Latest Cybersecurity News and Articles


Taiwan: Shopee, Carousell most popular platforms used by phishing scammers

14 March 2023
The attacks were aimed at stealing personal or business information used by customers to carry out online transactions, and the information was then used to conduct scams such as canceling installment payment setups, according to the CIB.

Death registry system in Hawaii had data breach, health department says

14 March 2023
Hawaii’s Department of Health says it is sending out breach notification letters after a cyberattack in January gave hackers limited access to the state’s death registry.

Update: Los Angeles Housing Authority Discloses Data Breach After it Suffers Ransomware Attack

14 March 2023
According to its data breach notice, HACLA discovered on December 31, 2022, that files on its computer systems were encrypted. This prompted the agency to shut down its servers and launch an investigation.

Fortinet FortiOS Flaw Exploited in Targeted Cyberattacks on Government Entities

14 March 2023
Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result in data loss and OS and file corruption. "The complexity of the exploit suggests an advanced actor and that it is highly targeted at governmental or government-related targets," Fortinet researchers Guillaume Lovet and Alex Kong said in an

International leaders to take centre stage at CYBERUK 2023 in Belfast

13 March 2023
Top security officials from the U.S., Canada, New Zealand and Singapore amongst speakers for CYBERUK 2023 announced today.

A shocking truth: One in five government employees, indifferent to workplace hacks

13 March 2023
EXECUTIVE SUMMARY: Around the globe, cyber risks are intensifying. Responding to these growing challenges requires developing new partnerships, encouraging inter-departmental collaboration, pursuing innovative cyber security solutions, and promoting employee security awareness and engagement, among other things. In honing in on employee engagement, new survey findings suggest that there is a significant disconnect between CISO expectations […] The post A shocking truth: One in five government employees, indifferent to workplace hacks appeared first on CyberTalk.

Golang-based GoBruteforcer Malware Targets Popular Web Services

13 March 2023
GoBruteforcer, a new Golang-based botnet, has been seen scanning and infecting well-known web servers including FTP and MySQL, and deploys an IRC bot to communicate. At the time of the attack, GoBruteforcer uses a Classless Inter-Domain Routing (CIDR) block for scanning the network. The best way to avoid threats originating from brute forcers is to change default passwords and implement a strong password policy including 2FA.

Hackers Push BatLoader via Google Search Ads

13 March 2023
BATLOADER, the notorious malware loader, was seen exploiting Google Ads to deliver secondary payloads such as Vidar Stealer and Ursnif. In their ads, attackers fake legitimate apps and services such as Adobe, Tableau, ChatGPT, Spotify, and Zoom. Other samples of BATLOADER display enhanced capability to establish persistence inside compromised networks.

Large-scale Cyber Campaign Hijacks East Asian Websites for Adult Content Redirects

13 March 2023
A widespread malicious cyber operation has hijacked thousands of websites aimed at East Asian audiences to redirect visitors to adult-themed content since early September 2022.

China-linked Hackers Abuse SonicWall SMA Devices

13 March 2023
UNC4540, a China-linked cybercriminal group, was observed deploying a custom backdoor on a SonicWall SMA appliance. Attackers show a thorough understanding of the appliance and use a set of malicious files to obtain privileges. The malware is capable of extracting credentials, achieving persistence through firmware upgrades, and remotely executing code.

Investment Fraud is Now Biggest Cybercrime Earner

13 March 2023
Total cybercrime losses for 2022 were estimated at $10.3bn by the FBI's IC3 on the back of nearly 801,000 complaints. Although the latter figure rose 49% on the previous year’s total, the number of complaints actually fell by over 46,000.

Estonian official says parliamentary elections were targeted by cyberattacks

13 March 2023
Gert Auväärt, head of the National Cyber Security Centre-Estonia (NCSC-EE), told The Record that his team had been in a “heightened awareness level for two weeks” during the campaign, and that attempts to enter the electoral system were unsuccessful.

Zoll Medical Discloses Data Breach Impacting One Million Individuals

13 March 2023
Medical technology developer Zoll Medical is notifying roughly one million individuals that their personal information might have been compromised in a recent data breach.

The SVB demise is a fraudster’s paradise, so take precautions

13 March 2023
The frenzy around the SVB collapse presents a huge opportunity for cybercriminals, and it creates a cyber risk for thousands of SVB account holders, and their customers and suppliers.

Large-scale Cyber Attack Hijacks East Asian Websites for Adult Content Redirects

13 March 2023
A widespread malicious cyber operation has hijacked thousands of websites aimed at East Asian audiences to redirect visitors to adult-themed content since early September 2022. The ongoing campaign entails injecting malicious JavaScript code to the hacked websites, often connecting to the target web server using legitimate FTP credentials the threat actor previously obtained via an unknown

AI-Generated YouTube Video Tutorials Increasingly Distribute Infostealer Malware

13 March 2023
One of the popular malware distribution channels is YouTube, with CloudSEK witnessing a 200-300% month-over-month increase in videos containing links to stealer malware in the description section.

Blackbaud settles with SEC over misleading ransomware information

13 March 2023
Blackbaud has agreed to settle SEC charges due to misleading information regarding the extent of a ransomware attack the company suffered in 2020.

The risk of pasting confidential company data into ChatGPT

13 March 2023
The use of ChatGPT is becoming a serious problem in the workspace, it can potentially cause the leak of sensitive and confidential data. Companies like JP Morgan and Verizon are blocking access to the chatbot over concerns about confidential data.

The 2 biggest regulatory challenges for the internet of “any” thing (IoT)

13 March 2023
By Antoinette Hodes, a Check Point Global Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO. She has worked as an engineer in IT for over 25 years. She is a strong customer advocate, who connects people & processes with technology by matching the clients’ business needs […] The post The 2 biggest regulatory challenges for the internet of “any” thing (IoT) appeared first on CyberTalk.

Medusa ransomware gang picks up steam as it targets companies worldwide

13 March 2023
The Medusa operation started in June 2021 but had relatively low activity, with few victims. However, in 2023 the ransomware gang increased in activity and launched a 'Medusa Blog' used to leak data for victims who refused to pay a ransom.