Latest Cybersecurity News and Articles


Information of European Hotel Chain’s Customers Found on Unprotected Elasticsearch Server

03 March 2023
An analysis conducted by researcher Anurag Sen at CloudDefense.AI showed that the exposed Falkensteiner customer data was associated with Gustaffo, a company offering IT solutions for the hospitality industry.

Hackers Steal Gun Owners' Data From Firearm Auction Website

03 March 2023
The breach exposed reams of sensitive personal data for more than 550,000 users, including customers’ full names, home addresses, email addresses, plaintext passwords, and telephone numbers.

British Retail Chain WH Smith Says Data Stolen in Cyberattack

03 March 2023
Individuals confirmed to be impacted by the incident will be notified directly. WH Smith says that special measures to support them will be put in place. This presumably will include identity protection services.

White House Unveils New National Cybersecurity Strategy

03 March 2023
The new strategy has five pillars: Defend critical infrastructure; Target and disrupt threat actors; Use market forces to improve security and resilience; Invest in resilience; and Enhance international partnerships.

Unpatched, known vulnerabilities still key driver of cyberattacks

03 March 2023
Vulnerabilities associated with Microsoft Exchange Server and some virtual private networks, many of which were first disclosed in 2017, continue to be a popular route for hackers to exploit, a report from exposure management company Tenable found.

New Flaws in TPM 2.0 Library Pose Threat to Billions of IoT and Enterprise Devices

03 March 2023
A pair of serious security defects has been disclosed in the Trusted Platform Module (TPM) 2.0 reference library specification that could potentially lead to information disclosure or privilege escalation. One of the vulnerabilities, CVE-2023-1017, concerns an out-of-bounds write, while the other, CVE-2023-1018, is described as an out-of-bounds read. Credited with discovering and reporting the

Update: Chick-fil-A confirms accounts hacked in months-long "automated" attack

03 March 2023
American fast food chain Chick-fil-A has confirmed that customers' accounts were breached in a months-long credential stuffing attack, allowing threat actors to use stored rewards balances and access personal information.

Chinese Hackers Targeting European Entities with New MQsTTang Backdoor

03 March 2023
The China-aligned Mustang Panda actor has been observed using a hitherto unseen custom backdoor called MQsTTang as part of an ongoing social engineering campaign that commenced in January 2023. "Unlike most of the group's malware, MQsTTang doesn't seem to be based on existing families or publicly available projects," ESET researcher Alexandre Côté Cyr said in a new report. Attack chains

Mobile Malware Landscape 2022 - Kaspersky Report

03 March 2023
A new report by Kaspersky states that almost 200,000 new mobile banking trojans surfaced in 2022, marking a 100% increase from 2021, with China being the most affected, followed by Syria and Iran. RiskTool-type potentially unwanted software accounted for the most distributions at 27.39%, followed by adware at 24.05% and trojan-type malware at 15.56%.

Gitpod flaw shows cloud-based development environments need security assessments

03 March 2023
The vulnerability found by Snyk, which the Gitpod team addressed within a day, is tracked as CVE-2023-0957 and falls into a category of issues known as cross-site WebSocket hijacking.

EU Data Protection Board Casts Doubt on Privacy Framework

03 March 2023
The European Data Protection Board on Tuesday published an analysis of the framework, lauding "substantial improvements" but simultaneously expressing "concerns" and requesting "clarifications on several points."

Multi-Year Spearphishing Campaign Targets the Maritime Industry Likely for Financial Gain

03 March 2023
Some of the emails likely used spoofed email addresses to appear as though they were sent from people within the same organization or from other maritime-related organizations.

HPE Buys SSE Firm Axis Security to Obtain Single-Vendor SASE

03 March 2023
Hewlett Packard Enterprise will soon offer its customers single-vendor SASE after agreeing to purchase a security service edge startup founded by a Symantec security researcher.

Critical Vulnerabilities Allowed Booking.com Account Takeover

03 March 2023
Security researchers discovered recently that the online travel agency Booking.com was impacted by serious vulnerabilities that could have been exploited to take complete control of a user’s account.

U.S. Cybersecurity Agency Raises Alarm Over Royal Ransomware's Deadly Capabilities

03 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory about Royal ransomware, which emerged in the threat landscape last year. "After gaining access to victims' networks, Royal actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting the systems," CISA said. The custom ransomware

Blind Eagle Re-appears in a Phishing Campaign to Target Colombian Entities

03 March 2023
BlackBerry researchers spotted the APT-C-36 threat group, aka Blind Eagle, masquerading as a Colombian government tax agency to target financial, health, immigration, and law enforcement sectors. Based on the infection vector and other tactics, researchers believed that the campaign targeted some organizations in Chile, Spain, and Ecuador.

Phishing is what type of attack? Definition, trends and best practices

03 March 2023
By George Mack, Content Marketing Manager, Check Point. Phishing threats have been making waves in the threat landscape, as they are responsible for more than 80% of security incidents. However, with all the cyber terminology thrown around, such as malware, hacks, and data loss – how do we classify phishing threats? Phishing attacks are social […] The post Phishing is what type of attack? Definition, trends and best practices appeared first on CyberTalk.

Highlights from the New U.S. Cybersecurity Strategy

02 March 2023
The Biden administration today issued its vision for beefing up the nation's collective cybersecurity posture, including calls for legislation establishing liability for software products and services that are sold with little regard for security. The White House's new national cybersecurity strategy also envisions a more active role by cloud providers and the U.S. military in disrupting cybercriminal infrastructure, and names China as the single biggest cyber threat to U.S. interests.

7 likely scenarios: How cyber security will change in 2023

02 March 2023
 By Isla Sibanda, an ethical hacker and cyber security specialist based out of Pretoria. For over twelve years, she’s worked as a cyber security analyst and penetration testing specialist for several major companies – including Standard Bank Group, CipherWave, and Axxess. Social engineering scams target roughly one hundred million people annually, resulting in astronomical amounts […] The post 7 likely scenarios: How cyber security will change in 2023 appeared first on CyberTalk.

Major Phishing Campaign Targets Trezor Crypto Wallets

02 March 2023
“The attackers contact the victims via phone call, SMS and/or email to say that there’s been a security breach or suspicious activity on their Trezor account,” the firm warned in a Twitter post.