Latest Cybersecurity News and Articles


Hackers Inject Credit Card Stealer Into Authorize.net Payment Processing Module

23 March 2023
A new credit card stealing hacking campaign is doing things differently by hiding its malicious code inside the 'Authorize.net' payment gateway module for WooCommerce, allowing the breach to evade detection by security scans.

Backslash Snags $8M Seed Financing for AppSec Tech

23 March 2023
The Israeli startup said the financing was provided by StageOne Ventures, First Rays Venture Partners, and D. E. Shaw & Co. A roster of prominent security practitioners and entrepreneurs also joined the round.

New Rising 'Nexus' Android Banking Trojan Targeting 450 Financial Apps

23 March 2023
"Nexus provides all the main features to perform ATO attacks (Account Takeover) against banking portals and cryptocurrency services, such as credentials stealing and SMS interception," Italian cybersecurity firm Cleafy said.

Digital fraud surpasses pre-pandemic levels

23 March 2023
According to research, the pivot to digital transactions during the pandemic means the risk of digital fraud is greater than it was pre-pandemic.  

CISA Expands Cybersecurity Committee, Updates Baseline Security Goals

23 March 2023
The US Cybersecurity and Infrastructure Security Agency (CISA) this week announced adding more experts to its Cybersecurity Advisory Committee (CSAC) and updating the baseline cybersecurity goals introduced last year.

North Korean Hackers Found Using Chrome Extensions to Steal Gmail Emails

23 March 2023
A joint cybersecurity advisory from the German Federal Office for the Protection of the Constitution (BfV) and the National Intelligence Service of the Republic of Korea (NIS) warn about Kimsuky's use of Chrome extensions to steal Gmail emails.

Here's what to expect from lawmakers who will grill TikTok's CEO on privacy, security and child safety

23 March 2023
The hearing comes as Congress weighs legislation that would empower the Biden administration to ban TikTok along with other foreign apps that many politicians in Washington and around the country say pose a U.S. national security threat.

New Kritec Magecart Skimmer Found on Magento Stores

23 March 2023
In the past few months, there have been several Magecart skimmers abusing Google Tag Manager in one way or another. While the Kritec skimmer hangs around the Google Tag Manager script, researchers believe it is not related to other active campaigns.

7 tips to combat government data breach risks

23 March 2023
Cybercrime is transitioning from targets of opportunity to focused targets of choice and the shift is bad news for government agencies.

Lionsgate Streaming Platform With 37 Million Subscribers Leaks User Data

23 March 2023
Cybernews researchers discovered an unprotected 20GB of server logs that contained nearly 30 million entries, with the oldest dated May 2022. The logs exposed subscribers’ IP addresses and user data about devices, operating systems, and web browsers.

Nexus: A New Rising Android Banking Trojan Targeting 450 Financial Apps

23 March 2023
An emerging Android banking trojan dubbed Nexus has already been adopted by several threat actors to target 450 financial applications and conduct fraud. "Nexus appears to be in its early stages of development," Italian cybersecurity firm Cleafy said in a report published this week. "Nexus provides all the main features to perform ATO attacks (Account Takeover) against banking portals and

2023 Cybersecurity Maturity Report Reveals Organizational Unpreparedness for Cyberattacks

23 March 2023
In 2022 alone, global cyberattacks increased by 38%, resulting in substantial business loss, including financial and reputational damage. Meanwhile, corporate security budgets have risen significantly because of the growing sophistication of attacks and the number of cybersecurity solutions introduced into the market. With this rise in threats, budgets, and solutions, how prepared are industries

Operation Soft Cell: Chinese Hackers Breach Middle East Telecom Providers

23 March 2023
Telecommunication providers in the Middle East are the subject of new cyber attacks that commenced in the first quarter of 2023. The intrusion set has been attributed to a Chinese cyber espionage actor associated with a long-running campaign dubbed Operation Soft Cell based on tooling overlaps. "The initial attack phase involves infiltrating Internet-facing Microsoft Exchange servers to deploy

German and South Korean Agencies Warn of Kimsuky's Expanding Cyber Attack Tactics

23 March 2023
German and South Korean government agencies have warned about cyber attacks mounted by a threat actor tracked as Kimsuky using rogue browser extensions to steal users' Gmail inboxes. The joint advisory comes from Germany's domestic intelligence apparatus, the Federal Office for the Protection of the Constitution (BfV), and South Korea's National Intelligence Service of the Republic of Korea (NIS

Google Suspends Chinese E-Commerce App Pinduoduo Over Malware

22 March 2023
Google says it has suspended the app for the Chinese e-commerce giant Pinduoduo after malware was found in versions of the app. The move comes just weeks after Chinese security researchers published an analysis suggesting the popular e-commerce app sought to seize total control over affected devices by exploiting multiple security vulnerabilities in a variety of Android-based smartphones.

80% of security leaders predict increase in cybersecurity automation

22 March 2023
Research finds that security leaders are dissatisfied with the use of automation within their company's security operation centers (SOCs).

10 top cyber security vulnerabilities that you can’t ignore (2023)

22 March 2023
EXECUTIVE SUMMARY: Welcome to the digital age, where everything from our personal information to the critical infrastructure of entire nations is stored and managed online. The value of the aforementioned data is immense and cyber criminals are eager to capitalize on ill-gotten gains. A combination of extortion and dark web data sales allow cyber criminals […] The post 10 top cyber security vulnerabilities that you can’t ignore (2023) appeared first on CyberTalk.

Update: LockBit ransomware gang now also claims City of Oakland breach

22 March 2023
This is the second ransomware gang claiming to have stolen data from the City of Oakland after Play ransomware took responsibility in early March for a mid-February cyberattack.

UK: NCSC Launches Two New Tools for Small Businesses

22 March 2023
The UK’s leading cybersecurity agency has launched two new services designed to help the nation’s small businesses to more effectively enhance their cyber-risk management.

How to combat hardware Trojans by detecting microchip manipulations

22 March 2023
Researchers from Ruhr University Bochum, Germany, and the Max Planck Institute for Security and Privacy (MPI-SP) are pioneering innovative detection techniques to combat these hardware Trojans.