Latest Cybersecurity News and Articles


6 dangerous cyber security vulnerabilities to watch for in 2023

22 February 2023
Contributed by George Mack, Content Marketing Manager, Check Point Software. What is a cyber security vulnerability? A cyber security vulnerability is a weakness in a computer system that malicious actors exploit to gain unauthorized access to sensitive data or resources. These vulnerabilities can exist in various aspects of a system, and can be found in […] The post 6 dangerous cyber security vulnerabilities to watch for in 2023 appeared first on CyberTalk.

Earth Kitsun Return to Target Selected Entities in China and Japan

22 February 2023
Trend Micro reported about a new threat actor that would drop a new backdoor dubbed WhiskerSpy. The cybercriminal group, tracked as Earth Kitsune, is a relatively new threat group that conducts watering hole attacks. The malware is delivered to users when they attempt to watch videos on attacker-compromised websites.

Over 90% of CISOs report frequent 40+ hour work weeks

22 February 2023
A report found that CISOs had high levels of workplace stress. The survey featured small to midsize businesses with teams of five employees or less.

Hackers Ran Amok Across GoDaddy for Three Years

22 February 2023
Internet domain registrar GoDaddy revealed that it has been the victim of a three-year-long campaign that deployed malware on internal systems and pilfered source code. Experts detected that an unauthorized third party had gained access to the company's cPanel hosting servers and installed malware. This resulted in random customer websites being intermittently redirected to malicious sites.

R1Soft Server Backup Manager Vulnerability Exploited to Deploy Backdoor

22 February 2023
During a recent incident response case, Fox-IT found evidence that the R1Soft vulnerability was exploited to gain initial access to a server. The attackers then deployed a malicious database driver that gave them backdoor access.

A Deep Dive into the Evolution of Ransomware Part 1

22 February 2023
Ransomware extortion tactics range from publishing data bit by bit in an attempt to increase pressure on targets through more aggressive measures, making these threats all the harder for organizations and individuals alike to protect against.

ChatGPT is on fire & the AI “gold rush” is here

22 February 2023
EXECUTIVE SUMMARY: This year will be the “Year of AI,” said Founder and CEO of Check Point, Gil Shwed, during a recent keynote presentation. Conversational AI-based chatbots have been around for years, but the release of ChatGPT made every other existent chatbot look like a lumbering dinosaur. Seen as an industry disruptor, ChatGPT also kicked […] The post ChatGPT is on fire & the AI “gold rush” is here appeared first on CyberTalk.

Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers

22 February 2023
ETW is a high-speed tracing facility built into the Windows operating system. It enables the logging of events and system activities by applications, drivers, and the operating system.

Accidental WhatsApp account takeovers? It's a thing

22 February 2023
A stranger may be receiving your private WhatsApp messages, and also be able to send messages to all of your contacts – if you have changed your phone number and didn't delete the WhatsApp account linked to it.

Multilingual Skimmer Fingerprints 'Secret Shoppers' via Cloudflare Endpoint API

22 February 2023
The skimmer uses iframes that are loaded if the current page is the checkout and if the browser's local storage does not include a font item (this is equivalent to using cookies to detect returning visitors).

Google will boost Android security through firmware hardening

22 February 2023
Google has started working to harden the security of Android at the firmware level, a component of the software stack that interacts directly with the various processors of a system on a chip (SoC).

Entitle Nabs $15M Seed Funding for Cloud Permissions Management Tech

22 February 2023
The Israeli security startup has attracted $15 million in early-stage venture capital funding from Glilot Capital Partners to build technology to address entitlement sprawl in the enterprise.

Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header

22 February 2023
During a recent customer pilot, Praetorian researchers identified an interesting method to bypass the cross-site scripting (XSS) filtering functionality within the Akamai Web Application Firewall (WAF) solution.

Metomic Lands $20 Series A for Data Security Platform

22 February 2023
The London-based company said the $20 million financing was led by Evolution Equity Partners. Venture capital firms Resonance and Connect Ventures also joined as investors.

Hackers Exploit Privilege Escalation Flaw on Windows Backup Service

22 February 2023
The high-severity vulnerability has a CVSS base score of 7.1 and affects Windows 7, 10, and 11 OS versions. It was patched by Microsoft in its first Patch Tuesday of 2023.

Most ransomware blocked last year, but cyberattacks are moving faster

22 February 2023
The latest annual IBM X-Force Threat Intelligence Index released today reported that deployment of backdoor malware, which allows remote access to systems, emerged as the top action by cyberattackers last year.

Sensitive US Military Emails Spilled Online via Exposed Azure Government Cloud Server

22 February 2023
The exposed server was part of an internal mailbox system storing about three terabytes of internal military emails, many pertaining to U.S. Special Operations Command (USSOCOM), the military unit tasked with conducting special military operations.

Apple Warns of 3 New Vulnerabilities Affecting iPhone, iPad, and Mac Devices

22 February 2023
Apple has revised the security advisories it released last month to include three new vulnerabilities impacting iOS, iPadOS, and macOS. The first flaw is a race condition in the Crash Reporter component (CVE-2023-23520) that could enable a malicious actor to read arbitrary files as root. The iPhone maker said it addressed the issue with additional validation. The two other vulnerabilities,

Most vulnerabilities associated with ransomware are old

22 February 2023
In a new report from Cyber Security Works (CSW), Ivanti, Cyware, and Securin, researchers identified 56 new vulnerabilities associated with ransomware threats among a total of 344 threats identified in 2022 – marking a 19% increase year-over-year.

More Supply Chain Attacks via New Malicious Python Packages in PyPi

22 February 2023
The FortiGuard Labs team discovered another 0-day attack in the PyPI packages (Python Package Index) by the malware authors ‘Portugal’ and ‘Brazil’ who published the packages ‘xhttpsp’ and ‘httpssp’.