Latest Cybersecurity News and Articles


THN Webinar: Inside the High Risk of 3rd-Party SaaS Apps

24 March 2023
Any app that can improve business operations is quickly added to the SaaS stack. However, employees don't realize that this SaaS-to-SaaS connectivity, which typically takes place outside the view of the security team, significantly increases risk. Whether employees connect through Microsoft 365, Google Workspace, Slack, Salesforce, or any other app, security teams have no way to quantify their

GitHub Swiftly Replaces Exposed RSA SSH Key to Protect Git Operations

24 March 2023
Cloud-based repository hosting service GitHub said it took the step of replacing its RSA SSH host key used to secure Git operations "out of an abundance of caution" after it was briefly exposed in a public repository. The activity, which was carried out at 05:00 UTC on March 24, 2023, is said to have been undertaken as a measure to prevent any bad actor from impersonating the service or

South Korea fines McDonald's for data leak from raw SMB share

24 March 2023
McDonald's was slapped with a ?696 million ($530,000) fine for storing backup files that contained users of its McDelivery service on an SMB volume that left sharing enabled. Hackers waltzed in and accessed 4,876,106 users' info.

CISA, NSA Issue Guidance for IAM Administrators

24 March 2023
CISA and the NSA point out that IAM solutions should be managed, patched, and updated as any other software, to prevent vulnerability exploitation that could lead to the compromise of multiple systems and data.

New Kritec Skimming Malware Found Targeting Magento Stores

24 March 2023
Akamai shed light on a Magecart skimmer campaign camouflaged as the Google Tag Manager script. Threat actors reportedly used a new skimmer, Kritec, named after one of its domain names. Its skimming code is heavily obfuscated, mostly via obfuscator[.]io, and loads the malicious JavaScript in an unprecedented way.

Clerk Raises $15M in Series A Funding

24 March 2023
The round was led by Madrona, with participation from Guillermo Rauch, Mango Capital, Dave Wilner, Andreessen Horowitz, S28 Capital, and Fathom Capital. Madrona’s managing director Karan Mehandru joined the board.

Microsoft fixes Acropalypse privacy bug in Windows 11 Snipping Tool

24 March 2023
As first spotted by Windows enthusiast Xeno, Microsoft released Windows 11 Snipping Tool version 11.2302.20.0 yesterday to Windows Insiders in the Canary channel via the Microsoft Store.

Researchers Uncover Chinese Nation State Hackers' Deceptive Attack Strategies

24 March 2023
A recent campaign undertaken by Earth Preta indicates that nation-state groups aligned with China are getting increasingly proficient at bypassing security solutions. The threat actor, active since at least 2012, is tracked by the broader cybersecurity community under Bronze President, HoneyMyte, Mustang Panda, RedDelta, and Red Lich. Attack chains mounted by the group commence with a

New 'FakeGPT' Chrome Extension Hijacks Facebook Accounts

24 March 2023
Guardio Labs found a new version of the FakeGPT Chrome extension that is again targeting Facebook accounts, through malicious sponsored Google search results. At the time of removal from the Google Play Store, the FakeGPT extension was downloaded by more than 9,000 users. To prevent such attacks and protect data privacy, awareness is crucial.

Phishing attack through SharePoint

24 March 2023
The targeted employee receives a standard notification about someone sharing a file. This is unlikely to arouse suspicion because it’s a real notification from a real SharePoint server.

Exploit released for Veeam bug allowing cleartext credential theft

24 March 2023
The flaw (CVE-2023-27532) affects all VBR versions and can be exploited by unauthenticated attackers to breach backup infrastructure after stealing cleartext credentials and gaining remote code execution as SYSTEM.

Critical Vulnerability Discovered in WooCommerce Payments

24 March 2023
The vulnerability was discovered by white hat security researcher Michael Mazzolini and responsibly disclosed through HackerOne, giving websites time to install the patched version 5.6.2 before full details of the exploit are released on April 6th.

Critical WooCommerce Payments Plugin Flaw Patched for 500,000+ WordPress Sites

24 March 2023
Patches have been released for a critical security flaw impacting the WooCommerce Payments plugin for WordPress, which is installed on over 500,000 websites. The flaw, if left unresolved, could enable a bad actor to gain unauthorized admin access to impacted stores, the company said in an advisory on March 23, 2023. It impacts versions 4.8.0 through 5.6.1. Put differently, the issue could permit

What is reverse tabnabbing and how can you stop it?

23 March 2023
EXECUTIVE SUMMARY: Reverse tabnabbing, also known simply as tabnabbing, is a form of phishing that involves deceiving a victim into entering login credentials on a fake website; a website that’s controlled by a cyber attacker. While there are numerous types of online attacks that leverage fake web pages to steal user information, tabnabbing distinguishes itself […] The post What is reverse tabnabbing and how can you stop it? appeared first on CyberTalk.

Kimsuky Updates its Tactics to Target South Korean Experts

23 March 2023
German and South Korean government agencies warned about a new spear-phishing campaign by the North Korean APT, Kimsuky. The campaign targets experts on issues related to the Korean peninsula. Attackers send a spear-phishing email to the targeted victims, asking them to install a malicious Chrome extension. The other tactic attempts to exploit Google Play's web-smartphone synchronization function to install malicious apps on the target’s device.

How AI is helping companies fight document fraud

23 March 2023
In an exclusive interview with David Hobbs, a fraud expert at Check Point, Conor Burke, the co-founder and CTO of Inscribe, sheds light on his AI-powered startup’s efforts to combat document fraud. As financial institutions prioritize the improvement of risk data availability, quality and timeliness, AI-powered fraud and credit insights can simplify decision-making, minimize uncertainty […] The post How AI is helping companies fight document fraud appeared first on CyberTalk.

Black Magic APT Targets Ukraine with CommonMagic and PowerMagic

23 March 2023
Kaspersky researchers have identified cyberattacks targeting government, agriculture, and transportation organizations in Donetsk, Lugansk, and Crimea, conducted by the new Bad Magic APT. The campaign leverages old artifacts created as early as September 2021, along with a previously unseen malicious framework dubbed CommonMagic.

48% of security leaders hesitant to adapt to post-quantum algorithms

23 March 2023
According to research, the rise of machine identities has created visibility and management challenges for public key infrastructures (PKI).

Skylink hit by hacker attack

23 March 2023
M7 Group’s Czech and Slovak operator Skylink has reportedly fallen victim to a hacker attack. Skylink offers DTH and internet TV services in the Czech Republic and Slovakia.

Hacktivists Increasingly Claim Targeting of OT Systems

23 March 2023
The number of false claims is at times challenging to debunk. However, despite the inaccuracy of most claims, when hacktivist activity targeting OT becomes commonplace, the likelihood of actual and even substantial OT incidents increases.