Latest Cybersecurity News and Articles


Privacy breach hits Japanese convenience stores

10 May 2023
Japan's minister for digital transformation and digital reform, Tono Karo, has apologized after a government app breached citizens' privacy. The app is called the "Certificate Issuing Server."

RapperBot DDoS Botnet Expands into Cryptojacking

10 May 2023
FortiGuard Labs has encountered new samples of the RapperBot campaign active since January 2023. RapperBot is a malware family primarily targeting IoT devices. It has been observed in the wild since June 2022.

Why Honeytokens Are the Future of Intrusion Detection

10 May 2023
A few weeks ago, the 32nd edition of RSA, one of the world's largest cybersecurity conferences, wrapped up in San Francisco. Among the highlights, Kevin Mandia, CEO of Mandiant at Google Cloud, presented a retrospective on the state of cybersecurity. During his keynote, Mandia stated: "There are clear steps organizations can take beyond common safeguards and security tools to strengthen their

Mastermind Behind Twitter 2020 Hack Pleads Guilty and Faces up to 70 Years in Prison

10 May 2023
A U.K. national has pleaded guilty in connection with the July 2020 Twitter attack affecting numerous high-profile accounts and defrauding other users of the platform. Joseph James O'Connor, who also went by the online alias PlugwalkJoe, admitted to "his role in cyberstalking and multiple schemes that involve computer hacking, including the July 2020 hack of Twitter," the U.S. Department of

Threat Assessment: Royal Ransomware

10 May 2023
It is suspected that this group is made up mainly of former members of the Conti ransomware group, who operate covertly and behind closed doors. The ex-members that formed this group are known as Team One.

56,000+ cloud-based apps at risk of malware exfiltration

10 May 2023
The technology sector had the highest number of malware-infected employees, the most exposed corporate credentials, and the majority of all stolen cookies, according to SpyCloud.

FBI-led Operation Medusa kills Russian FSB malware network

10 May 2023
The FBI has sabotaged a suite of malicious software used by elite Russian spies, U.S. authorities said on Tuesday, providing a glimpse of the digital tug-of-war between two cyber superpowers.

Kubernetes Bill of Materials (KBOM) open-source tool enhances cloud security response to CVEs

10 May 2023
Available in an open-source CLI tool, this KBOM enables cloud security teams to understand the scope of third-party tooling in their environment to respond quicker to new vulnerabilities, which have become frequent in recent months.

New Linux kernel NetFilter flaw gives attackers root privileges

10 May 2023
The security problem stems from Netfilter nf_tables accepting invalid updates to its configuration, allowing specific scenarios where invalid batch requests lead to the corruption of the subsystem's internal state.

U.S. Government Neutralizes Russia's Most Sophisticated Snake Cyber Espionage Tool

10 May 2023
The U.S. government on Tuesday announced the court-authorized disruption of a global network compromised by an advanced malware strain known as Snake wielded by Russia's Federal Security Service (FSB). Snake, dubbed the "most sophisticated cyber espionage tool," is the handiwork of a Russian state-sponsored group called Turla (aka Iron Hunter, Secret Blizzard, SUMMIT, Uroburos, Venomous Bear,

Microsoft Patch Tuesday for May 2023 fixed two actively exploited zero-day flaws

10 May 2023
The flaws addressed by these Patch Tuesday updates affect Microsoft Windows and Windows Components; Office and Office Components; Microsoft Edge (Chromium-based); SharePoint Server; Visual Studio; SysInternals; and Microsoft Teams.

SideCopy Breaches Indian Organizations with Action and AllaKore RATs

10 May 2023
Pakistani cyberespionage group, SideCopy APT, was found targeting employees at India’s Defence Research and Development Organization (DRDO), to pilfer confidential military secrets. Instead of using CACTUSTORCH to deploy code obfuscated via JavaScript and VBScript, SideCopy's latest campaign appears to have utilized SILENTTRINITY,

Microsoft's May Patch Tuesday Fixes 38 Flaws, Including Active Zero-Day Bug

10 May 2023
Microsoft has rolled out Patch Tuesday updates for May 2023 to address 38 security flaws, including one zero-day bug that it said is being actively exploited in the wild. Trend Micro's Zero Day Initiative (ZDI) said the volume is the lowest since August 2021, although it pointed out that "this number is expected to rise in the coming months." Of the 38 vulnerabilities, six are rated Critical and

Microsoft Patch Tuesday, May 2023 Edition

09 May 2023
Microsoft today released software updates to fix at least four dozen security holes in its Windows operating systems and other software, including patches for two zero-day vulnerabilities that are already being exploited in active attacks.

Are your employees missing these social engineering red flags?

09 May 2023
EXECUTIVE SUMMARY: Social engineering is one of the most significant and difficult network security challenges to contend with. Due to the discrete nature of social engineering, attacks can occur without anyone in your organization recognizing that anything deceitful has occurred at all. Employees still fall for social engineering scams on a regular basis. This endangers […] The post Are your employees missing these social engineering red flags? appeared first on CyberTalk.

U.S. Authorities Seize 13 Domains Offering Criminal DDoS-for-Hire Services

09 May 2023
U.S. authorities have announced the seizure of 13 internet domains that offered DDoS-for-hire services to other criminal actors. The takedown is part of an ongoing international initiative dubbed Operation PowerOFF that's aimed at dismantling criminal DDoS-for-hire infrastructures worldwide. The development comes almost five months after a "sweep" in December 2022 dismantled 48 similar services 

Update: Dallas restores core emergency dispatch systems

09 May 2023
The city continues to recover and restore access to its computer-assisted dispatch system. The city’s municipal court system remains offline, and court hearings and trials have been suspended since Wednesday.

CISOs Worried About Personal Liability For Breaches

09 May 2023
Over 62% of global CISOs are concerned about being held personally liable for successful cyberattacks that occur on their watch, and a similar share would not join organizations that fail to offer insurance to protect them, according to Proofpoint.

Unconsidered benefits of a consolidation strategy every CISO should know

09 May 2023
Pete has 32 years of Security, Network, and MSSP experience and has been a hands-on CISO for the last 17 years and joined Check Point as Field CISO of the Americas. Pete’s cloud security deployments and designs have been rated by Garter as #1 and #2 in the world and he literally “wrote the book” […] The post Unconsidered benefits of a consolidation strategy every CISO should know appeared first on CyberTalk.

Nationwide push to require social media age verification raises questions about privacy, industry standards

09 May 2023
Lawmakers in Washington and in statehouses around the country are seeking to compel tech companies to prove the age of their users, part of a growing national effort to better protect young children from the harms of the internet.