Latest Cybersecurity News and Articles


SolarWinds Announces Upcoming Patches for High-Severity Vulnerabilities

18 February 2023
Out of a total of seven security defects, five are described as deserialization of untrusted data issues that could be exploited to achieve command execution. Four of them have a CVSS score of 8.8.

GoDaddy Discloses Multi-Year Security Breach Causing Malware Installations and Source Code Theft

18 February 2023
Web hosting services provider GoDaddy on Friday disclosed a multi-year security breach that enabled unknown threat actors to install malware and siphon source code related to some of its services. The company attributed the campaign to a "sophisticated and organized group targeting hosting services." GoDaddy said in December 2022, it received an unspecified number of customer complaints about

WordPress sites backdoored with ad fraud plugin

18 February 2023
About 50 WordPress blogs have been backdoored with a plugin called fuser-master. This plugin is being triggered via popunder traffic from a large ad network. The WordPress sites are loaded on a separate page underneath and display a number of ads.

Analysis of New CatB Ransomware Variant

18 February 2023
CatB is a reasonably new entrant to the ransomware field, with samples only dating back to December 2022. The CatB threat actor does not offer a web portal (on TOR or otherwise) to name and shame victims.

Fortinet fixes critical RCE flaws in FortiNAC and FortiWeb

18 February 2023
Fortinet has released security updates for its FortiNAC and FortiWeb products, addressing two critical-severity vulnerabilities that may allow unauthenticated attackers to perform arbitrary code or command execution.

New Protections for Food Benefits Stolen by Skimmers

17 February 2023
Millions of Americans receiving food assistance benefits just earned a new right that they can't yet enforce: The right to be reimbursed if funds on their Electronic Benefit Transfer (EBT) cards are stolen by card skimming devices secretly installed at cash machines and grocery store checkout lanes.

Federal government announces new disruptive technology strike force

17 February 2023
Federal disruptive technology strike force aims to defend against illicit actors, strengthen supply chains and protect critical technological assets.

Hackers Using Google Ads to Spread FatalRAT Malware Disguised as Popular Apps

17 February 2023
A majority of the victims are located in Taiwan, China, and Hong Kong, followed by Malaysia, Japan, the Philippines, Thailand, Singapore, Indonesia, and Myanmar. The attackers' end goals are unclear as yet.

ChatGPT Subs In as Security Analyst, Hallucinates Only Occasionally

17 February 2023
A number of experiments suggest ChatGPT could be useful to help defenders triage potential security incidents and find security vulnerabilities in code, even though it was not specifically trained for such activities, according to recent studies.

Atlassian Says Leaked Data Stolen via Third-Party App

17 February 2023
A threat group called SiegedSec recently posted a cache of employee and operations information allegedly stolen from software workforce collaboration tool provider Atlassian.

The US Government’s Open Source Security Policy Discussed

17 February 2023
With a reliance on volunteers and committed contributors to manage vulnerabilities in the open-source ecosystem, there are often disparities in the extent to which codes are maintained, if at all.

Experts Warn of RambleOn Android Malware Targeting South Korean Journalists

17 February 2023
Suspected North Korean nation-state actors targeted a journalist in South Korea with a malware-laced Android app as part of a social engineering campaign. The findings come from South Korea-based non-profit Interlab, which coined the new malware RambleOn. The malicious functionalities include the "ability to read and leak target's contact list, SMS, voice call content, location and others from

Hackers Leverage PayPal to Send Malicious Invoices

17 February 2023
“This is different from the plenty of attacks we’ve seen that spoof PayPal. This is a malicious invoice that comes directly from PayPal,” reads an advisory by Avanan published earlier today.

Researchers Discover Account Takeover Flaw in Popular NPM Package With Millions of Downloads

17 February 2023
"The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password," software supply chain security company Illustria said in a report.

Are cyber risks higher in different geographical areas?

17 February 2023
By Devin Partida, Editor-in-Chief, Rehack.com. Addressing cyber risks is rarely a cut-and-dry experience. Cyber security is constantly evolving and shifting to face new threats and actors worldwide. Much of the action occurs on the digital playing field, but can the physical location of a business or organization increase the number of cyber attacks? With clarity on […] The post Are cyber risks higher in different geographical areas? appeared first on CyberTalk.

Burton Snowboards Cancels Online Orders After 'Cyber Incident'

17 February 2023
"Burton recently experienced a cyber incident, which is impacting some of our operations. We are working closely with third-party specialists to investigate the incident and determine the full nature and scope," Burton said.

Ransomware gangs force cybersecurity teams to reassess

17 February 2023
Just as LockBit 3.0 replaced Conti in 2022, newcomers such as BlackBasta, BianLian, and new-kid-on-the-block Royal are now all seriously vying for LockBit's crown in 2023.

New Frebniis Malware Abuses Microsoft IIS Feature to Establish Backdoor

17 February 2023
Frebniis ensures Failed Request Tracing is enabled and then accesses w3wp.exe (IIS) process memory, obtaining the address of where the Failed Request Event Buffering code (iisfreb.dll) is loaded.

Pending National Cyber Strategy to Feature ‘Strong Stand’ on Quantum Cryptography

17 February 2023
Ahead of the release of the first National Cybersecurity Strategy from the White House Office of the National Cyber Director, Dylan Presman, the director for budget and assessment, confirmed that it will include guidance on post-quantum cryptography.