Latest Cybersecurity News and Articles


APT27 Modified its Custom RAT to Target Linux Systems

08 March 2023
Iron Tiger, an APT organization, has updated its SysUpdate RAT by incorporating additional functionality and support for malware infection to target the Linux OS. Experts suspect APT27 used the chat app Youdu to send malicious links to the employees, luring them into downloading the initial infection payloads. Organizations are suggested to tighten up the vigilance of all entry points, including emails and IM with ant-malware and anti-phishing solutions. 

CISA's KEV Catalog Updated with 3 New Flaws Threatening IT Management Systems

08 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below - CVE-2022-35914 (CVSS score: 9.8) - Teclib GLPI Remote Code Execution Vulnerability CVE-2022-33891 (CVSS score: 8.8) - Apache Spark Command Injection Vulnerability

Parallax RAT Targets Crypto Companies via Process Hollowing

08 March 2023
Uptycs researchers spotted a new malware campaign targeting cryptocurrency companies with Parallax RAT. It can collect system metadata and data stored in the clipboard. Once the malware has been successfully injected, attackers interact with the victims by asking questions and sharing their Telegram ID via Notepad for further communication.

Ghosts of Vulnerabilities Past Still Haunt the Present

08 March 2023
According to VulnCheck, the KEV Catalog comprises 868 bugs, including 557 added in the past year. Among these, 241 have been abused by APT actors, 122 by ransomware gangs, and 69 by botnets. Another report by Tenable categorized significant vulnerability data to identify the most significant risks and disrupt attack paths, thereby reducing the overall exposure to cyberattacks.

New HiatusRAT Emerges to Infect Business-Grade Routers

08 March 2023
Experts at Lumen Black Lotus Labs stumbled across a campaign dubbed Hiatus dropping a pair of payloads to infect business routers. The payloads include HiatusRAT and a variant of tcpdump (which enables packet capture on the target device). With HiatusRAT, criminals can turn a compromised machine into a secret proxy system. Researchers identified at least 100 infected systems, with most of the infections in Europe and Latin America.

New Cyber Reports & Initiatives Target Key Vulnerabilities

08 March 2023
Two recently released reports highlight the increasing challenges faced by security practitioners, particularly those who have larger and more integrated systems between their IT and OT environments.

New Vulnerabilities in TPM 2.0 May Affect IoT and Enterprise Devices

07 March 2023
Researchers at Quarkslab unveiled two bugs in the Trusted Platform Module (TPM) 2.0 reference library specification. The attacks could potentially lead to information disclosure or privilege escalation. The first bug, CVE-2023-1017, concerns an out-of-bounds write while the other bug, CVE-2023-1018, is an out-of-bounds read issue. Billions of internet-connected devices across different organizations are vulnerable to the threat.

Breaking barriers: Insight’s investment in women’s leadership and board readiness

07 March 2023
Megan Amdahl is Senior Vice President of Partner Alliances & North America Transformation at Insight, a solutions integrator company that provides technical expertise and advisory services to help organizations accelerate their digital journeys and modernize their businesses. Megan is a finance leader with more than 10 years of diverse experience in financial planning and analysis, […] The post Breaking barriers: Insight’s investment in women’s leadership and board readiness appeared first on CyberTalk.

Sued by Meta, Freenom Halts Domain Registrations

07 March 2023
The domain name registrar Freenom, whose free domain names have long been a draw for spammers and phishers, has stopped allowing new domain name registrations. The move comes just days after the Dutch registrar was sued by Meta, which alleges the company ignores abuse complaints about phishing websites while monetizing traffic to those abusive domains.

Fighting back against cyber attacks on water systems

07 March 2023
EXECUTIVE SUMMARY: In the U.S., the government is requiring states to research and report on the cyber capabilities of drinking water utilities. This is part of the White House’s larger effort to protect the country’s critical infrastructure from nation-state cyber attacks and similarly dangerous threats. The new requirements were implemented by the Environmental Protection Agency […] The post Fighting back against cyber attacks on water systems appeared first on CyberTalk.

New SYS01stealer Threat Uses Facebook Ads to Target Critical Infrastructure Firms

07 March 2023
Morphisec has tracked an advanced info-stealer called SYS01stealer since November 2022. It uses similar lures and loading techniques to another information stealer recently named S1deload by Bitdefender, but the actual payload is different.

Vice Society Ransomware Group Claims Hamburg University of Applied Sciences as Latest Victim

07 March 2023
The university warned that “significant amounts of data from various areas” were copied, including usernames and “cryptographically secured” passwords, email addresses, and mobile phone numbers.

Transparent Tribe Lures Indian and Pakistani Officials With Romance Scam to Spread Malware

07 March 2023
ESET researchers have identified an active Transparent Tribe campaign, targeting mostly Indian and Pakistani Android users – presumably with a military or political orientation.

FCC proposes new data breach notification rules

07 March 2023
New data breach notification rules have been proposed by the FCC to strengthen the rules for notifying customers and law enforcement of breaches.

David Dunn named Chief Information Security Officer at Kroll

07 March 2023
David Dunn has been appointed as Kroll’s Chief Information Security Officer (CISO). Dunn succeeds Wayne Peterson, who recently retired.

Android’s March 2023 Updates Patch Over 50 Vulnerabilities

07 March 2023
The most severe of the patched vulnerabilities are two remote code execution (RCE) flaws in the System component, both of which were addressed as part of the 2023-03-01 security patch level.

Exploitation of Critical Vulnerability in End-of-Life VMware Product Ongoing

07 March 2023
Tracked as CVE-2021-39144 (CVSS score of 9.8), the issue was disclosed in October 2022, when VMware announced patches for it, although the affected product had reached end-of-life (EOL) status in January 2022.

SYS01stealer: New Threat Using Facebook Ads to Target Critical Infrastructure Firms

07 March 2023
Cybersecurity researchers have discovered a new information stealer dubbed SYS01stealer targeting critical government infrastructure employees, manufacturing companies, and other sectors. "The threat actors behind the campaign are targeting Facebook business accounts by using Google ads and fake Facebook profiles that promote things like games, adult content, and cracked software, etc. to lure

Brazilian Conglomerate Andrade Gutierrez Suffers 3TB Data Breach

07 March 2023
Hackers have stolen several terabytes of corporate and employee information from controversial Brazilian multi-national Andrade Gutierrez, in a raid the firm reportedly still hasn’t acknowledged.

Legislation introduced to protect personally identifiable health data

07 March 2023
The UPHOLD Privacy Act was introduced to the Senate to prevent companies from profiting off of identifiable health data for advertising purposes.