Latest Cybersecurity News and Articles
09 May 2023
The advanced persistent threat (APT) actor known as SideWinder has been accused of deploying a backdoor in attacks directed against Pakistan government organizations as part of a campaign that commenced in late November 2022.
"In this campaign, the SideWinder advanced persistent threat (APT) group used a server-based polymorphism technique to deliver the next stage payload," the BlackBerry
09 May 2023
Iranian nation-state groups have now joined financially motivated actors in actively exploiting a critical flaw in PaperCut print management software, Microsoft said.
The tech giant's threat intelligence team said it observed both Mango Sandstorm (Mercury) and Mint Sandstorm (Phosphorus) weaponizing CVE-2023-27350 in their operations to achieve initial access.
"This activity shows Mint
09 May 2023
This botnet, known as AndoryuBot, first appeared in February 2023. It contains DDoS attack modules for different protocols and communicates with its command-and-control server using SOCKS5 proxies.
09 May 2023
The new rules_oci plugin can use trusted third-party toolchains, does not require running a docker daemon already on the machine, and does not include language-specific rules.
09 May 2023
This week's seizures are part of a coordinated international law enforcement effort (known as Operation PowerOFF) to disrupt online platforms allowing anyone to launch massive DDoS attacks against any target for the right amount of money.
09 May 2023
A new malware known as NodeStealer can extract sensitive information of Facebook users. This malware allows cybercriminals to take over accounts on the platform as well as Gmail and Outlook accounts by stealing browser cookies. Facebook's engineers spotted the NodeStealer malware first in late January and linked the attacks to Vietnamese threat actors.
09 May 2023
Cybersecurity researchers have shed light on a new ransomware strain called CACTUS that has been found to leverage known flaws in VPN appliances to obtain initial access to targeted networks.
"Once inside the network, CACTUS actors attempt to enumerate local and network user accounts in addition to reachable endpoints before creating new user accounts and leveraging custom scripts to automate
08 May 2023
Snake malware and its variants have been a core component in Russian operations carried out by Centre 16 of Russia’s Federal Security Service (FSB).
08 May 2023
EXECUTIVE SUMMARY: A vicious series of cyber attacks has targeted social media accounts belonging to individuals across South Asia. In this alarming set of incidents, hackers attempted to leverage fictitious Facebook and Instagram personas in order to execute espionage attempts, deliver malware and/or to steal information. But we’re still at the beginning of this story… […]
The post Massive cyber espionage operation uncovered in South Asia appeared first on CyberTalk.
08 May 2023
"The PaperCut exploitation activity by Mint Sandstorm appears opportunistic, affecting organizations across sectors and geographies," the Microsoft Threat Intelligence team said.
08 May 2023
This investment is expected to provide HUB Security with additional resources to fuel its rapid growth and development, enhance its financial stability, and enable the company to pursue its future plans.
08 May 2023
Immuta, a Boston, MA-based leader in data security, received a strategic investment from Databricks Ventures, the investment arm of Databricks, a data and AI company and pioneer of the lakehouse. The amount of the deal was not disclosed.
08 May 2023
A recent report by Torii found that 99% of IT professionals say they’re fulfilled in their jobs despite increasing SaaS spend concerns.
08 May 2023
As QR codes continue to be heavily used by legitimate organizations—from Super Bowl advertisements to enforcing parking fees and fines, scammers have crept in to abuse the very technology for their nefarious purposes.
08 May 2023
Kabarak University's Facebook account was seized by hackers who have been using it to spread malicious and misleading images and content that contravenes the institution’s Christian values and have since tabled their demands.
08 May 2023
OT&P Healthcare CEO Robin Green on Monday said the cyberattack took place within the clinic’s management and operating system. “That system holds both patient identity and medical records. We have no idea … how much data was taken,” he said.
08 May 2023
According to White House Deputy National Security Adviser Anne Neuberger, there were more than 6,500 ransomware attacks across the globe between 2020 and 2022, prompting difficult discussions about ways to disrupt the ecosystem.
08 May 2023
The threat actors behind the ransomware attack on Taiwanese PC maker MSI last month have leaked the company's private code signing keys on their dark website.
"Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem," Alex Matrosov, founder and CEO of firmware security firm Binarly, said in a tweet over the weekend.
"It appears that Intel Boot Guard may not be
08 May 2023
Headquartered in Atlanta, Georgia, the company makes and sells electronic health records software and provides doctors and medical professionals with practice management services.
08 May 2023
The suspected Pakistan-aligned threat actor known as SideCopy has been observed leveraging themes related to the Indian military research organization as part of an ongoing phishing campaign.