Latest Cybersecurity News and Articles


Hackers are quickly learning how to breach cloud systems

08 March 2023
Attacks exploiting cloud systems nearly doubled in 2022, and the number of hacking groups that can target the cloud tripled last year, according to a CrowdStrike report released last week.

Malicious PyPI Package Delivers Colour-Blind RAT

08 March 2023
Security researchers at Kroll laid bare a malicious PyPI package called Colour-Blind. The malware package is a fully-featured info-stealer RAT with a plethora of features and capabilities, including the theft of crypto wallet data. According to researchers, the malware "points to the democratization of cybercrime" to help adversaries develop their own variations based on the shared source code.

Syxsense Platform: Unified Security and Endpoint Management

08 March 2023
As threats grow and attack surfaces get more complex, companies continue to struggle with the multitude of tools they utilize to handle endpoint security and management. This can leave gaps in an enterprise's ability to identify devices that are accessing the network and in ensuring that those devices are compliant with security policies. These gaps are often seen in outdated spreadsheets that

Russia-Aligned TA499 Beleaguers Targets with Video Call Requests

08 March 2023
The threat actor’s campaigns attempt to convince high-profile North American and European government officials as well as CEOs of prominent companies and celebrities into participating in recorded phone calls or video chats.

ATM Malware FiXS Targets Mexican Banks to Dispense Quick Money

08 March 2023
Security analysts at Metabase Q uncovered the new FiXS ATM malware that targets Mexican bank customers. Though the initial attack vector is unclear as of now, analysts have discovered hackers using an external keyboard, like in Ploutus attacks. The FiXS malware releases money 30 minutes after the latest ATM reset, leveraging the Windows GetTickCount API.

Chinese State-Sponsored Hackers Break Into Mail Servers Used by ASEAN Members

08 March 2023
The Chinese threat actors reportedly leveraged “valid credentials” to compromise ASEAN’s Microsoft Exchange servers, which used mail.asean.org and auto.discover.asean.org domains.

Celebrating International Women’s Day: Creating awareness & driving change

08 March 2023
Ulrica is a VP of Product & Strategy at Indeni with over 30 years experience developing software in networking & security technologies. She loves explaining complex technology and building high-profile and high-performing teams.  In this exclusive CyberTalk interview, Ulrica shares a bit about how her passion for technology and solving challenging customer problems has driven […] The post Celebrating International Women’s Day: Creating awareness & driving change appeared first on CyberTalk.

Microsoft Found Shein App Copying Clipboard Content on Android Phones

08 March 2023
The app was found to send the contents of the clipboard to a remote server if a particular pattern was present, though it is not clear whether there was any malicious intent behind the behaviour.

Lazarus Group Exploits Zero-Day Vulnerability to Hack South Korean Financial Entity

08 March 2023
The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year. While the first attack in May 2022 entailed the use of a vulnerable version of a certificate software that's widely used by public institutions and universities, the re-infiltration in October 2022 involved the

Exposed Redis Database Servers Churned for Cryptojacking

08 March 2023
A cryptojacking operation was found using an authentic, open-source command-line file transfer service to carry out its attack against misconfigured Redis database servers. Although the objective of the campaign is to mine cryptocurrencies, the script performs several additional tasks to ensure the effective utilization of resources. It is imperative that administrators actively monitor any misconfigurations in Redis servers and fix them. 

BlackMamba: Using AI to Generate Polymorphic Malware

08 March 2023
Using AI-generated polymorphic malware, a threat actor can combine a series of typically highly detectable behaviors in an unusual combination and evade detection by exploiting the model’s inability to recognize it as a malicious pattern.

Chinese Hackers Target Asian and European Entities With MQsTTang

08 March 2023
As part of an ongoing social engineering campaign, the China-aligned Mustang Panda threat group has been seen using a previously unknown custom backdoor dubbed MQsTTang. It’s unclear who the cybercriminals are targeting. A rare observation in the implant is the use of MQTT, an IoT messaging protocol, for C2 communications.

Russia's Cyber Tactics in Ukraine Shift to Focus on Espionage

08 March 2023
This is according to Victor Zhora, deputy chairman and chief digital transformation officer of the SSSCIP of Ukraine, who explained the strategic change from disruptive attacks to cyber espionage to Infosecurity.

Emotet malware attacks return after three-month break

08 March 2023
The Emotet malware operation is again sending malicious spam emails as of Tuesday morning after a three-month break, rebuilding its network and infecting devices worldwide.

R3NIN Sniffer-as-a-Service Targets E-commerce Consumers

08 March 2023
Cybersecurity analysts at Cybel reported on R3NIN, an online skimmer, that pilfers payment card data and PII from unsuspecting individuals while they checkout from online shops. This toolkit has capabilities for creating unique JavaScript injection codes, managing exfiltrated data, managing compromised payment card info (across different browsers), checking BINs, parsing data, and generating statistics.

PayPal Ventures Invests in Threat Prevention Leader Deep Instinct

08 March 2023
Deep Instinct, the first company to apply deep learning to cybersecurity, today announced an investment from PayPal Ventures. The funding will help further accelerate Deep Instinct's growth, driven by its disruptive threat prevention technology.

CISA's KEV Catalog Updated with Three New Flaws Threatening IT Management Systems

08 March 2023
The most critical of the three is CVE-2022-35914, which concerns a remote code execution vulnerability in the third-party library htmlawed present in Teclib GLPI, an open-source asset and IT management software package.

BlackLotus UEFI Bootkit Bypasses Fully Patched Windows 11

08 March 2023
BlackLotus bootkit has been discovered interfering with UEFI Secure Boot, a crucial platform security feature, that can run even on fully up-to-date Windows 11 systems. The robust, persistent 80 KB toolkit was created in Assembly and C language. To prevent infecting computers in Armenia, Belarus, Kazakhstan, Moldova, Romania, Russia, and Ukraine, it also has geofencing capabilities.

Private Malware for Sale: A Closer Look at AresLoader

08 March 2023
In December 2022, a private loader named “AresLoader” was advertised for sale on the top-tier Russian-language hacking forum XSS by a threat actor going by the name “DarkBLUP”.

Sharp Panda Using New Soul Framework Version to Target Southeast Asian Governments

08 March 2023
High-profile government entities in Southeast Asia are the target of a cyber espionage campaign undertaken by a Chinese threat actor known as Sharp Panda since late last year. The intrusions are characterized by the use of a new version of the Soul modular framework, marking a departure from the group's attack chains observed in 2021. Israeli cybersecurity company Check Point said the "