Latest Cybersecurity News and Articles
13 March 2023
The Dark Pink advanced persistent threat (APT) actor has been linked to a fresh set of attacks targeting government and military entities in Southeast Asian countries with a malware called KamiKakaBot.
Dark Pink, also called Saaiwc, was first profiled by Group-IB earlier this year, describing its use of custom tools such as TelePowerBot and KamiKakaBot to run arbitrary commands and exfiltrate
12 March 2023
ReliaQuest has laid bare the detail of a phishing campaign by IAB Exotic Lily wherein its members pretend to be a potential business opportunity. The attackers follow a well-established procedure that typically commences with initiating an open conversation with the victim. ReliaQuest advises blocking unsanctioned file sharing, torrent, and peer-to-peer sites.
12 March 2023
Chinese 8220 Gang deployed the new ScrubCrypt payload exploiting an Oracle Weblogic Server in a specific URI between January and February 2023, revealed security experts at Fortinet. The ScrubCrypt crypter allows a hacker to secure applications with a unique BAT packing technique. It was found to be available for sale on dark web forums.
11 March 2023
The malware downloader known as BATLOADER has been observed abusing Google Ads to deliver secondary payloads like Vidar Stealer and Ursnif.
According to cybersecurity company eSentire, malicious ads are used to spoof a wide range of legitimate apps and services such as Adobe, OpenAPI's ChatGPT, Spotify, Tableau, and Zoom.
BATLOADER, as the name suggests, is a loader that's responsible for
10 March 2023
The White House has allocated a total of $3.1bn to cybersecurity infrastructure in its latest budget report. The document shows $145m of this figure will go toward making the CISA “more resilient and defensible.”
10 March 2023
Go programming language is a newer language that’s becoming more popular with malware programmers. It has proven to be versatile enough to develop all kinds of malware, including ransomware, stealers or remote access trojans (RATs).
10 March 2023
A smart intercom product made by Chinese company Akuvox is affected by more than a dozen vulnerabilities, including potentially serious flaws that can be exploited for spying.
10 March 2023
Media and entertainment sector organizations worldwide are under attack by the threat actor using the Linux version of the IceFire ransomware. SentinelLabs first made this observation and found that criminals abused a deserialization bug in IBM Aspera Faspex file sharing software, tracked as CVE-2022-47986. Its Windows version is known to spread via phishing messages.
10 March 2023
EXECUTIVE SUMMARY: Let’s out-innovate ransomware! Thanks to the latest technological advancements and expert insights, you might be closer to achieving this goal than you think. Stop next-generation attacks and their culprits. In the past 30 years, ransomware attacks have proliferated at a dizzying pace, victimizing millions of organizations and causing billions of dollars in losses. […]
The post Top insights from the most notorious ransomware attacks & attackers appeared first on CyberTalk.
10 March 2023
The Imperva Red Team discovered a vulnerability affecting the world’s largest NFT marketplace, OpenSea. It is a cross-site search (XS-Search) vulnerability that can be exploited by an attacker to obtain a user’s identity.
10 March 2023
The budget proposes $3.1 billion for the CISA. This includes “$98 million to implement the Cyber Incident Reporting for Critical Infrastructure Act,” as well as “$425 million to improve CISA’s internal cybersecurity and analytical capabilities.”
10 March 2023
If a malicious hacker were to discover the flaw, they could exploit it to access customer data, steal the company’s source code, and look for other vulnerabilities to exploit.
10 March 2023
This line of credit will further strengthen the company's financial position as it continues on its mission to be the first and only solution provider to verify 100% of good identities in real-time and eliminate identity fraud on the internet.
10 March 2023
Prometei, first observed in 2016, is a modular botnet that features a large repertoire of components and several proliferation methods, some of which also include the exploitation of ProxyLogon Microsoft Exchange Server flaws.
10 March 2023
They do this using custom-created gaming apps that promise huge financial rewards directly proportional to investments to potential targets they've established trust with beforehand in lengthy online conversations.
10 March 2023
Zscaler ThreatLabz has identified significant code similarities between Nevada and Nokoyawa ransomware including debug strings, command-line arguments, and encryption algorithms
10 March 2023
EXECUTIVE SUMMARY: Hackers harvest, weaponize and sell corporate and personal passwords in order to obtain financial reward, damage reputations, steal intellectual property, or for other illegal undertakings. According to cyber security researchers, 80% of hacks involve the theft or reuse of employee passwords. This is in no small part due to lack of employee education […]
The post 20 password management best practices 2023 appeared first on CyberTalk.
10 March 2023
A North Korean espionage group tracked as UNC2970 has been observed employing previously undocumented malware families as part of a spear-phishing campaign targeting U.S. and European media and technology organizations since June 2022.
10 March 2023
The 2023 Security 360: Annual Trends Report by Jamf examines the top security threats that impact devices used in the modern workplace.
10 March 2023
The 2023 Security 360: Annual Trends Report by Jamf examines the top security threats that impact devices used in the modern workplace.