Latest Cybersecurity News and Articles


NewsPenguin Threat Actor Emerges with Malicious Campaign Targeting Pakistani Entities

09 February 2023
A previously unknown threat actor dubbed NewsPenguin has been linked to a phishing campaign targeting Pakistani entities by leveraging the upcoming international maritime expo as a lure. "The attacker sent out targeted phishing emails with a weaponized document attached that purports to be an exhibitor manual for PIMEC-23," the BlackBerry Research and Intelligence Team said. PIMEC, short for

FBI Media Alert: Valentine's Day in New Mexico Means Love - and Scams

09 February 2023
Romance scam perpetrators are usually men targeting older women who are divorced, widowed, elderly, or disabled—but scammers do not discriminate. To facilitate the investment and demonstrate the ROI, victims are directed to fake websites.

THN Webinar – Learn How to Comply with New Cyber Insurance Identity Security Requirements

09 February 2023
The Hacker News is thrilled to announce the launch of our new educational webinar series, in collaboration with the leading cybersecurity companies in the industry! Get ready to dive into the world of enterprise-level security with expert guests who will share their vast knowledge and provide you with valuable insights and information on various security topics. Whether you're a seasoned

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices

09 February 2023
A set of 38 security vulnerabilities has been uncovered in wireless industrial internet of things (IIoT) devices from four different vendors that could pose a significant attack surface for threat actors looking to exploit operational technology (OT) environments. "Threat actors can exploit vulnerabilities in Wireless IIoT devices to gain initial access to internal OT networks," Israeli

US NIST unveils winning encryption algorithm for IoT data protection

09 February 2023
Small IoT devices are becoming increasingly popular and omnipresent, used in wearable tech, smart home applications, etc. However, they are still used to store and handle sensitive personal information, such as health data, and financial details.

10 secrets for successful digital transformations

09 February 2023
EXECUTIVE SUMMARY: Digitize to survive and thrive? Digital transformations account for 40% of all business technology spending, and the digital transformation era is expected continue well into 2023. As enterprises become digital-at-scale, building on strategies and investments to meet new demands, drive growth and enhance customer experiences, businesses may wish to appraise how digital transformations are […] The post 10 secrets for successful digital transformations appeared first on CyberTalk.

GAO Calls for Action to Protect Cybersecurity of Critical Energy, Communications Networks

09 February 2023
The GAO's assessment also calls on the Cybersecurity and Infrastructure Agency (CISA) to improve coordination and incident management among all levels of government—local, regional, and national—to protect against ransomware cyberattacks.

Unpatched Security Flaws Disclosed in Multiple Document Management Systems

09 February 2023
A typical attack pattern would be to steal the session cookie that a locally logged in administrator is authenticated with, and reuse that session cookie to impersonate that user to create a new privileged account.

Weee! Grocery Service Confirms Data Breach Affecting 1.1 Million

09 February 2023
The leaked database contains Weee! customers' first and last names, email addresses, phone numbers, device type (iOS/PC/Android), order notes, and other data the delivery platform uses.

Russian e-Commerce Giant Elevel Exposed Buyers’ Delivery Addresses

09 February 2023
The dataset with seven million data entries leaked two years’ worth of sensitive data, including names, surnames, phone numbers, email addresses, and delivery addresses of customers.

Chrome 110 Patches 15 Vulnerabilities

09 February 2023
Of the externally reported bugs, three are rated ‘high severity’. These include a type confusion flaw in the V8 engine, an inappropriate implementation issue in full screen mode, and an out-of-bounds read vulnerability in WebRTC.

Malicious Dota 2 Game Mods Infected Players with Malware

09 February 2023
While the threat actor made it very easy to detect the bundled backdoor in the first game mode published on the Steam Store, the twenty lines of code malicious code included with the three newer game mods were much harder to spot.

New Graphiron Info-stealer Used in Attacks Against Ukraine

09 February 2023
The Graphiron malware allows operators to harvest a wide range of information from the infected systems, including system info, credentials, screenshots, and files. The malicious code is written in the Go programming language.

Tor and I2P Networks Hit by Wave of Ongoing DDoS Attacks

09 February 2023
The Tor network and I2P peer-to-peer network has been dealing with massive DDoS attack. Tor's team said it will keep tweaking the network's defenses to address this ongoing issue. The goal of these ongoing attacks is unknown.

Titan Stealer: A New Golang-Based Information Stealer Malware Emerges

09 February 2023
A new Golang-based information stealer malware dubbed Titan Stealer is being advertised by threat actors through their Telegram channel. "The stealer is capable of stealing a variety of information from infected Windows machines, including credential data from browsers and crypto wallets, FTP client details, screenshots, system information, and grabbed files," Uptycs security researchers

Realtek Vulnerability Under Attack: Over 134 Million Attempts to Hack IoT Devices

09 February 2023
Researchers are warning about a spike in exploitation attempts weaponizing a critical remote code execution flaw in Realtek Jungle SDK since the start of August 2022. According to Palo Alto Networks Unit 42, the ongoing campaign is said to have recorded 134 million exploit attempts as of December 2022, with 97% of the attacks occurring in the past four months. Close to 50% of the attacks

Gootkit Malware Continues to Evolve with New Components and Obfuscations

09 February 2023
The threat actors associated with the Gootkit malware have made "notable changes" to their toolset, adding new components and obfuscations to their infection chains. Google-owned Mandiant is monitoring the activity cluster under the moniker UNC2565, noting that the usage of the malware is "exclusive to this group." Gootkit, also called Gootloader, is spread through compromised websites that

Microsoft Urges Customers to Secure On-Premises Exchange Servers

09 February 2023
Microsoft is urging customers to keep their Exchange servers updated as well as take steps to bolster the environment, such as enabling Windows Extended Protection and configuring certificate-based signing of PowerShell serialization payloads. "Attackers looking to exploit unpatched Exchange servers are not going to go away," the tech giant's Exchange Team said in a post. "There are too many

ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

09 February 2023
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could lead to a denial-of-service (DoS) condition. "A remote attacker could exploit these vulnerabilities to potentially cause denial-of-service conditions and system failures," the U.S. Cybersecurity

Ukraine Hit with New Golang-based 'SwiftSlicer' Wiper Malware in Latest Cyber Attack

09 February 2023
Ukraine has come under a fresh cyber onslaught from Russia that involved the deployment of a previously undocumented Golang-based data wiper dubbed SwiftSlicer. ESET attributed the attack to Sandworm, a nation-state group linked to Military Unit 74455 of the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). "Once executed it deletes shadow