Latest Cybersecurity News and Articles


North Korean UNC2970 Hackers Expands Operations with New Malware Families

10 March 2023
A North Korean espionage group tracked as UNC2970 has been observed employing previously undocumented malware families as part of a spear-phishing campaign targeting U.S. and European media and technology organizations since June 2022. Google-owned Mandiant said the threat cluster shares "multiple overlaps" with a long-running operation dubbed "Dream Job" that employs job recruitment lures in

OneNote Used as New Distribution Channel for Qakbot Malware

09 March 2023
Researchers observed a notable spike in emails utilizing malicious OneNote attachments, especially to drop Qakbot or QBot. Operators have apparently reorganized its infrastructure to target specific regions and industries.

Who’s Behind the NetWire Remote Access Trojan?

09 March 2023
A Croatian national has been arrested for allegedly operating NetWire, a Remote Access Trojan (RAT) marketed on cybercrime forums since 2012 as a stealthy way to spy on infected systems and siphon passwords. The arrest coincided with a seizure of the NetWire sales website by the U.S. Federal Bureau of Investigation (FBI). While the defendant in this case hasn’t yet been named publicly, the NetWire website has been leaking information about the likely true identity and location of its owner for the past 11 years.

EPA stresses the need for improved water cybersecurity

09 March 2023
The EPA is stressing the need to improve the cybersecurity of drinking water systems to better defend critical infrastructure from cyberattacks.

Beware! AI Generates a Truly Polymorphic Malware BlackMamba

09 March 2023
A BlackMamba proof-of-concept attack was demonstrated by researchers. The technology on which ChatGPT is built, the large language model (LLM), was used to create a polymorphic keylogger functionality on the fly. The malware was tested against a renowned EDR system and resulted in absolutely no alerts or detections.

Iran-linked hackers used fake Atlantic Council-affiliated persona to target human rights researchers

09 March 2023
It’s not clear if this particular persona’s efforts resulted in any successful phishing attacks. The Twitter account, created in October 2022, remains active. An Instagram account associated with the name is unavailable.

Researchers Uncover Email Threats From Exotic Lily

09 March 2023
Exotic Lily is an initial access broker who specializes in gathering credentials from high-value targets through employee impersonation, deep open-source intelligence (OSINT), and by creating convincing malicious documents.

Russian TA499 Targets North American and European Countries

09 March 2023
Russia-linked TA499 threat actor has been aggressively conducting email campaigns to target high-profile European and North American government authorities and CEOs of reputable organizations. The attack begins with an email or phone call, masquerading as prominent political figures. The phone call recordings are then released to the public via YouTube and RuTube.

Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX Malware

09 March 2023
In the attacks observed by ASEC, successful exploitation of the flaws is followed by the execution of a PowerShell command that retrieves an executable and a DLL file from a remote server.

Threat vectors converging, increasing damage

09 March 2023
The threat intelligence vendor Flashpoint warned that threat actors are increasingly combining known vulnerabilities, stolen credentials, and exposed data to wreak maximum damage.

China-Linked UNC4540 Hackers Infect Unpatched SonicWall Appliances With Info-Stealer

09 March 2023
Suspected Chinese cybercriminals have zeroed in on unpatched SonicWall gateways and are infecting the devices with credential-stealing malware that persists through firmware upgrades, according to Mandiant.

Anti-theft software solution developed for Hyundai and Kia users

09 March 2023
Theft deterrent software has been developed by Hyundai and Kia following online videos detailing how to start and steal the vehicles without a key.

Cado Security Banks $20M in Series B Funding

09 March 2023
The London-based company said Series B financing was led by Eurazeo, a French investment and asset management firm. Ten Eleven Ventures, a prior backer, also expanded its equity stake.

Bitwarden flaw can let hackers steal passwords using iframes

09 March 2023
Bitwarden's credentials autofill feature contains a risky behavior that could allow malicious iframes embedded in trusted websites to steal people's credentials and send them to an attacker.

Empowering women in cyber security: A CEO’s perspectives

09 March 2023
Meet the founder and CEO of ReynCon, Connie Matthews Reynolds. With more than two decades of experience in the cyber security industry, she has received much recognition for her work. As a founding member of EmpoWE-R Women of InfoSec, she encourages women and minorities to consider careers in cyber security and lives by the motto […] The post Empowering women in cyber security: A CEO’s perspectives appeared first on CyberTalk.

Hackers Exploiting Remote Desktop Software Flaws to Deploy PlugX Malware

09 March 2023
Security vulnerabilities in remote desktop programs such as Sunlogin and AweSun are being exploited by threat actors to deploy the PlugX malware. AhnLab Security Emergency Response Center (ASEC), in a new analysis, said it marks the continued abuse of the flaws to deliver a variety of payloads on compromised systems. This includes the Sliver post-exploitation framework, XMRig cryptocurrency

Germany could ban China's Huawei, ZTE from parts of 5G networks

09 March 2023
An interior ministry spokesperson on Tuesday confirmed that the German government was carrying out a general review of telecoms tech suppliers, but said that this was not directed at specific manufacturers.

Veeam warns to install patches to fix a bug in its Backup & Replication product

09 March 2023
An unauthenticated attacker can exploit the vulnerability to obtain the credentials stored in the VeeamVBR configuration database and use them to access backup infrastructure hosts.

RangeForce Raises $20 Million in Financing

09 March 2023
The Series B round was led by Energy Impact Partners and Paladin Capital Group, along with participation from KPN Ventures, Lapa Capital Partners, Lanx Capital, and Cisco Investments.

IceFire Ransomware Exploits IBM Aspera Faspex to Attack Linux-Powered Enterprise Networks

09 March 2023
A previously known Windows-based ransomware strain known as IceFire has expanded its focus to target Linux enterprise networks belonging to several media and entertainment sector organizations across the world. The intrusions entail the exploitation of a recently disclosed deserialization vulnerability in IBM Aspera Faspex file-sharing software (CVE-2022-47986, CVSS score: 9.8), according to