Latest Cybersecurity News and Articles


CVEs expected to rise in 2023, as organizations still struggle to patch

09 February 2023
The increase is likely because researchers are investing more to uncover vulnerabilities and organizations are also conducting more audits to find flaws in their software inventory.

Hackers Target Switzerland’s Largest University With ‘Professional’ Cyberattack

09 February 2023
The university said on Friday that it is battling to keep the hackers out of critical zones by isolating parts of its IT system. This defense has compromised access to its systems but prevented cyberattackers from encrypting or extracting data.

Inability to prevent bad things from happening seen as the worst part of a security job

09 February 2023
83% of organizations experienced more than one data breach in 2022. However, 97% of respondents feel confident that they are well-equipped with the tools and processes needed to prevent and identify intrusions or breaches, according to Exabeam.

Finland’s Most-Wanted Hacker Nabbed in France

09 February 2023
In late October 2022, Julius “Zeekill” Kivimäki was charged (and “arrested in absentia,” according to the Finns) with attempting to extort money from the Vastaamo Psychotherapy Center.

Mortgage Financial Technologies Company 8Twelve Exposed 717,814 Records Online

09 February 2023
Security researcher Jeremiah Fowler together with the Website Planet research team discovered an open and non-password-protected database that contained 717,814 records and the PII of thousands of Canadian citizens.

Update: 110,000 more users affected in LG Uplus' data breach

09 February 2023
On January 10, the nation's third-largest wireless carrier disclosed that the personal data of 180,000 customers, including their names, birth dates, and phone numbers, had been breached.

Feds Say Cyberattack Caused Suicide Helpline’s Outage

09 February 2023
“On Dec. 1, the voice calling functionality of the 988 Lifeline was rendered unavailable as a result of a cybersecurity incident,” Danielle Bennett, a spokeswoman for the Substance Abuse and Mental Health Services Administration, said in an email.

Top trends for cyber warfare, new report highlights

09 February 2023
EXECUTIVE SUMMARY: In the past decade, the cyber threat landscape has evolved significantly. Just a few short years ago, few businesses had reason to concern themselves with the notion of cyber warfare. However, the boundaries between different cyber threat activities and their meanings have blurred; a cyber attack on a hospital, for example, could be […] The post Top trends for cyber warfare, new report highlights appeared first on CyberTalk.

Linux version of Royal Ransomware targets VMware ESXi servers

09 February 2023
Royal Ransomware is the latest ransomware operation to add support for encrypting Linux devices to its most recent malware variants, specifically targeting VMware ESXi virtual machines.

President Biden appoints Scott Charney as Chair of NSTAC

09 February 2023
President Biden announced the appointees for the National Security Telecommunications Advisory Committee. Scott Charney has been appointed as Chair.

5 mysterious new malware that could burn your business

09 February 2023
EXECUTIVE SUMMARY: IT and security leaders have come to realize that they need to alter the way in which they prepare for tomorrow. The swift evolution of technologies, best practices, threat intelligence and cyber attacks makes staying up on the latest security trends an absolute must. To help you shape your security approach and remain […] The post 5 mysterious new malware that could burn your business appeared first on CyberTalk.

Hackers backdoor Windows devices in Sliver and BYOVD attacks

09 February 2023
A new hacking campaign exploits Sunlogin flaws to deploy the Sliver post-exploitation toolkit and launch Windows Bring Your Own Vulnerable Driver (BYOVD) attacks to disable security software.

OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability

09 February 2023
"This is not believed to be exploitable, and it occurs in the unprivileged pre-auth process that is subject to chroot(2) and is further sandboxed on most major platforms," OpenSSH disclosed in its release notes on February 2, 2023.

Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping

09 February 2023
A critical vulnerability affecting wireless communication base stations from Baicells Technologies can be exploited to cause disruption in telecom networks or take complete control of data and voice traffic, according to a researcher.

Lazarus Group Exploits Unpatched Zimbra Devices

09 February 2023
WithSecure researchers spotted a new campaign, dubbed No Pineapple, by North Korean Lazarus hackers targeting energy and medical research sectors with the Acres RAT. Lazarus gains access to a flawed Zimbra mail server by abusing RCE flaws tracked as CVE-2022-27925 and CVE-2022-37042.

America’s top cyber diplomat says his Twitter account was hacked

09 February 2023
There did not appear to be any broader fallout from the hacking incident. Nate Fick uses the account sparingly and instead promotes his work through an official State Department account.

Hackers Abuse RCE Vulnerability to Deploy Sliver Backdoor

09 February 2023
Sunlogin security holes are being used by a new hacking effort to launch Windows Bring Your Own Vulnerable Driver (BYOVD) attacks and distribute the Sliver post-exploitation toolkit. The exploitation of the flaw leads to the installation of Gh0st RAT. However, in some cases, hackers installed XMRig CoinMiner instead of Gh0st RAT.

Italy, France and Singapore Warn of a Spike in ESXI Ransomware

09 February 2023
CERT-FR was the first to notice and send an alert about the attack. Italy’s National Cybersecurity Agency (ACN) and Cyber Security Agency of Singapore have also issued warnings for organizations to take immediate action to protect their systems.

Biden Announces New Appointees for Telecommunications Advisory Committee

09 February 2023
Biden’s announcement also included new leadership for NSTAC. Scott Charney, VP for Security Policy at Microsoft, will chair the committee, while Jeffrey Storey, former President and CEO at Lumen Technologies will serve as vice-chair.

Linux Variant of Clop Ransomware Spotted, But Uses Faulty Encryption Algorithm

09 February 2023
The first-ever Linux variant of the Clop ransomware has been detected in the wild, but with a faulty encryption algorithm that has made it possible to reverse engineer the process. "The ELF executable contains a flawed encryption algorithm making it possible to decrypt locked files without paying the ransom," SentinelOne researcher Antonis Terefos said in a report shared with The Hacker News.