Latest Cybersecurity News and Articles


Hacker Claims to Sell 160GB Trove of Stolen Confidential Data From Acer

07 March 2023
The list of stolen data included confidential slides and presentations, technical manuals, Windows Imaging Format files, binaries of various types, backend infrastructure data, product model documentation, and information about various devices.

Two-Thirds of European Firms Have Started Zero Trust

07 March 2023
Over two-thirds of European organizations have begun developing a zero trust strategy, up from around a quarter in 2020, according to Forrester. The analyst house said a further 15% were planning to adopt zero trust tech.

Sandbox Blockchain Game Breached to Send Emails Linking to Malware

07 March 2023
The Sandbox blockchain game is warnings its community that a security incident caused some users to receive fraudulent emails impersonating the game, trying to infect them with malware.

Transparent Tribe Hackers Distribute CapraRAT via Trojanized Messaging Apps

07 March 2023
A suspected Pakistan-aligned advanced persistent threat (APT) group known as Transparent Tribe has been linked to an ongoing cyber espionage campaign targeting Indian and Pakistani Android users with a backdoor called CapraRAT. "Transparent Tribe distributed the Android CapraRAT backdoor via trojanized secure messaging and calling apps branded as MeetsApp and MeetUp," ESET said in a report

RansomHouse Ransomware Attack Hit Hospital Clinic de Barcelona

07 March 2023
“The hospital’s press department said that all written work was being done on paper and that the hospital was diverting new urgent cases to other hospitals in the city,” states the Associated Press.

Why Healthcare Can't Afford to Ignore Digital Identity

07 March 2023
Investing in digital identity can improve security, increase clinical productivity, and boost healthcare's bottom line. — by Gus Malezis, CEO of Imprivata Digitalization has created immeasurable opportunities for businesses over the past two decades. But the growth of hybrid work and expansion of Internet of Things (IoT) has outpaced traditional 'castle and moat' cybersecurity, introducing

Ransomware Roundup – Sirattacker and ALC Ransomware

07 March 2023
Sirattacker is one of the latest Chaos ransomware variants. It was first released in the middle of February 2023. ALC is a recently reported ransomware. It is known for a message aimed at “Russia and its counterpart” in its ransom note.

Almost Half of Industrial Sector Computers Affected By Malware in 2022

07 March 2023
Two out of every five (40.6%) operational technology (OT) computers used in industrial settings have been affected by malware in 2022. The data comes from a report published earlier today by security researchers at Kaspersky.

Old Windows ‘Mock Folders’ UAC bypass used to drop malware

07 March 2023
A new phishing campaign targets organizations in Eastern European countries with the Remcos RAT malware with aid from an old Windows User Account Control bypass discovered over two years ago.

The Role of Marketing and PR in Incident Response

07 March 2023
Clear communication is essential. Communication strategies differ before and after a cyber incident. The way a company approaches both is as important as incident mitigation itself.

Vulnerability in DJI drones may reveal pilot’s location

07 March 2023
The researchers informed DJI of the 16 detected vulnerabilities prior to releasing the information to the public. In the course of the responsible disclosure process, the manufacturer has fixed these issues.

Suprbay.org, The Pirate Bay Web Forum Down amid Cyberattack

07 March 2023
The official forum of The Pirate Bay is the latest victim of an apparent cyberattack that forced its site to remain offline for several days. The forum allows users to request torrent reseeding and report malware found in torrent files.

Scammers Pose as ChatGPT in New Phishing Scam

07 March 2023
Bitdefender researchers have discovered a new phishing scam in which cybercriminals are redirecting unsuspecting users to a fake ChatGPT version. The primary targets were found in Ireland, Australia, Germany, Denmark, and the Netherlands.

Microsoft and MITRE developed a tool to prepare security teams for attacks on ML systems

07 March 2023
A new plug-in, created by Microsoft and MITRE, integrates various open-source software tools to aid cybersecurity professionals in bolstering their defenses against attacks on machine learning (ML) systems.

Update: Ransomware gang leaks data stolen from City of Oakland

07 March 2023
The Play ransomware gang has begun to leak data from the City of Oakland, California. The initial data leak consists of a 10GB multi-part RAR archive allegedly containing confidential documents, employee information, passports, and IDs.

Shein's Android App Caught Transmitting Clipboard Data to Remote Servers

07 March 2023
An older version of Shein's Android application suffered from a bug that periodically captured and transmitted clipboard contents to a remote server. The Microsoft 365 Defender Research Team said it discovered the problem in version 7.9.2 of the app that was released on December 16, 2021. The issue has since been addressed as of May 2022. Shein, originally named ZZKKO, is a Chinese online fast

LastPass Hack: Engineer's Failure to Update Plex Software Led to Massive Data Breach

07 March 2023
The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what's a sobering reminder of the dangers of failing to keep software up-to-date. The embattled password management service last week revealed how unidentified actors leveraged information stolen from an earlier incident that took place prior to August 12, 2022, along with

The evolving sophistication of social engineering attacks

06 March 2023
By Anas Baig, product manager and cyber security expert with Securiti. A social engineering attack is a type of cyber attack in which a threat actor attempts to manipulate people into performing certain actions or divulging confidential information, such as passwords and credit card details. These attacks often target unsuspecting users who do not realize […] The post The evolving sophistication of social engineering attacks appeared first on CyberTalk.

After Clasiopa, APT41 Targets Asian Materials Sector

06 March 2023
Symantec warned against the Chinese state-sponsored Winnti, aka APT41 and Blackfly, hacker group targeting two subsidiaries of an Asian conglomerate in the materials sector. The operation ran from late 2022 to early 2023, with a focus on intellectual property theft. Symantec has provided IOCs to detect and mitigate any threat due to the malicious activity of the Blackfly group.

Digital Smoke: Massive Investment Fraud Scam

06 March 2023
Resecurity identified Digital Smoke, one of the largest investment scam networks, that has been defrauding netizens mostly from Europe, Asia, and Australia. The attackers impersonate Fortune 100 firms from the U.S. and the U.K. Most of the fraudulent schemes pertained to financial services, EV and EV batteries, oil & gas, renewable energy, healthcare, semiconductors, as well as internationally renowned investment corporations and funds with global footprint.