Latest Cybersecurity News and Articles


Drone Goggles Maker Orqa Hit with 'Time-bomb' Ransomware Attack

06 May 2023
Orqa, a maker of FPV drone racing goggles, claimed that a contractor introduced code into the firmware of the devices, designed to brick them as a time bomb. Findings say that the contractor had been in business relations with Orqa for several years and had waited for the code bomb to detonate. Orqa has issued a warning, urging users not to install the unofficial firmware version, as it may be another piece of malicious code.

Russian actor Uses WinRAR and DD Command to Destroy Ukrainian Data

06 May 2023
CERT-UA confirmed the discovery of a malicious script dubbed RoarBat that is most probably being used by the Russian threat group Sandworm to wipe off data from Ukrainian state networks. The script uses the WinRaR application for archiving and compressing applications and then deleting specific files. However, Ukrainian defenders attributed the attack to Sandworm with moderate confidence.

Dragon Breath APT Group Using Double-Clean-App Technique to Target Gambling Industry

06 May 2023
An advanced persistent threat (APT) actor known as Dragon Breath has been observed adding new layers of complexity to its attacks by adopting a novel DLL side-loading mechanism. "The attack is based on a classic side-loading attack, consisting of a clean application, a malicious loader, and an encrypted payload, with various modifications made to these components over time," Sophos researcher

Twitter admits to ‘security incident’ involving Circles tweets

06 May 2023
Twitter admits to ‘security incident’ involving Circles tweets Feature allows users to set a list of friends and post tweets that only they are supposed to be able to readA privacy breach at Twitter published tweets that were never supposed to be seen by anyone but the poster’s closest friends to the site at large, the company has admitted after weeks of stonewalling reports.The site’s Circles feature allows users to set an exclusive list of friends and post tweets that only they can read. Similar to Instagram’s Close Friends setting, it allows users to share private thoughts, explicit images or unprofessional statements without risking sharing them with their wider network. Continue reading...

"Kekw" Malware in Python Packages Could Steal Data and Hijack Crypto

06 May 2023
According to new data by Cyble Research and Intelligence Labs (CRIL), Kekw malware can steal sensitive information from infected systems and perform clipper activities that can hijack cryptocurrency transactions.

Meta Cracks Down on South Asian Cyberespionage Groups

06 May 2023
Social media giant Meta took down hundreds of fake Facebook and Instagram accounts used by South Asia advanced persistent threat groups to glean sensitive information and coax users into installing malware.

ALPHV gang claims ransomware attack on Constellation Software

06 May 2023
Canadian diversified software company Constellation Software confirmed on Thursday that some of its systems were breached by threat actors who also stole personal information and business data.

New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to Cyberattacks

06 May 2023
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw. The issue, assigned the identifier CVE-2023-30777, relates to a case of reflected cross-site scripting (XSS) that could be abused to inject arbitrary executable scripts into otherwise benign websites. The plugin, which is available both as a free and pro

Ransomware gang hijacks university’s emergency alert system, threatens students

05 May 2023
EXECUTIVE SUMMARY: On May 1st, a group of cyber criminals hacked into and gained control over a U.S. university’s emergency alert system. Students at Bluefield University received the following unexpected message: “Hello students of Bluefield University! We’re Avoslocker Ransomwar. We hacked the university network to exfiltrate 1.2 TB files…We have admissions data from thousands of […] The post Ransomware gang hijacks university’s emergency alert system, threatens students appeared first on CyberTalk.

White House officials discuss AI concerns with security organizations

05 May 2023
Vice President Harris and other White House officials met with security leaders to address risks associated with artificial intelligence (AI). 

Virginia school offers cybersecurity education program

05 May 2023
A tech industry adult education program is being offered by Virginia Commonwealth University and the Institute of Data to help fill the talent gap.

WordPress custom field plugin bug exposes over 1M sites to XSS attacks

05 May 2023
Security researchers warn that the 'Advanced Custom Fields' and 'Advanced Custom Fields Pro' WordPress plugins, with millions of installs, are vulnerable to cross-site scripting attacks (XSS).

Pro-Russian Hackers Claim Downing of French Senate Website

05 May 2023
“Access to the site has been disrupted since this morning,” the upper house of Parliament said on Twitter shortly before midday, saying a team was busy fixing the problem.

Azure API Management Vulnerabilities Allowed Unauthorized Access

05 May 2023
Three security vulnerabilities in the Azure API Management service could be exploited to perform various types of malicious actions, cloud security company Ermetic reveals.

New Android Malware 'FluHorse' Targeting East Asian Markets with Deceptive Tactics

05 May 2023
Various sectors in East Asian markets have been subjected to a new email phishing campaign that distributes a previously undocumented strain of Android malware called FluHorse that abuses the Flutter software development framework.

Will the EU’s new cyber security law change the game?

05 May 2023
Peter Sandkuijl, a resident of The Netherlands, is a senior security specialist who has operated in the security market for over 25 years. He started his career at a local Check Point distributor, where he served as a technical product manager. In 2000, Check Point started a Benelux office, where Sandkuijl started as the Technical […] The post Will the EU’s new cyber security law change the game? appeared first on CyberTalk.

City of Dallas recovers after recent ransomware attack

05 May 2023
City of Dallas residents are still dealing with some delays and disruptions following a Wednesday ransomware attack which affected some city websites and services.

Fortinet Patches High-Severity Vulnerabilities in FortiADC, FortiOS

05 May 2023
Fortinet this week announced its monthly set of security updates that address nine vulnerabilities in multiple products, including two high-severity bugs in FortiADC, FortiOS, and FortiProxy.

Hackers Targeting Italian Corporate Banking Clients with New Web-Inject Toolkit DrIBAN

05 May 2023
Italian corporate banking clients are the target of an ongoing financial fraud campaign that has been leveraging a new web-inject toolkit called drIBAN since at least 2019.

Vulnerability Could Have Been Exploited for ‘Unlimited’ Free Credit on OpenAI Accounts

05 May 2023
A vulnerability in OpenAI’s account validation process allowed anyone to obtain virtually unlimited free credit for the company’s services by registering new accounts using the same phone number, application security firm Checkmarx says.