Latest Cybersecurity News and Articles


PlugX Exploits Flaws in Remote Control Software

15 March 2023
Researchers from AhnLab have observed some unidentified threat actors use PlugX to exploit well-known flaws in remote desktop software to get complete control over the infected system. Several other threats, including the Sliver backdoor, Gh0st RAT, and XMRig coinminer, have abused the bugs in previous attacks. To prevent such threats, organizations are suggested to regularly review and update their security posture, and keep all the software updated.

New Cryptojacking Operation Targeting Kubernetes Clusters for Dero Mining

15 March 2023
Cybersecurity researchers have discovered the first-ever illicit cryptocurrency mining campaign used to mint Dero since the start of February 2023. "The novel Dero cryptojacking operation concentrates on locating Kubernetes clusters with anonymous access enabled on a Kubernetes API and listening on non-standard ports accessible from the internet," CrowdStrike said in a new report shared with The

Shift to secure-by-design must start at university level, CISA director says

15 March 2023
The transition to secure-by-design will require a major shift in how technology products are developed, Jen Easterly said, and that will include changes in the code used to develop software.

The Different Methods and Stages of Penetration Testing

15 March 2023
The stakes could not be higher for cyber defenders. With the vast amounts of sensitive information, intellectual property, and financial data at risk, the consequences of a data breach can be devastating. According to a report released by Ponemon institute, the cost of data breaches has reached an all-time high, averaging $4.35 million in 2022. Vulnerabilities in web applications are often the

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

15 March 2023
Eight of the 80 bugs are rated Critical, 71 are rated Important, and one is rated Moderate in severity. The updates are in addition to 29 flaws the tech giant fixed in its Chromium-based Edge browser in recent weeks.

Tick APT Targeted High-Value Customers of East Asian Data-Loss Prevention Company

15 March 2023
A cyberespionage actor known as Tick has been attributed with high confidence to a compromise of an East Asian data-loss prevention (DLP) company that caters to government and military entities. "The attackers compromised the DLP company's internal update servers to deliver malware inside the software developer's network, and trojanized installers of legitimate tools used by the company, which

Dark Pink Deploys KamiKakaBot to Target Government Entities in South Asian Countries

15 March 2023
Cybercriminals, purportedly of Asia-Pacific origin, have launched attacks aimed at government and military organizations in Southeast Asian countries. According to EclecticIQ, Dark Pink APT is behind the campaign and attempts to cripple systems via a custom malware dubbed KamiKakaBot. There are used to execute arbitrary commands and pilfer sensitive data from users.

Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

15 March 2023
In all, Adobe released patches for a whopping 106 vulnerabilities in a wide range of products, some serious enough to expose both Windows and macOS users to remote code execution attacks.

Emotet, QSnatch Malware Dominate Malicious DNS Traffic

15 March 2023
An analysis of trillions of DNS requests by Akamai showed a shocking amount of malicious traffic inside enterprise networks, with threats using DNS as a sort of malicious Autobahn.

SAP releases security updates fixing five critical vulnerabilities

15 March 2023
Software vendor SAP has released security updates for 19 vulnerabilities, five rated as critical, meaning that administrators should apply them as soon as possible to mitigate the associated risks.

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

15 March 2023
Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild. Eight of the 80 bugs are rated Critical, 71 are rated Important, and one is rated Moderate in severity. The updates are in addition to 29 flaws the tech giant fixed in its Chromium-based Edge browser in recent weeks. The

Two U.S. Men Charged in 2022 Hacking of DEA Portal

14 March 2023
Two U.S. men have been charged with hacking into a U.S. Drug Enforcement Agency (DEA) online portal that taps into 16 different federal law enforcement databases. Both are alleged to be part of a larger criminal organization that specializes in using fake emergency data requests from compromised police and government email accounts to publicly threaten and extort their victims.

10 of the best places to find AI talent for your business

14 March 2023
EXECUTIVE SUMMARY: Investing in AI? Don’t forget to invest in AI talent. In the modern business world, Artificial Intelligence (AI) tools are like powerful and versatile Swiss Army knives. As a Swiss Army knife offers a wide range of capabilities that can be adapted to a variety of situations, AI tools provide enterprises with a […] The post 10 of the best places to find AI talent for your business appeared first on CyberTalk.

UK's schoolgirl cyber security champions joined by undeclared war star at prestigious awards night

14 March 2023
Winning teams from the National Cyber Security Centre’s 2023 CyberFirst Girls Competition attend prize-giving ceremony in Belfast.

DEV-1101 Offers Phishing Kit for High-Volume AiTM Campaigns

14 March 2023
Microsoft Threat Intelligence stumbled across an open source adversary-in-the-middle (AiTM) phishing kit that furthers the ability of hackers to launch organized attacks and also scale it. The threat actor behind the kit is being tracked under the moniker DEV-1101. The kit’s features include setting up landing pages impersonating Microsoft Office and Outlook platforms. It can let attackers manage campaigns from mobile devices and even bypass CAPTCHA barriers.

2022 saw a 61% increase in the rate of phishing attacks

14 March 2023
A 2022 SaaS report by SaaS Alerts analyzed new threat vectors, key areas of concern and potential security gaps in SaaS applications. 

Users question corporate data responsibility & privacy

14 March 2023
Users question corporate data responsibility & privacy The Corporate Data Responsibility Survey 2022 from KPMG found disparate views on data privacy between U.S. users and corporations.

Antwan D. Banks hired as NMFTA Director of Enterprise Security

14 March 2023
Antwan D. Banks has been hired as Director of Enterprise Security for the National Motor Freight Traffic Association to defend trucking cybersecurity.

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

14 March 2023
An open-source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale. Microsoft is tracking the threat actor behind the kit under the moniker DEV-1101.

Siemens Addresses Over 90 Vulnerabilities for ICS Patch Tuesday

14 March 2023
Siemens has released only seven new advisories, but they describe a total of 92 vulnerabilities. However, a vast majority are introduced by the use of third-party components rather than being specific to Siemens products.