Latest Cybersecurity News and Articles


Old Cybercrime Group '8220 Gang' Uses New ScrubCrypt Crypter to Dodge Defenses

09 March 2023
ScrubCrypt obfuscates and encrypts applications and makes them able to dodge security programs. It has an updated version, and the seller’s webpage guarantees that it can bypass Windows Defender and provide anti-debug and some bypass functions.

Australian official demands Russia bring criminal hackers ‘to heel’

09 March 2023
Michael Pezullo, currently serving as the secretary of the Department of Home Affairs, said the Russian Federation hosted “the greatest density of cybercriminals, particularly those with ransomware,” in the world.

Microsoft enables LSA protection by default in Windows Canary build

09 March 2023
LSA protection is crucial for safeguarding against the theft of sensitive information or login credentials by blocking untrusted code injection into the LSA process and blocking process memory dumping.

Does Your Help Desk Know Who's Calling?

09 March 2023
Phishing, the theft of users' credentials or sensitive data using social engineering, has been a significant threat since the early days of the internet – and continues to plague organizations today, accounting for more than 30% of all known breaches. And with the mass migration to remote working during the pandemic, hackers have ramped up their efforts to steal login credentials as they take

Iranian Hackers Target Women Involved in Human Rights and Middle East Politics

09 March 2023
Iranian state-sponsored actors are continuing to engage in social engineering campaigns targeting researchers by impersonating a U.S. think tank. "Notably the targets in this instance were all women who are actively involved in political affairs and human rights in the Middle East region," Secureworks Counter Threat Unit (CTU) said in a report shared with The Hacker News. The cybersecurity

FBI Investigates Data Breach Impacting U.S. House Members and Staff

09 March 2023
The FBI is investigating a data breach affecting U.S. House of Representatives members and staff after their account and sensitive personal information was stolen from DC Health Link's servers.

SANS, Google launch academy to promote cloud security, diversity in workforce

09 March 2023
To help tackle the skills deficit in cloud security, the SANS Institute and Google have launched a new academy focused on providing scholarship-based training for underrepresented groups.

Ransomware Group Says it Stole Student Data From Minneapolis Public Schools

09 March 2023
On March 7, the Medusa ransomware group added the school district to its list of victims, giving them 10 days to pay a ransom before data stolen from the school was leaked.

Illegal 'DeepStreamer' movie streaming platforms hide lucrative ad fraud operation

09 March 2023
DeepStreamer used different techniques to evade detection and forge traffic by surreptitiously loading “money sites” filled with Google ads completely hidden from view, while internet users were watching movies.

Update: Dole doesn’t expect to recover full costs of ransomware attack

09 March 2023
During a conference call on Tuesday, company executives were asked whether they could recover any of the disruption amounts later in the year through supplier recovery or insurance coverage.

MedusaLocker Distributes GlobeImposter Ransomware via RDP

09 March 2023
ASEC researchers have reported the active distribution of the GlobeImposter ransomware by the threat actors behind MedusaLocker that used remote desktop protocols as an attack vector. Besides other malware, hackers also deployed an XMRig CoinMiner to compromised systems. Security experts suggest users should ensure that RDP is deactivated when not in use.

New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access

09 March 2023
Fortinet has released fixes to address 15 security flaws, including one critical vulnerability impacting FortiOS and FortiProxy that could enable a threat actor to take control of affected systems.

SeigedSec hacking group defaces Faroe Islands tourist website, but kept out of government systems

09 March 2023
A hacking group defaced the tourist website for the Faroe Islands – a self-governing territory of the Kingdom of Denmark — and claimed it stole employee data and other sensitive information.

Mistakes by Threat Actors Lead to Disruption, Not Just Better Blocking

09 March 2023
Threat actors really only stop when their infrastructure is disrupted and their flow of funds disappears, and this normally can only be achieved through the activities of U.S. law enforcement agencies and major commercial data hosting providers.

TSA Requires Aviation Sector to Enhance Cybersecurity Resilience

09 March 2023
Airport and aircraft operators are required to develop a plan for improving their resilience and preventing infrastructure disruption and degradation. In addition, they need to assess the effectiveness of their measures.

New ScrubCrypt Crypter Used in Cryptojacking Attacks Targeting Oracle WebLogic

09 March 2023
The infamous cryptocurrency miner group called 8220 Gang has been observed using a new crypter called ScrubCrypt to carry out cryptojacking operations. According to Fortinet FortiGuard Labs, the attack chain commences with successful exploitation of susceptible Oracle WebLogic servers to download a PowerShell script that contains ScrubCrypt. Crypters are a type of software that can encrypt,

New Security Flaws in Jenkins Could Allow Code Execution Attacks

09 March 2023
The flaws, tracked as CVE-2023-27898 and CVE-2023-27905, impact the Jenkins server and Update Center, and have been collectively christened CorePlague by cloud security firm Aqua. All versions of Jenkins versions prior to 2.319.2 are vulnerable.

New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access

09 March 2023
Fortinet has released fixes to address 15 security flaws, including one critical vulnerability impacting FortiOS and FortiProxy that could enable a threat actor to take control of affected systems. The issue, tracked as CVE-2023-25610, is rated 9.3 out of 10 for severity and was internally discovered and reported by its security teams. "A buffer underwrite ('buffer underflow') vulnerability in

Purpose, direction and innovation: The mindset of a successful leader

08 March 2023
In her role as president and co-founder of Six Degrees Consulting, Molly actively oversees strategy, vision, marketing, professional services, human resources, and day-to-day operations. The company’s mission is to solve clients’ IT operational challenges and anticipate future needs, yet Molly has found that its true value to clients is the honesty and passion found in […] The post Purpose, direction and innovation: The mindset of a successful leader appeared first on CyberTalk.

Report: Collaboration is key to security optimization

08 March 2023
Report reveals good relationships, strong communication, & transparency are key factors in security collaborative optimization success.