Latest Cybersecurity News and Articles


Phishing Campaign Targets Job Seekers, Employers

06 March 2023
Threat actors are exploiting the ongoing economic downturn using job-themed phishing and malware campaigns to target job seekers and employers to steal sensitive information and hack company recruiters.

Security and IT Teams No Longer Need To Pay For SaaS-Shadow IT Discovery

04 March 2023
This past January, a SaaS Security Posture Management (SSPM) company named Wing Security (Wing) made waves with the launch of its free SaaS-Shadow IT discovery solution. Cloud-based companies were invited to gain insight into their employees' SaaS usage through a completely free, self-service product that operates on a "freemium" model. If a user is impressed with the solution and wants to gain

New FiXS ATM Malware Targeting Mexican Banks

04 March 2023
A new ATM malware strain dubbed FiXS has been observed targeting Mexican banks since the start of February 2023. "The ATM malware is hidden inside another not-malicious-looking program," Latin American cybersecurity firm Metabase Q said in a report shared with The Hacker News. Besides requiring interaction via an external keyboard, the Windows-based ATM malware is also vendor-agnostic and is

Thousands of Websites Hijacked Using Compromised FTP Credentials

04 March 2023
In many cases, the attackers managed to obtain highly secure auto-generated FTP credentials and used them to hijack the victim websites to redirect visitors to adult-themed content.

Microsoft releases Windows security updates for Intel CPU flaws

04 March 2023
The Mapped I/O side-channel vulnerabilities were initially disclosed by Intel on June 14th, 2022, warning that the flaws could allow processes running in a virtual machine to access data from another virtual machine.

Southeastern Louisiana University 'Likely' Suffered Cyber Attack

04 March 2023
Southeastern Louisiana University suffered a week-long outage of its website, email, or system for submitting assignments after a "potential incident" last week caused the university to shut down its network.

The U.S. CISA and FBI warn of Royal ransomware operation

04 March 2023
The FBI and the CISA released a joint Cybersecurity Advisory to provide organizations, tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with this ransomware family.

Play ransomware claims disruptive attack on City of Oakland

04 March 2023
The city’s authorities informed the public it had been targeted by a ransomware attack on February 10, 2023. It impacted all network systems except 911 dispatch, fire emergency services, and the city’s financial systems.

CISA Releases Decider Tool to Help with MITRE ATT&CK Mapping

03 March 2023
Decider makes the mapping process easier by asking the user a series of questions about the adversary’s activity in their network. The tool also provides search and filtering functionality, and allows users to export the results to common formats.

Over 50% of personal devices were exposed to a mobile phishing attack

03 March 2023
According to a recent report, mobile phishing is on the rise with 2022 having the highest percentage of mobile phishing encounter rates.

Vice Society publishes data stolen during Vesuvius ransomware attack

03 March 2023
The Vice Society ransomware gang has published on the dark web files that it stole from Vesuvius, one month after the company announced that it had suffered a “cyber incident.”

White House cyber security strategy shifts burden to providers

03 March 2023
EXECUTIVE SUMMARY: On Thursday, the White House released an ambitious and wide-ranging cyber security plan that calls for stronger security protections on behalf of critical sectors and that calls for making software firms legally accountable for product security. According to the strategy document, “all instruments of national power” will be used in order to pre-empt […] The post White House cyber security strategy shifts burden to providers appeared first on CyberTalk.

Hatch Bank Discloses Data Breach After GoAnywhere MFT Hack

03 March 2023
Fintech banking platform Hatch Bank has reported a data breach after hackers stole the personal information of almost 140,000 customers from the company's Fortra GoAnywhere MFT secure file-sharing platform.

Experts Identify Fully-Featured Info Stealer and Trojan in Python Package on PyPI

03 March 2023
The malware, besides performing defense evasion checks to determine if it's being executed in a sandbox, establishes persistence by means of a Visual Basic script and uses transfer[.]sh for data exfiltration.

Security leaders share thoughts on Biden's cyber strategy announcement

03 March 2023
Security leaders share thoughts on the National Cybersecurity Strategy released by the Biden Administration, designed to expand and improve standards.

Mustang Panda’s Latest 'MQsTTang' Backdoor Treads New Ground With Qt and MQTT

03 March 2023
This backdoor is part of an ongoing campaign that researchers can trace back to early January 2023. Unlike most of the group’s malware, MQsTTang doesn’t seem to be based on existing families or publicly available projects.

Poland Blames Russian Hackers for Cyberattack on Tax Service Website

03 March 2023
The distributed denial-of-service (DDoS) attack occurred on Tuesday, causing the website to crash for approximately one hour and blocking users’ access to the online tax filing system.

US Cybersecurity Strategy Shifts Liability Issues to Vendors

03 March 2023
A new federal strategy to make manufacturers liable for insecure software requires an attainable safe harbor policy and could be a disincentive for them in sharing important vulnerability info with the government, according to industry observers.

Cryptojacking Campaign Targets Insecure Deployments of Redis Servers

03 March 2023
Cado Labs researchers recently discovered a new cryptojacking campaign targeting insecure deployments of Redis database servers. Threat actors behind this campaign used the free and open source command line file transfer service transfer.sh.

Nigerian Citizen Gets 11-Year US Federal Sentence for Global BEC Scam

03 March 2023
A leader of an international crime network that attempted to launder more than $25 million in fraudulently obtained funds, including through business email compromise, received a sentence of more than a decade in prison.