Latest Cybersecurity News and Articles
06 March 2023
EclecticIQ has revealed that a single connected threat cluster is most likely behind an attack campaign targeting the maritime industry with spearphishing emails to distribute different malware threats. In July 2022, the campaign shifted from Agent Tesla to Formbook using CAB file attachments. However, there’s not much clarity on why the cluster changed its tooling.
06 March 2023
EXECUTIVE SUMMARY: In recent years, protecting critical infrastructure entities has been synonymous with ensuring the continued operations of governments and economies. In the United States, a CISA Red Team was recently granted permission to conduct a stealthy three-month attack on a critical infrastructure organization to assess the group’s cyber security posture. The Red Team gained […]
The post CISA red-teamed a ‘large critical infrastructure’ organization, no one noticed appeared first on CyberTalk.
06 March 2023
Researchers uncovered a new LockBit ransomware campaign last December and January using a novel technique involving the use of a .img container to bypass the Mark of The Web (MOTW) protection mechanism. LockBit remained one of the most active ransomware families in successful RaaS and extortion attacks for the second and third quarters of 2022.
06 March 2023
Hackers in the underground marketplace have introduced a new Exfiltrator-22, or EX-22, post-exploitation framework. According to the CYFIRMA team, LockBit 3.0 affiliates or its members are most probably behind its development. The developers have used the same C2 infrastructure previously exposed in a LockBit 3.0 sample. In the latest instance, criminals displayed lateral movement and ransomware-spreading capabilities.
06 March 2023
According to a Tenable report, the number one group of most frequently exploited vulnerabilities represents a large pool of known vulnerabilities, some of which were originally disclosed as far back as 2017.
06 March 2023
RIG EK continues to make its mark as a successful exploit kit as it attempted to make roughly 2,000 intrusions daily, with the highest attack success rate of its lifetime of 30%. By exploiting relatively old Internet Explorer vulnerabilities, the exploit kit has been seen distributing various types of malware such as Dridex, SmokeLoader, and Raccoon Stealer.
06 March 2023
Tracking devices are a boon to organizations with vast logistical operations and anyone who has ever lost a set of car keys. But trackers can also be a nightmare for cybersecurity, opening up a whole new world of opportunity for intruders.
06 March 2023
While there was a reduction in the widespread exploitation of new vulnerabilities in 2022, the risk remains significant as broad and opportunistic attacks continue to pose a threat, according to Rapid7.
06 March 2023
Keith Anderson has been named CISO at JetBlue. Anderson will work to ensure the company’s data, systems and other assets remain protected.
06 March 2023
Municipal CISOs grapple with challenges as they become targets for nation-state threat actors, cope with regulations, and pursue funding from resource-constrained governments.
06 March 2023
The new hacking campaign, which started in July 2022 and is still ongoing, relies on three components: a malicious bash script, a malware named "HiatusRAT," and the legitimate 'tcpdump,' used to capture network traffic flowing over the router.
06 March 2023
A global threat report analyzed the trends and behaviors of recent cyberattacks finding that attacks had increased in both number and complexity.
06 March 2023
There were 311 vulnerabilities in the catalog at the beginning of 2022 and it reached 868 by the end of the year. On average, more than ten exploited flaws were added to the KEV list every week in 2022.
06 March 2023
EXECUTIVE SUMMARY: In this edited interview excerpt from CRN, a media brand of The Channel Company, Check Point CEO Gil Shwed discusses emerging cyber threats, corporate technological advancement strategies, and Check Point’s innovation around security products. Don’t miss this. And if you like what you read, please be sure to read the full interview. What is […]
The post Check Point CEO talks emerging cyber threats & advancement strategies (2023) appeared first on CyberTalk.
06 March 2023
92% of the most popular banking and financial services apps contain easy-to-extract secrets and vulnerabilities that can let attackers steal consumer data and finances, according to Approov.
06 March 2023
The operation consisted in raiding multiple locations in the two countries in February and was the result of a coordinated effort that also involved Europol, the FBI, and the Dutch Police.
06 March 2023
Online counseling service BetterHelp has received a proposed order from the FTC banning the company from sharing users' private health information.
06 March 2023
Last month, Flutterwave, Africa’s largest startup by private valuation, was involved in a hack that resulted in over ?2.9 billion (~$4.2 million) missing from its accounts, according to local tech publication Techpoint Africa.
06 March 2023
A never-before-seen complex malware is targeting business-grade routers to covertly spy on victims in Latin America, Europe, and North America at least since July 2022.
The elusive campaign, dubbed Hiatus by Lumen Black Lotus Labs, has been found to deploy two malicious binaries, a remote access trojan dubbed HiatusRAT and a variant of tcpdump that makes it possible to capture packet capture on
06 March 2023
Deep fakes are expected to become a more prominent attack vector. Here's how to identify them.
What are Deep Fakes?
A deep fake is the act of maliciously replacing real images and videos with fabricated ones to perform information manipulation. To create images, video and audio that are high quality enough to be used in deep fakes, AI and ML are required. Such use of AI, ML and image replacement