Latest Cybersecurity News and Articles
02 March 2023
Security researchers at Quarkslab have identified a pair of serious security defects in the Trusted Platform Module (TPM) 2.0 reference library specification, prompting a massive cross-vendor effort to identify and patch vulnerable installations.
02 March 2023
Over the weekend, an attacker was found uploading thousands of malicious Python packages to the public PyPI software repository. If executed on a Windows system, these packages will download and install a Trojan program hosted on Dropbox.
02 March 2023
“Certain data was extracted,” the company said in a statement Tuesday. The acknowledgment is an evolution from last week’s earnings call, where it was described as an “internal outage.”
02 March 2023
Because of its age, patching the vulnerabilities does not appear to be a priority for the game’s publisher Activision, so two gamers-turned-hackers have taken it into their own hands to patch the game’s vulnerabilities and make it safer to play.
02 March 2023
Successful attacks on systems no longer require zero-day exploits, as attackers now focus on compromising identities through methods such as bypassing MFA, hijacking sessions, or brute-forcing passwords, according to Oort.
02 March 2023
The vulnerability, tracked as CVE-2023-20078, is rated 9.8 out of 10 on the CVSS scoring system and is described as a command injection bug in the web-based management interface arising due to insufficient validation of user-supplied input.
02 March 2023
The threat actor known as Lucky Mouse has developed a Linux version of a malware toolkit called SysUpdate, expanding on its ability to target devices running the operating system.
The oldest version of the updated artifact dates back to July 2022, with the malware incorporating new features designed to evade security software and resist reverse engineering.
Cybersecurity company Trend Micro said
02 March 2023
A new malware stealer called WhiteSnake has surfaced to steal credit card numbers and other sensitive information from Windows and Linux users. The Windows variant, comparatively an older and mature variant, is capable of stealing sensitive data from different browsers. The info-stealer can steal files from various cryptocurrency wallets such as Atomic, Bitcoin, Coinomi, Electrum, Exodus, and Guarda.
01 March 2023
Cisco on Wednesday rolled out security updates to address a critical flaw impacting its IP Phone 6800, 7800, 7900, and 8800 Series products.
The vulnerability, tracked as CVE-2023-20078, is rated 9.8 out of 10 on the CVSS scoring system and is described as a command injection bug in the web-based management interface arising due to insufficient validation of user-supplied input.
Successful
01 March 2023
A recent report analyzed medium and small businesses' email security solutions' popularity and incidence defense between 2018 and 2022.
01 March 2023
SaaS report quantifies the volume, types and exposure risk of business assets stored within the SaaS estates of medium and large companies.
01 March 2023
EXECUTIVE SUMMARY: As cyber threats continue to evolve and become increasingly sophisticated, it is critical for organizations to share threat intelligence to stay ahead of potential attacks. However, sharing sensitive information can be a challenge, as doing so requires a balance between the actual sharing of information and the need to protect it. This is […]
The post Leveraging the Traffic Light Protocol helps CISOs share threat data effectively appeared first on CyberTalk.
01 March 2023
A stealthy Unified Extensible Firmware Interface (UEFI) bootkit called BlackLotus has become the first publicly known malware capable of bypassing Secure Boot defenses, making it a potent threat in the cyber landscape.
01 March 2023
2022 was the second-highest year on record for global ransomware attempts, as well as an 87% increase in IoT malware and a record number of cryptojacking attacks (139.3 million), according to SonicWall.
01 March 2023
Several industrial IoT (IIoT) software products made by PTC are affected by two critical vulnerabilities that can be exploited for denial-of-service (DoS) attacks and remote code execution.
01 March 2023
Immuta, a Boston, MA-based data security company, received an additional strategic investment from ServiceNow. The investment, which was in addition to the Series E funding round, will allow the company to continue growing its cloud offering.
01 March 2023
Six different law firms were targeted in January and February 2023 as part of two disparate threat campaigns distributing GootLoader and FakeUpdates (aka SocGholish) malware strains.
GootLoader, active since late 2020, is a first-stage downloader that's capable of delivering a wide range of secondary payloads such as Cobalt Strike and ransomware.
It notably employs search engine optimization (
01 March 2023
In 2022, Trend Micro researchers noticed that they updated SysUpdate, one of their custom malware families, to include new features and add malware infection support for the Linux platform.
01 March 2023
Researchers from FortiGuard Labs observed a new LockBit ransomware campaign during December 2022 and January 2023 using a combination of techniques effective against AV and EDR solutions.
01 March 2023
A misconfigured database has exposed test and personal data belonging to over 700,000 users of the websites getshow.io (an all-in-one video marketing platform) and animaker.com (a DIY video animation software).