelihood of a successful phishing attack, and could cause domain extraction errors in logging or security ...

  • Unleash AI Technologies In Oil And Gas With AUTOMA 2023

    May 22, 2023

    The topic of artificial intelligence in the oil and gas industry is one of the highlights of the Oil and Gas Automation and Digitalization Congress, held on November, 27-28, 2023. The Congress gathers the leading industry representatives to share innovative ways of industry transformation through digital tools and AI systems. The whole value chain of the ...

  • More UK councils caught by Capita’s open AWS bucket blunder

    May 22, 2023

    The bad news train keeps rolling for Capita, with more local British councils surfacing to say their data was put on the line by an unsecured AWS bucket, and, separately, pension clients warning of possible data theft in March’s mega breach. Colchester City Council was the first to step forward last week to claim that tech ...

  • Google launches bug bounty program for its Android applications

    May 22, 2023

    Google has launched the Mobile Vulnerability Rewards Program (Mobile VRP), a new bug bounty program that will pay security researchers for flaws found in the company’s Android applications. “We are excited to announce the new Mobile VRP! We are looking for bughunters to help us find and fix vulnerabilities in our mobile applications,” Google VRP tweeted. Read ...

  • Cyber Signals: Shifting tactics fuel surge in business email compromise

    May 19, 2023

    Today Microsoft released the fourth edition of Cyber Signals highlighting a surge in cybercriminal activity around business email compromise (BEC). Microsoft has observed a 38 percent increase in cybercrime as a service (CaaS) targeting business email between 2019 and 2022. Successful BEC attacks cost organizations hundreds of millions of dollars annually. In 2022, the FBI’s Recovery ...