Latest Cybersecurity News and Articles


Siemens Addresses Over 90 Vulnerabilities for ICS Patch Tuesday

14 March 2023
Siemens has released only seven new advisories, but they describe a total of 92 vulnerabilities. However, a vast majority are introduced by the use of third-party components rather than being specific to Siemens products.

Hospital in Brussels latest victim in spate of European healthcare cyberattacks

14 March 2023
Ambulances were diverted from the Centre Hospitalier Universitaire (CHU) Saint-Pierre this weekend following the attack in the early hours of Friday morning. Details about the attack and the perpetrators have not yet been disclosed.

Financial services DDoS resilience starts with understanding attack surface

14 March 2023
The recent attack on Danish Bank shows what can happen when organizations need more awareness of vulnerabilities and evolving DDoS attack surface. 

CISA now warns critical infrastructure of ransomware-vulnerable devices

14 March 2023
"As part of RVWP, CISA leverages existing authorities and technology to proactively identify information systems that contain security vulnerabilities commonly associated with ransomware attacks," the cybersecurity agency said.

Grip Security Receives Investment from The Syndicate Group

14 March 2023
The Boston, MA, and Tel Aviv, Israel-based SaaS security company unifying discovery, access control, and data governance, received an investment from The Syndicate Group. The amount of the deal was not disclosed.

LockBit Claims it Stole SpaceX Schematics From Parts Supplier, Threatens to Leak Them

14 March 2023
Ransomware gang Lockbit has boasted it broke into Maximum Industries, which makes parts for SpaceX, and stole 3,000 proprietary schematics developed by Elon Musk's rocketeers.

88% of breached passwords are 12 characters or less

14 March 2023
A recent study of 800 million breached passwords found that 88% of passwords used in successful cyberattacks were 12 characters or less.

New Fake ChatGPT Chrome Extension Stealing Facebook Ad Accounts with Thousands of Installs

14 March 2023
A Chrome Extension offering quick access to fake ChatGPT functionality was found to be hijacking Facebook accounts and installing hidden account backdoors. Notably, the Facebook app “backdoor” gives the threat actors super-admin permissions.

Increasing infrastructure security by reducing complexity

14 March 2023
By Deryck Mitchelson, Field CISO EMEA, Check Point Software Technologies. Cyber complexity can impede efforts to secure systems. In particular, cyber security complexity increases risks, drives high costs, and can result in sub-par decision-making. By pursuing a simplification agenda, leaders can build true cyber security resilience. Reducing complexity means focusing on operational overlap, on duplication and […] The post Increasing infrastructure security by reducing complexity appeared first on CyberTalk.

Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms

14 March 2023
Reports published in the past couple of months by various industrial cybersecurity companies provide different numbers when it comes to the vulnerabilities discovered in industrial control system (ICS) products in 2022.

Pro-Russian Hackers Blackmail Ukrainian Developer of S.T.A.L.K.E.R. 2 Game

14 March 2023
GSC Game World says it has been enduring cyberattacks for ‘more than a year’ and that hackers demand Russia-friendly changes to the game or else they’ll leak tons of the game’s development materials.

GoBruteforcer: New Golang-Based Malware Breaches Web Servers Via Brute-Force Attacks

14 March 2023
A new Golang-based malware dubbed GoBruteforcer has been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a botnet. "GoBruteforcer chose a Classless Inter-Domain Routing (CIDR) block for scanning the network during the attack, and it targeted all IP addresses within that CIDR range," Palo Alto Networks Unit 42 researchers said. "The threat actor

GitHub 2FA plan adds SMS, account lockout safeguards

14 March 2023
GitHub has added SMS support and fresh account lockout prevention features to its phased rollout plans as it prepares to implement a 2FA requirement for accounts beginning Monday.

The Prolificacy of LockBit Ransomware

14 March 2023
Today, the LockBit ransomware is the most active and successful cybercrime organization in the world. Attributed to a Russian Threat Actor, LockBit has stepped out from the shadows of the Conti ransomware group, who were disbanded in early 2022. LockBit ransomware was first discovered in September 2019 and was previously known as ABCD ransomware because of the ".abcd virus" extension first

Hackers Steal Around $200 Million From Crypto Lender Euler Finance

14 March 2023
According to PeckShield, hackers exploited Euler “in a flurry of transactions” which led to the theft of around $197 million in crypto. Crypto security firm BlockSec also reported the attack.

Fighting financial fraud through fusion centers

14 March 2023
Cyberattacks and fraud are now too closely linked to be considered separately. But many firms still have investigative fraud teams and cybersecurity teams operating independently, along with the systems and processes that support them.

Clop ransomware gang begins extorting GoAnywhere zero-day victims

14 March 2023
The Clop ransomware gang has begun extorting companies whose data was stolen using a zero-day flaw in the Fortra GoAnywhere MFT secure file-sharing solution. The extortion group said they used the flaw over ten days to steal data from 130 companies.

Dissecting the malicious arsenal of the Makop ransomware gang

14 March 2023
Makop ransomware operations are based on the human operator ransomware practice where most of the intrusion is handled by hands-on keyboard criminals, even in the encryption stage.

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

14 March 2023
An open source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale. Microsoft Threat Intelligence is tracking the threat actor behind the development of the kit under its emerging moniker DEV-1101. An AiTM phishing attack typically involves a threat actor attempting to steal and intercept a target's

Fortinet FortiOS Flaw Exploited in Targeted Cyberattacks on Government Entities

14 March 2023
The zero-day flaw in question is CVE-2022-41328 (CVSS score: 6.5), a medium security path traversal bug in Fortinet's FortiOS that could lead to arbitrary code execution.