Latest Cybersecurity News and Articles


Passport Breach Hits Over 500 Cricket Stars, From Wasim Akram To Ian Bell

16 February 2023
The data appears to relate to teams involved in both the Pakistan Super League and the Abu Dhabi T10 competitions. Often, cricketers have to provide their passports and other personal data to event organizers.

Medibank class action launched after massive hack put private information of millions on dark web

15 February 2023
Medibank class action launched after massive hack put private information of millions on dark web Law firm Baker McKenzie says company failed to protect privacy of customers in Australia and overseasFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastThe law firm Baker McKenzie has launched a class action lawsuit against Medibank over the health insurer’s massive cyber attack last year that resulted in the personal details of up to 10 million customers being posted on the dark web.In what became the largest breach of its kind to date in Australia, the hack on Medibank resulted in the personal details of 9.7 million current and former customers, including 5.1 million Medibank customers, 2.8 million ahm customers and 1.8 million international customers, being leaked.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

How Concerned Should You be about Your Hardware Wallet?

15 February 2023
Security company Unciphered successfully breached OneKey, the maker of hardware wallets for cryptocurrencies, in a matter of seconds, underlining security gaps in the emerging crypto world. Unciphered posted a video on YouTube demonstrating its ability to exploit a critical flaw that enabled it to infiltrate a OneKey Mini. It is important that organizations routinely scan their system for bugs and security gaps.

Everything you need to know – Netflix password sharing

15 February 2023
EXECUTIVE SUMMARY: Netflix once tweeted “Love is sharing a password,” but the company is breaking up with password sharing. At that point in time, the company’s strategy focused on getting eyeballs glued to screens. Netflix didn’t much care about who shared passwords, as long as millions of people were watching Netflix shows and movies. But […] The post Everything you need to know – Netflix password sharing appeared first on CyberTalk.

Organizations fought an average of 29.3 attacks daily in late 2022

15 February 2023
2022 Radware threat analysis report defined DDoS attack profiles by gains in number, frequency, volume, power, duration and complexity.

Dark Caracal APT Reappears with a New Version of Bandook Spyware

15 February 2023
Lookout Security published a report describing the activities of a new APT actor dubbed Dark Caracal that has claimed hundreds of infections in more than a dozen countries since March of 2022. The APT is currently using a new version of Bandook spyware to target Windows systems. Organizations in vulnerable regions organizations must watch out for IOCs associated with the threat actors and the malware to take necessary preventive measures.

Here’s how hackers use ClickFunnels to deliver malware

15 February 2023
By George Mack, Content Marketing Manager, Check Point. ClickFunnels is a platform that provides entrepreneurs and small businesses with the tools needed to create online sales funnels. ClickFunnels’ tools include landing pages, which are designed to capture the information of potential customers; video sales pages, which host videos that are designed to sell; checkout systems, […] The post Here’s how hackers use ClickFunnels to deliver malware appeared first on CyberTalk.

Recently Patched IBM Aspera Faspex Vulnerability Exploited in the Wild

15 February 2023
The security hole, tracked as CVE-2022-47986 and classified as ‘high severity’, is a YAML deserialization flaw that can be exploited by a remote attacker for arbitrary code execution using specially crafted API calls.

Passwordless authentication startup Descope lands $53M seed round

15 February 2023
The money came from Lightspeed Venture Partners and GGV Capital, with additional funds contributed by Dell Technologies Capital, TechAviv, J Ventures, Cerca, Unusual Ventures, Silicon Valley CISO Investments, and several individual investors.

SideWinder APT Attacks Regional Targets in New Campaign

15 February 2023
The suspected state-sponsored group – also known as Rattlesnake, Hardcore Nationalist (HN2) and T-APT4 – comes under the spotlight in a new report from Group-IB, Old snake, new skin: Analysis of SideWinder APT activity between June and November 2021.

Tonga is the latest Pacific Island nation hit with ransomware

15 February 2023
Tonga Communications Corporation (TCC) — one of two telecoms companies in the country — published a notice on Facebook saying the attack may slow down administrative operations.

Vladislav “Vlad” Rudnitsky hired as CISO for Kaufman Rossin

15 February 2023
Vladislav Rudnitsky has been hired as Kaufman Rossin's CISO and will be responsible for safeguarding the firm’s systems, data and applications.

SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities

15 February 2023
The most severe of the new security notes delivers updates to the Chromium browser in the SAP Business Client, to resolve a total of 54 vulnerabilities, including 22 high-severity issues.

Binance, Huobi freeze some cryptocurrency stolen in $100 million Harmony hack

15 February 2023
The two crypto platforms were notified about the funds by blockchain research company Elliptic, which managed to trace it through sanctioned cryptocurrency mixer Tornado Cash.

Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps

15 February 2023
Tracked as CVE-2023-24483, the Virtual Apps and Desktops vulnerability is described as a privilege escalation issue that allows an attacker with access to a Windows VDA as a standard Windows user to elevate privileges to System.

North Korea's APT37 Targeting Southern Counterpart with New M2RAT Malware

15 February 2023
The North Korea-linked threat actor tracked as APT37 has been linked to a piece of new malware dubbed M2RAT in attacks targeting its southern counterpart, suggesting continued evolution of the group's features and tactics. APT37, also tracked under the monikers Reaper, RedEyes, Ricochet Chollima, and ScarCruft, is linked to North Korea's Ministry of State Security (MSS) unlike the Lazarus and

One in nine online stores are leaking your data: study

15 February 2023
Sansec has revealed it's found a number of online stores accidentally leaking highly sensitive data. After studying 2,037 online stores, the company found that 12.3 percent exposed compressed files (in ZIP, SQL, and TAR archive formats).

Oligo raises $28M to secure open-source libraries at runtime

15 February 2023
The investors include Lightspeed Venture Partners, Ballistic Ventures, and TLV Partners, as well as angel investors like Eyal Waldman, Adi Sharabani, and Eyal Manor. Cyber Club London (CCL), Kmehin Ventures, and OperAngels also participated.

Webinar — A MythBusting Special: 9 Myths about File-based Threats

15 February 2023
Bad actors love to deliver threats in files. Persistent and persuasive messages convince unsuspecting victims to accept and open files from unknown sources, executing the first step in a cyber attack.  This continues to happen whether the file is an EXE or a Microsoft Excel document. Far too often, end users have an illusion of security, masked by good faith efforts of other users and (

Financially Motivated Threat Actor Strikes with New Ransomware and Clipper Malware

15 February 2023
A new financially motivated campaign that commenced in December 2022 has seen the unidentified threat actor behind it deploying a novel ransomware strain dubbed MortalKombat and a clipper malware known as Laplas. Cisco Talos said it "observed the actor scanning the internet for victim machines with an exposed remote desktop protocol (RDP) port 3389." The attacks, per the cybersecurity company,