Latest Cybersecurity News and Articles


Adobe Plugs Critical Security Holes in Illustrator, After Effects Software

15 February 2023
The Mountain View, California-based company warned that security problems exist on three of its most popular software products — Photoshop, Illustrator, and After Effects.

Google Rolling Out Privacy Sandbox Beta on Android 13 Devices

15 February 2023
Google announced on Tuesday that it's officially rolling out Privacy Sandbox on Android in beta to eligible mobile devices running Android 13. "The Privacy Sandbox Beta provides new APIs that are designed with privacy at the core, and don't use identifiers that can track your activity across apps and websites," the search and advertising giant said. "Apps that choose to participate in the Beta

The 2 biggest regulatory challenges for the internet of “any” thing (IoT)

15 February 2023
By Antoinette Hodes, a Check Point Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO. She has worked as an engineer in IT for over 25 years. She is a strong customer advocate, who connects people & processes with technology by matching the clients’ business needs with […] The post The 2 biggest regulatory challenges for the internet of “any” thing (IoT) appeared first on CyberTalk.

Update Now: Microsoft Releases Patches for 3 Actively Exploited Windows Vulnerabilities

14 February 2023
Microsoft on Tuesday released security updates to address 75 flaws spanning its product portfolio, three of which have come under active exploitation in the wild. The updates are in addition to 22 flaws the Windows maker patched in its Chromium-based Edge browser over the past month. Of the 75 vulnerabilities, nine are rated Critical and 66 are rated Important in severity. 37 out of 75 bugs are

Pepsi Bottling Ventures breached, extensive employee data stolen

14 February 2023
EXECUTIVE SUMMARY: Pepsi Bottling Ventures, the largest bottler of Pepsi-Cola beverages in the United States, is responsible for manufacturing, selling and distributing a variety of popular consumer brands. The company operates 18 bottling facilities across North and South Carolina, Virginia, Maryland and Delaware. On the 23rd of December, a network intrusion occurred, resulting in a […] The post Pepsi Bottling Ventures breached, extensive employee data stolen appeared first on CyberTalk.

Microsoft Patch Tuesday, February 2023 Edition

14 February 2023
Microsoft is sending the world a whole bunch of love today, in the form of patches to plug dozens of security holes in its Windows operating systems and other software. This year's special Valentine's Day Patch Tuesday includes fixes for a whopping three different "zero-day" vulnerabilities that are already being used in active attacks.

Social Engineering Attacks Increases in Q4 2022, Reveals Avast Labs

14 February 2023
Cybercriminals are becoming more adept at creating a sense of urgency for victims and motivating them to engage in their agenda, reveals the Avast Q4 2022 report. Refund and invoice fraud saw a 22% jump in December 2022, with perpetrators utilizing emails originating from a trustworthy organization to create the illusion of unauthorized charges and false receipts.

Industrial wireless IoT present risks to operational technology

14 February 2023
Research on the risks of industrial wireless IoT was released finding that they can provide a path to internal operational technology (OT) networks.

11,000 WordPress Sites Hacked in a Backdoor Attack

14 February 2023
According to Sucuri’s research, the backdoor redirects users to sites that show fraudulent views of Google AdSense ads. The company’s SiteCheck remote scanner has detected more than 10,890 infected sites.

Massive AdSense Fraud Campaign Uncovered - 10,000+ WordPress Sites Infected

14 February 2023
The threat actors behind the black hat redirect malware campaign have scaled up their campaign to use more than 70 bogus domains mimicking URL shorteners and infected over 10,800 websites. "The main objective is still ad fraud by artificially increasing traffic to pages which contain the AdSense ID which contain Google ads for revenue generation," Sucuri researcher Ben Martin said in a report

Eurostar forces 'password resets' — then fails and locks users out

14 February 2023
International high-speed rail operator, Eurostar, is emailing its users this week and forcing them to reset their account passwords in a bid to "upgrade" security. But users who visit the password reset link are met with "technical problems."

GoAnywhere Zero-Day Attack Victims Start Disclosing Significant Impact

14 February 2023
In an SEC filing, Community Health Systems (CHS), one of the largest US healthcare services providers, revealed that a “security breach experienced by Fortra” resulted in the exposure of personal info and PHI belonging to patients of CHS affiliates.

Reducing RPA security risk

14 February 2023
Robot process automation (RPA) has expanded to meet workforce needs. Unfortunately, RPA can put the sensitive data that it touches at risk. 

Update: BlackCat Leaks Data Belonging to Irish University

14 February 2023
The Sunday dump, which appears to include sensitive data including staff medical diagnoses and student bank account information, came days after the Irish High Court issued a temporary injunction prohibiting ransomware attackers from leaking data.

VMware ransomware was on the rise leading up to ESXiArgs spree, research finds

14 February 2023
Only two cyberattacks targeted ESXi with ransomware in 2020, but in 2021, Recorded Future identified more than 400 incidents. Last year the number ballooned, growing almost threefold to 1,118 in 2022, the research found.

Clipper Malware Spread via Over 450 PyPI Packages Using Typosquatting

14 February 2023
Software supply chain security company Phylum, which spotted the libraries, said the ongoing activity is a follow-up to a campaign that was initially disclosed in November 2022.

Accenture acquires cybersecurity company Morphus

14 February 2023
Acquiring the privately held cyber defence, risk management, and cyber threat intelligence services provider is set to enable Accenture to widen its cybersecurity footprint within the region.

New MortalKombat Ransomware and Laplas Clipper Malware Threats Deployed in Recent Attacks

14 February 2023
Talos observed the actor scanning the internet for victim machines with an exposed remote desktop protocol (RDP) port 3389, using one of their download servers that run an RDP crawler and also facilitates MortalKombat ransomware.

Hackers Target Bahrain Airport, State News Agency Sites to Mark Uprising

14 February 2023
Hackers said they had taken down the websites of Bahrain’s international airport and state news agency on Tuesday to mark the 12-year anniversary of an Arab Spring uprising in the small Gulf country.

Cybercriminals target fans of The Last of Us with recent malware and phishing scams

14 February 2023
Recently, Kaspersky researchers shared with VPNOverview details of two separate campaigns — a scam designed to inject PCs with malware and a phishing ploy designed to steal banking information and other financial data.