Latest Cybersecurity News and Articles


Google's Zero-Day Hunters Test AI for Security Research

24 June 2024
Google's Project Zero team of zero-day hunters believes that artificial intelligence (AI) can enhance automated threat identification and analysis by detecting vulnerabilities that are often missed by current tools.

Meta, MS SQL Make Strange Bedfellows on Couch of Cyber-Pain

24 June 2024
The article discusses how Meta and Microsoft SQL Server, two very different parts of the tech industry, are both facing issues related to software and services supply chain.

RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations

24 June 2024
The primary objective appears to be gathering intelligence on Taiwan's economic policy, trade, and diplomatic relations. The group focuses on targeting vulnerabilities in internet-facing devices due to their limited security solutions.

Ease the Burden with AI-Driven Threat Intelligence Reporting

24 June 2024
Learn about critical threats that can impact your organization and the bad actors behind them from Cybersixgill’s threat experts. Each story shines a light on underground activities, the threat actors involved, and why you should care, along with what you can do to mitigate risk.  Cybersecurity professionals are facing unprecedented challenges as they strive to manage increasing workloads

RedJuliett Cyber Espionage Campaign Hits 75 Taiwanese Organizations

24 June 2024
A likely China-linked state-sponsored threat actor has been linked to a cyber espionage campaign targeting government, academic, technology, and diplomatic organizations in Taiwan between November 2023 and April 2024. Recorded Future's Insikt Group is tracking the activity under the name RedJuliett, describing it as a cluster that operates Fuzhou, China, to support Beijing's intelligence

Multiple Threat Actors Deploying Open-Source Rafel RAT to Target Android Devices

24 June 2024
Multiple threat actors, including cyber espionage groups, are employing an open-source Android remote administration tool called Rafel RAT to meet their operational objectives by masquerading it as Instagram, WhatsApp, and various e-commerce and antivirus apps. "It provides malicious actors with a powerful toolkit for remote administration and control, enabling a range of malicious activities

ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor

22 June 2024
Russian organizations have been targeted by a cybercrime gang called ExCobalt using a previously unknown Golang-based backdoor known as GoRed. "ExCobalt focuses on cyber espionage and includes several members active since at least 2016 and presumably once part of the notorious Cobalt Gang," Positive Technologies researchers Vladislav Lunin and Alexander Badayev said in a technical report

Warning: New Adware Campaign Targets Meta Quest App Seekers

22 June 2024
A new campaign is tricking users searching for the Meta Quest (formerly Oculus) application for Windows into downloading a new adware family called AdsExhaust. "The adware is capable of exfiltrating screenshots from infected devices and interacting with browsers using simulated keystrokes," cybersecurity firm eSentire said in an analysis, adding it identified the activity earlier this month. "

U.S. Treasury Sanctions 12 Kaspersky Executives Amid Software Ban

22 June 2024
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) imposed sanctions against a dozen individuals serving executive and senior leadership roles at Kaspersky Lab, a day after the Russian company was banned by the Commerce Department. The move "underscores our commitment to ensure the integrity of our cyber domain and to protect our citizens against malicious cyber

How will ChatGPT-5 change your cyber security strategy?

21 June 2024
EXECUTIVE SUMMARY: Yesterday, OpenAI’s Chief Technology Officer, Mira Murati, described the level of intelligence that will be packed into the forthcoming ChatGPT model. ChatGPT-5 is expected to have ‘Ph.D-level’ smarts. “If you look at the trajectory of improvement, systems like GPT-3 were maybe toddler-level intelligence,” said Murati. “And then systems like GPT-4 are more like […] The post How will ChatGPT-5 change your cyber security strategy? appeared first on CyberTalk.

