Latest Cybersecurity News and Articles


Top 5 Valentine’s Day cyber scams

14 February 2023
EXECUTIVE SUMMARY: One wrong click to heartache? Valentine’s Day is a serious, seasonal opportunity for scammers. This Valentine’s Day, red roses, heart-shaped boxes of candies, heart-themed cards, and other popular, expressive, and traditional gifts are expected to collectively account for $26 billion in retail revenue. This reflects a two billion dollar increase over last year’s […] The post Top 5 Valentine’s Day cyber scams appeared first on CyberTalk.

Massive HTTP DDoS Attack Hits Record High of 71 Million Requests/Second

14 February 2023
Web infrastructure company Cloudflare on Monday disclosed that it thwarted a record-breaking distributed denial-of-service (DDoS) attack that peaked at over 71 million requests per second (RPS). "The majority of attacks peaked in the ballpark of 50-70 million requests per second (RPS) with the largest exceeding 71 million," the company said, calling it a "hyper-volumetric" DDoS attack. It's also

Patch Now: Apple's iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day Flaw

13 February 2023
Apple on Monday rolled out security updates for iOS, iPadOS, macOS, and Safari to address a zero-day flaw that it said has been actively exploited in the wild. Tracked as CVE-2023-23529, the issue relates to a type confusion bug in the WebKit browser engine that could be activated when processing maliciously crafted web content, culminating in arbitrary code execution. The iPhone maker said the

New TA866 Threat Group Selectively Targets U.S. and German Organizations

13 February 2023
Proofpoint security experts uncovered a threat actor, tracked as TA886, infecting companies in the U.S. and Germany with the new WasabiSeed and Screenshotter malware. The custom malware can perform surveillance and steal data. Hackers push their malware via phishing emails that include Microsoft Publisher (.pub) attachments with malicious macros or PDFs containing URLs that download JavaScript files.

Christopher Walcutt promoted to Chief Security Officer at DirectDefense

13 February 2023
Christopher Walcutt has been promoted to Chief Security Officer at DirectDefense. Walcutt will partner with internal teams across all levels.

Enigma InfoStealer Steals Sensitive Data From Crypto Firms

13 February 2023
Trend Micro spotted an active campaign that leverages a fake employment bait against the cryptocurrency industry in Eastern Europe. Hackers are reportedly deploying Enigma Stealer which is a modified version of the Stealerium information stealer. The infection chain begins with a malicious RAR archive distributed through phishing attempts or via social media.

Earth Zhulong Group Uses ShellFang Loader to Target Vietnam

13 February 2023
Information on the sophisticated APT group Earth Zhulong, which targets Vietnamese organizations, has recently come to light. The gang, which has been active since 2020, is thought to be connected to the hacker collective 1937CN from China. Organizations are suggested to stay alert and leverage best practices such as the use of anti-malware and firewalls to stay protected.

7 tips for National Clean Out Your Computer Day

13 February 2023
EXECUTIVE SUMMARY: Looking to maximize your productivity and save time while working? Whether you have hundreds of audio recordings, RFPs, client documents, data sheets, drafts of publications, photos, or a smattering of each, keeping your computer organized can go a long way in enabling you be your best self at work. National Clean Out Your […] The post 7 tips for National Clean Out Your Computer Day appeared first on CyberTalk.

NewsPenguin Waddles into Pakistani Organizations

13 February 2023
A previously unknown threat group, named NewsPenguin, was found targeting organizations in Pakistan with the upcoming Pakistan International Maritime Expo & Conference (PIMEC-2023) as bait. The researchers stated that the goal of the cybercriminal group is solely focused on cyberespionage, with no financial motivation. 

Vulnerabilities open Korenix JetWave industrial networking devices to attack

13 February 2023
Three vulnerabilities found in a variety of Korenix JetWave industrial access points and LTE cellular gateways may allow attackers to either disrupt their operation or to use them as a foothold for further attacks, CyberDanube researchers have found.

U.S. Treasury assesses cloud-based technology

13 February 2023
The U.S. Department of the Treasury released a report on the potential risks with financial service firms adopting cloud services technology.

Medical records for 4,000 Garrison Women's Health patients lost

13 February 2023
Medical records of Garrison Women’s Health patients were recently "subject to unauthorized third-party activity," according to information released Friday evening by Wentworth-Douglass Hospital.

Radio silence from DMS vendor quartet over XSS zero-days

13 February 2023
The most severe issue belongs to ONLYOFFICE’s Workspace enterprise app platform. Tracked as CVE-2022-47412, the stored cross-site scripting (XSS) vulnerability is believed to impact versions from 0 through 12.1.0.1760.

Play Ransomware Lists A10 Networks on Its Leak Site

13 February 2023
BetterCyber says that the leak site claims the ransomware group has "private and personal confidential data, a lot of technical documentation, agreements, employee and client documents."

Hackers Create Malicious Dota 2 Game Modes to Secretly Access Players' Systems

13 February 2023
An unknown threat actor created malicious game modes for the Dota 2 multiplayer online battle arena (MOBA) video game that could have been exploited to establish backdoor access to players' systems. The modes exploited a high-severity flaw in the V8 JavaScript engine tracked as CVE-2021-38003 (CVSS score: 8.8), which was exploited as a zero-day and addressed by Google in October 2021. "Since V8

Education Department reminds colleges of deadline for following cybersecurity rules

13 February 2023
Higher-education institutions that handle federal financial aid data have until early June to comply with federal rules for protecting privacy and personal information, the Education Department noted this week.

Chinese Tonto Team Hackers' Second Attempt to Target Cybersecurity Firm Group-IB Fails

13 February 2023
The Singapore-headquartered firm said that it detected and blocked malicious phishing emails originating from the group targeting its employees. It's also the second attack aimed at Group-IB, the first of which took place in March 2021.

Pepsi Bottling Ventures Suffers Data Breach After Malware Attack

13 February 2023
Pepsi Bottling Ventures LLC suffered a data breach caused by a network intrusion that resulted in the installation of information-stealing malware and the extraction of data from its IT systems.

From Huawei to TikTok, Chinese tech giants face scrutiny amid spying concerns

13 February 2023
With Chinese tech giants triggering national security concerns -- amid Beijing-backed bad actors capable of orchestrating massive cyberattacks worldwide -- the outcome of the constant tussle could shape the world's tech landscape for years to come.

Indian Social Media App Slick Exposed Childrens' User Data

13 February 2023
Due to a misconfiguration, anyone familiar with the database’s IP address could access the database, which contained entries of over 153,000 users at the time it was secured.