Latest Cybersecurity News and Articles
16 February 2023
EXECUTIVE SUMMARY: It’s exciting! We are finally getting back to traveling and gathering again, after several years of 100% virtual events. In 2023, take the opportunity to connect, learn and grow with mentors, experts, and industry leaders who you haven’t seen in years. You’ve expanded your knowledge and skills, they’ve expanded their knowledge and skills, […]
The post 10 top cyber security conferences of 2023 appeared first on CyberTalk.
16 February 2023
Skipping patching VMware ESXi bugs? Beware! Hundreds of systems in Europe were found infected with the ESXiArgs ransomware. Hackers reportedly abused a two-year-old RCE bug (CVE-2021-21974) and compromised thousands of servers across the world.
16 February 2023
There’s a new financially motivated campaign utilizing MortalKombat ransomware and the Laplas clipper. While the former is a variant of the Xortist commodity ransomware, the latter is a cryptocurrency hijacker that monitors the Windows clipboard for crypto addresses. The campaign’s focus remained on the U.S., with a handful of victims spread across the U.K, Turkey, and the Philippines.
16 February 2023
After surveying over 700 senior IT and cybersecurity leaders, a cybersecurity trends report revealed that risk management remained a concern.
16 February 2023
By Rachel Teitz, Technical Communications. ChatGPT, the chatbot launched by OpenAI in November 2022, is the hot new thing that everyone is talking about. As ChatGPT itself will tell you, it is “an AI language model capable of generating human-like text based on the input it is given.” Ask it a question, and it will […]
The post ChatGPT, the hackers’ new secret weapon appeared first on CyberTalk.
16 February 2023
A popular npm package with more than 3.5 million weekly downloads has been found vulnerable to an account takeover attack.
"The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password," software supply chain security company Illustria said in a report.
While npm's security protections limit users to have only one active email address
16 February 2023
The prolific SideWinder group has been attributed as the nation-state actor behind attempted attacks against 61 entities in Afghanistan, Bhutan, Myanmar, Nepal, and Sri Lanka between June and November 2021.
Targets included government, military, law enforcement, banks, and other organizations, according to an exhaustive report published by Group-IB, which also found links between the adversary
16 February 2023
The law firm Baker McKenzie has launched a class action lawsuit against Medibank over the health insurer’s massive cyber attack last year that resulted in the personal details of up to 10 million customers being posted on the dark web.
16 February 2023
These new guidelines will help set the course for best practices in handling digital identity for organizations across all sectors. The security risk around digital identities stems from verification.
16 February 2023
Among its most interesting capabilities, Havoc is cross-platform and it bypasses Microsoft Defender on up-to-date Windows 11 devices using sleep obfuscation, return address stack spoofing, and indirect syscalls.
16 February 2023
Silicon Valley investor Costanoa Ventures, one of the co-leads in its Series A, also co-led this recent Series B round with Africa-focused venture capital firm Norrsken22. Lexi Novitske, general partner at Norrsken22, will join the company’s Board.
16 February 2023
Cisco on Wednesday announced updates for endpoint, cloud, and web security products to address a critical vulnerability in the third-party open-source scanning library ClamAV.
16 February 2023
Russian national Vladislav Klyushin was found guilty of participating in a global scheme that involved hacking into U.S. computer networks to steal confidential earnings reports, which helped the criminals net $90,000,000 in illegal profits.
16 February 2023
More than 500 hosts have been newly compromised en masse by the ESXiArgs ransomware strain, most of which are located in France, Germany, the Netherlands, the U.K., and Ukraine.
16 February 2023
High-risk users represent approximately 10% of the worker population and are found in every department and function of the organization, according to Elevate Security research.
16 February 2023
By exploiting these flaws, hackers can access anything from sensors responsible for gauging temperature, pressure, liquid, air, and gas levels, as well as analyzers used to determine chemical compositions.
16 February 2023
Cloud monitoring, log management, and SIEM solutions provider Sumo Logic is set to become a private company after it has entered into a definitive agreement to be acquired by affiliates of private equity firm Francisco Partners for $1.7 billion.
16 February 2023
The only Catholic historically Black college or university (HBCU) reported a data breach this week involving Social Security numbers and other personal information from more than 44,000 students and vendors.
16 February 2023
Chinese-speaking individuals in Southeast and East Asia are the targets of a new rogue Google Ads campaign that delivers remote access trojans such as FatalRAT to compromised machines.
The attacks involve purchasing ad slots to appear in Google search results that direct users searching for popular applications to rogue websites hosting trojanized installers, ESET said in a report published
16 February 2023
Security researchers have disclosed two new vulnerabilities affecting Schneider Electric Modicon programmable logic controllers (PLCs) that could allow for authentication bypass and remote code execution.
The flaws, tracked as CVE-2022-45788 (CVSS score: 7.5) and CVE-2022-45789 (CVSS score: 8.1), are part of a broader collection of security defects tracked by Forescout as OT:ICEFALL.
Successful