NCSC statement following reports of a Synnovis data breach

21 June 2024
The NCSC has published advice on protecting yourself against the impact of data breaches.

Chinese Hackers Deploy SpiceRAT and SugarGh0st in Global Espionage Campaign

21 June 2024
A previously undocumented Chinese-speaking threat actor codenamed SneakyChef has been linked to an espionage campaign primarily targeting government entities across Asia and EMEA (Europe, Middle East, and Africa) with SugarGh0st malware since at least August 2023. "SneakyChef uses lures that are scanned documents of government agencies, most of which are related to various countries' Ministries

Military-themed Email Scam Spreads Malware to Infect Pakistani Users

21 June 2024
Cybersecurity researchers have shed light on a new phishing campaign that has been identified as targeting people in Pakistan using a custom backdoor. Dubbed PHANTOM#SPIKE by Securonix, the unknown threat actors behind the activity have leveraged military-related phishing documents to activate the infection sequence. "While there are many methods used today to deploy malware, the threat actors

Oyster Backdoor Spreading via Trojanized Popular Software Downloads

21 June 2024
A malvertising campaign is leveraging trojanized installers for popular software such as Google Chrome and Microsoft Teams to drop a backdoor called Oyster (aka Broomstick and CleanUpLoader). That's according to findings from Rapid7, which identified lookalike websites hosting the malicious payloads that users are redirected to after searching for them on search engines like Google and Bing. The

SolarWinds Serv-U Vulnerability Under Active Attack - Patch Immediately

21 June 2024
A recently patched high-severity flaw impacting SolarWinds Serv-U file transfer software is being actively exploited by malicious actors in the wild. The vulnerability, tracked as CVE-2024-28995 (CVSS score: 8.6), concerns a directory transversal bug that could allow attackers to read sensitive files on the host machine. Affecting all versions of the software prior to and including Serv-U 15.4.2

Hacked London NHS hospitals data allegedly published online

21 June 2024
Hacked London NHS hospitals data allegedly published online Cyber-attack earlier this month led to cancellation of almost 1,600 operations and outpatient appointmentsData from a ransomware attack has allegedly been published online weeks after the attack halted operations and tests in major London hospitals, NHS England has said.A Russian group is believed to have carried out the cyber-attack on Synnovis, a private pathology firm that analyses blood tests for Guy’s and St Thomas’ NHS foundation trust (GSTT) and King’s College trust, on 3 June, forcing hospitals in the capital to cancel almost 1,600 operations and outpatient appointments. Continue reading...

U.S. Bans Kaspersky Software, Citing National Security Risks

21 June 2024
The U.S. Department of Commerce's Bureau of Industry and Security (BIS) on Thursday announced a "first of its kind" ban that prohibits Kaspersky Lab's U.S. subsidiary from directly or indirectly offering its security software in the country. The blockade also extends to the cybersecurity company's affiliates, subsidiaries and parent companies, the department said, adding the action is based on

US bans sales of Kaspersky antivirus software over Russia ties

20 June 2024
US bans sales of Kaspersky antivirus software over Russia ties Washington says Moscow’s influence over company poses significant risk, as Kaspersky argues its activities do not threaten US securityJoe Biden’s administration has banned Russia-based cybersecurity firm Kaspersky from providing its popular antivirus products in the US over national security concerns.“Kaspersky will generally no longer be able to, among other activities, sell its software within the United States or provide updates to software already in use,” said a commerce department statement. The announcement came after a lengthy investigation found Kaspersky’s “continued operations in the United States presented a national security risk due to the Russian government’s offensive cyber capabilities and capacity to influence or direct Kaspersky’s operations”. Continue reading...

CISO security & business continuity insights: lessons from an undersea cable blackout

20 June 2024
Issam El Haddioui: Head of Security Engineering, EMEA – Africa | Security Evangelist with the Office of the CTO. Issam El Haddioui has held multiple technical leadership and management roles with major cyber security vendors in different countries. He has 20+ years’ experience in worldwide consulting, designing, and implementing security architectures across verticals. He holds […] The post CISO security & business continuity insights: lessons from an undersea cable blackout appeared first on CyberTalk.

KrebsOnSecurity Threatened with Defamation Lawsuit Over Fake Radaris CEO

20 June 2024
On March 8, 2024, KrebsOnSecurity published a deep dive on the consumer data broker Radaris, showing how the original owners are two men in Massachusetts who operated multiple Russian language dating services and affiliate programs, in addition to a dizzying array of people-search websites. The subjects of that piece are threatening to sue KrebsOnSecurity for defamation unless the story is retracted. Meanwhile, their attorney has admitted that the person Radaris named as the CEO from its inception is a fabricated identity.