Latest Cybersecurity News and Articles
16 March 2023
Rapid7 says Minerva’s technology will be fitted into its Managed Detection and Response (MDR) services to beef up detection and response capabilities across cloud, on-premise, and extended attack surfaces.
16 March 2023
A vendor of clinical and third-party administrative services to managed care organizations serving elderly and disabled patients said a cybersecurity incident last summer affected more than 4.2 million individuals.
16 March 2023
Dubbed “FakeCalls” by the Check Point Research (CPR) team, the malware baits victims with fake loans, requesting them to confirm their credit card numbers, which are then stolen.
16 March 2023
Following the collapse of Silicon Valley Bank (SVB), security researchers from all around the world warned that threat actors are already registering suspicious domains, creating phishing pages, and planning for BEC attacks. Through bogus domains, actors request personal information of individuals, such as their name, mobile number, email, and balance amount to process a claim.
16 March 2023
Adobe Acrobat Sign allows registered users to send a document signature request to anyone. When doing so, an email will be generated and sent to the intended recipients from a legitimate email address.
16 March 2023
Two new surveys examine what it takes to make a successful SOC. Both surveys stress the need for automation and artificial intelligence (AI) – but one survey raises the additional specter of the growing use of bring your own AI (BYO-AI).
16 March 2023
A cancer patient whose nude medical photos and records were posted online after they were stolen by a ransomware gang, has sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.
16 March 2023
A coalition of law enforcement agencies across Europe and the U.S. announced the takedown of ChipMixer, an unlicensed cryptocurrency mixer that began its operations in August 2017.
"The ChipMixer software blocked the blockchain trail of the funds, making it attractive for cybercriminals looking to launder illegal proceeds from criminal activities such as drug trafficking, weapons trafficking,
16 March 2023
The Russian APT29 threat group abused multiple legitimate systems, including LegisWrite and eTrustEx, which are used by EU nations for exchanging info and data in a secure way.
16 March 2023
'Pig Butchering' cryptocurrency investment schemes increasingly target Americans; over $2 billion in cryptocurrencies were stolen by hackers in the U.S. last year. The fraudsters approach victims via dating platforms, messaging apps, or social media platforms to introduce themselves. The FBI has recommended some tips for users to defend themselves against cryptocurrency investment scams.
16 March 2023
While massive public data breaches rightfully raise alarms, the spike in malware designed to exfiltrate data directly from devices and browsers is a key contributor to continued user exposure, according to SpyCloud.
16 March 2023
According to the NSA, a mature zero trust framework requires the adoption of capabilities from seven different pillars, namely application/workload, automation and orchestration, device, data, network/environment, user, and visibility and analytics.
16 March 2023
The operation was conducted by Europol in coordination with law enforcement in Germany (BKA) and the United States (FBI), allowing the police to seize four servers, 7 TB of data, and $46.5 million worth of cryptocurrency (Bitcoin).
16 March 2023
A day after sounding an alarm for live exploitation of the Outlook security flaw, Microsoft said it traced the exploit to a Russian APT targeting a limited number of organizations in government, transportation, energy, and military sectors in Europe.
16 March 2023
In last year's edition of the Security Navigator we noted that the Manufacturing Industry appeared to be totally over-represented in our dataset of Cyber Extortion victims. Neither the number of businesses nor their average revenue particularly stood out to explain this.
Manufacturing was also the most represented Industry in our CyberSOC dataset – contributing more Incidents than any other
16 March 2023
Multiple threat actors, including a nation-state group, exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal entity in the U.S.
The disclosure comes from a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC).
16 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 15 added a security vulnerability impacting Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The critical flaw in question is CVE-2023-26360 (CVSS score: 8.6), which could be exploited by a threat actor to achieve arbitrary code execution.
"Adobe ColdFusion
15 March 2023
By Mazhar Hamayun, cyber security engineer and member of the Office of the CTO at Check Point. In the digital age, public sector organizations face a myriad of cyber security challenges that can potentially compromise sensitive information and critical infrastructure. From phishing schemes to ransomware attacks, public sector organizations must stay ahead of threats while […]
The post Cyber security for the public sector: What you need to know appeared first on CyberTalk.
15 March 2023
To help improve threat prevention, the NSA released the Advancing Zero Trust Maturity throughout the User Pillar Cybersecurity Information Sheet.
15 March 2023
Tick (aka Bronze Butler, REDBALDKNIGHT, Stalker Panda, and Stalker Taurus) is a suspected China-aligned collective that has primarily gone after government, manufacturing, and biotechnology firms in Japan. It's said to be active since at least 2006.