Latest Cybersecurity News and Articles


Research indicates humans are still better than ChatGPT at phishing — for now

16 March 2023
A study by Hoxhunt sampling 53,000 email users in more than 100 countries found that professional red teamers generated a click rate of 4.2%, while ChatGPT-generated emails induced just a 2.9% click rate.

CISA says federal civilian agency hacked by nation-state and criminal hacking groups

16 March 2023
According to the alert, both the unnamed nation-backed hacking group and the criminal group dubbed XE Group exploited known vulnerabilities in Progress Telerik software located in the unnamed government agency’s Microsoft IIS web server.

Google Proposes Reducing TLS Cert Life Span to 90 Days

16 March 2023
By virtue of Chrome's market share, if Google makes this change for Chrome, that makes it a de facto standard that every commercial public certificate authority would have to follow.

US threatens to ban TikTok unless Chinese owners divest

16 March 2023
US threatens to ban TikTok unless Chinese owners divest Move is latest escalation by lawmakers over fears user data could be passed on to China’s governmentThe Biden administration has threatened to ban TikTok in the US unless the social media company’s Chinese owners divest their stakes in it, according to news reports on Wednesday.The move, first reported by the Wall Street Journal, is the most dramatic in a series of escalations by US officials and legislators, driven by fears that US user data held by the company could be passed on to China’s government. It also comes amid a global backlash to the popular video-based app over concerns about the potential for Chinese spying, with countries including the UK, Canada and Australia recently moving to ban the app from government phones. Continue reading...

Chinese and Russian Hackers Using SILKLOADER Malware to Evade Detection

16 March 2023
Threat activity clusters affiliated with the Chinese and Russian cybercriminal ecosystems have been observed using a new piece of malware that's designed to load Cobalt Strike onto infected machines. Dubbed SILKLOADER by Finnish cybersecurity company WithSecure, the malware leverages DLL side-loading techniques to deliver commercial adversary simulation software. The development comes as 

UK bans TikTok from government mobile phones

16 March 2023
UK bans TikTok from government mobile phones Move brings Britain in line with US and Europe and reflects worsening relations with ChinaBritain is to ban the Chinese-owned video-sharing app TikTok from ministers’ and civil servants’ mobile phones, bringing the UK in line with the US and the European Commission and reflecting deteriorating relations with Beijing.The decision marks a sharp U-turn from the UK’s previous position and came a few hours after TikTok said its owner, ByteDance, had been told by Washington to sell the app or face a possible ban in the country. Continue reading...

Update: Hacker selling data allegedly stolen in US Marshals Service hack

16 March 2023
The announcement, titled "350 GB from US Marshal Service (USMS) law enforcement confidential information," was added on March 15, using an account registered just a day earlier on a Russian-speaking hacking forum.

Supercharge your productivity, 5 ingenious ChatGPT integrations

16 March 2023
EXECUTIVE SUMMARY: The powerful next-generation artificial intelligence-based tool known as ChatGPT has not only captured the public’s imagination; it’s shaking up the business world. For companies that figure out how to leverage the technology strategically, it’s altering the ways in which companies do business, opening doors for greater innovation, and shifting expectations around business growth. […] The post Supercharge your productivity, 5 ingenious ChatGPT integrations appeared first on CyberTalk.

Feds fine Florida children's health insurance site for massive 2020 hack

16 March 2023
Jelly Bean Communications Design reached a $293,771 settlement to resolve False Claims Act allegations that it knowingly provided deficient security controls to Florida Healthy Kids Corp., which caused the second-largest healthcare breach of 2021.

Portable health device company suffers data breach

16 March 2023
ZOLL Medical has notified its customers of a data breach affecting customers' protected health information (PHI) that occurred in late January.  

GoatRAT Android Banking Trojan Targets Mobile Automated Payment System

16 March 2023
The new GoatRAT — like BraxDex, Senomorphy, and PixPirate before it — steals the Pix key of the mobile devices it targets to make instant payments from compromised accounts, researchers from Cyble revealed in a blog post.

Why Healthcare Boards Lag Other Industries in Preparing for Cyberattacks

16 March 2023
A new report from Proofpoint and Cybersecurity at MIT Sloan says 61% of healthcare boards discuss cybersecurity at least monthly (versus 75% across all sectors), and only 64% believe they have invested adequately in it (versus 76% for all sectors).

Voice system used to verify identity by Centrelink can be fooled by AI

16 March 2023
Voice system used to verify identity by Centrelink can be fooled by AI Exclusive: Voiceprint program used by millions of Australians to access data held by government agencies shown to have a serious security flaw Get our morning and afternoon news emails, free app or daily news podcastA voice identification system used by the Australian government for millions of people has a serious security flaw, a Guardian Australia investigation has found.Centrelink and the Australian Taxation Office (ATO) both give people the option of using a “voiceprint”, along with other information, to verify their identity over the phone, allowing them to then access sensitive information from their accounts.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

LockBit Ransomware Claims Attack on Essendant, Company Says Network Outage

16 March 2023
As earlier reported by BleepingComputer, Essendant's widespread network outage has prevented the placement or fulfillment of online orders and impacted both the company's customers and suppliers.

Cryptojacking Group TeamTNT Suspected of Using Decoy Miner to Conceal Data Exfiltration

16 March 2023
The cryptojacking group known as TeamTNT is suspected to be behind a previously undiscovered strain of malware used to mine Monero cryptocurrency on compromised systems. That's according to Cado Security, which found the sample after Sysdig detailed a sophisticated attack known as SCARLETEEL aimed at containerized environments to ultimately steal proprietary data and software. Specifically, the

The Role of Customer Service in Cybersecurity

16 March 2023
Depending on the business, a customer service agent may have access to a trove of customer information and company systems. They may even have access to change customer account information or take payments over the phone.

GAO Offers Quantum Guidance to Federal Agencies

16 March 2023
More federal guidance has emerged as the world continues its preparations for the advent of quantum computing with the Government Accountability Office disseminating fast facts on how to secure sensitive data in a post-quantum cryptographic world.

Department of State receives funding for semiconductor development

16 March 2023
The Department of State implements new funding to address security objectives through new programs and initiatives for semiconductor development.

Latitude Financial Says Hacking Incident Led to Theft of 328,000 Customer IDs

16 March 2023
Latitude said the details were stolen from service providers it uses. The company did not clarify further, but this is believed to refer to companies that provide corporate services to Latitude.

Rapid7 Buys Anti-Ransomware Firm Minerva Labs for $38 Million

16 March 2023
Rapid7 says Minerva’s technology will be fitted into its Managed Detection and Response (MDR) services to beef up detection and response capabilities across cloud, on-premise, and extended attack surfaces.