Latest Cybersecurity News and Articles


AT&T Email Accounts Abused to Steal Cryptocurrency

04 May 2023
Cybercriminals have been using AT&T-provided email addresses to steal large amounts of cryptocurrency by accessing accounts via mail keys. One victim claimed to have lost $134,000 from its Coinbase account. The firms are suggested to update their security controls to prevent such activities and proactively require a password reset on some email accounts.

Drone Goggles Maker Claims Firmware Sabotaged to Brick Devices

04 May 2023
Orqa, a maker of First Person View (FPV) drone racing goggles, claims that a contractor introduced code into its devices' firmware that acted as a time bomb designed to brick them.

The future of cellular IoT

04 May 2023
By Antoinette Hodes, a Check Point Global Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO.  The growth of IoT devices is transforming the way we live and work, offering unparalleled efficiency, productivity and interconnectedness. From smart homes to industrial automation, each IoT deployment scenario addresses a […] The post The future of cellular IoT appeared first on CyberTalk.

UK Government's New Fraud Strategy Gets Lukewarm Reception

04 May 2023
The UK government has announced a new fraud strategy which will focus heavily on mitigating the impact of telephone and online scams, although critics have said it doesn’t go far enough.

Researchers Discover 3 Vulnerabilities in Microsoft Azure API Management Service

04 May 2023
Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive information or backend services. This includes two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal, according to Israeli cloud security firm Ermetic. "

Researchers Uncover New Exploit for PaperCut Vulnerability That Can Bypass Detection

04 May 2023
Cybersecurity researchers have found a way to exploit a recently disclosed critical flaw in PaperCut servers in a manner that bypasses all current detections. Tracked as CVE-2023-27350 (CVSS score: 9.8), the issue affects PaperCut MF and NG installations that could be exploited by an unauthenticated attacker to execute arbitrary code with SYSTEM privileges. While the flaw was patched by the

New Rapture Ransomware Bears Notable Similarities with Paradise

04 May 2023
Trend Micro noticed a ransomware variant called Rapture that adopts a minimalistic approach and leaves behind only a small digital footprint. The attackers utilized the commercial packer Themida to pack the ransomware, hence making the analysis challenging. An RSA key configuration file used by the attackers was found to be similar to that used by the Paradise ransomware.

Payment Software Giant AvidXchange Suffers its Second Ransomware Attack of 2023

04 May 2023
Hackers have published a trove of sensitive data stolen from payment software company AvidXchange after the company fell victim to ransomware for the second time this year.

Fight over Kids Online Safety Act heats up as bill gains support in Congress

04 May 2023
The Kids Online Safety Act, known as KOSA, would place a duty of care on platforms to prevent promoting to users under 17 content that includes harmful behaviors such as eating disorders and suicide.

Brightline Data Breach Impacts 783,000 Pediatric Mental Health Patients

04 May 2023
Pediatric mental health provider Brightline is warning patients that it suffered a data breach impacting 783,606 people after a ransomware gang stole data using a zero-day vulnerability in its Fortra GoAnywhere MFT secure file-sharing platform.

CISA Advises FCC Covered List For Risk Management

04 May 2023
The list encompasses a number of communications equipment and service providers that have been determined by the US government to pose a potential national security risk according to the Secure and Trusted Communications Networks Act of 2019.

Ransomware Attack Affects Dallas Police, Court Websites

04 May 2023
Dallas was hit with a computer ransomware attack Wednesday that brought down its Police Department and City Hall websites and caused some jury trials to be canceled, officials said.

Tor Project, LGBTQ groups and CDT sound alarm over efforts to weaken encryption

04 May 2023
A group of more than 40 media and digital rights organizations are calling on Five Eyes nations and democratic governments around the world to reject efforts to weaken encryption and support a global vision of a free and open internet.

Why the Things You Don't Know about the Dark Web May Be Your Biggest Cybersecurity Threat

04 May 2023
IT and cybersecurity teams are so inundated with security notifications and alerts within their own systems, it’s difficult to monitor external malicious environments – which only makes them that much more threatening.  In March, a high-profile data breach hit national headlines when personally identifiable information connected to hundreds of lawmakers and staff was leaked on the dark web. The

Meta Uncovers Massive Social Media Cyber Espionage Operations Across South Asia

04 May 2023
Three different threat actors leveraged hundreds of elaborate fictitious personas on Facebook and Instagram to target individuals located in South Asia as part of disparate attacks. "Each of these APTs relied heavily on social engineering to trick people into clicking on malicious links, downloading malware or sharing personal information across the internet," Guy Rosen, chief information

US Authorities Dismantle Dark Web "Card Checking" Platform

04 May 2023
Try2Check’s websites have now been taken offline and the State Department has issued a $10m reward for information leading to the capture of the man accused of running the platform.

FTC accuses Facebook of violating privacy agreement, proposes ban on profiting off children's data

04 May 2023
The FTC proposed on Wednesday that Facebook be prohibited from profiting off of data it collects from minors, a move that comes in response to alleged violations of the company’s previous agreements with the agency to protect user privacy.

Netgear Vulnerabilities Lead to Credentials Leak, Privilege Escalation

04 May 2023
Vulnerabilities in Netgear’s NMS300 ProSAFE network management system allow attackers to retrieve cleartext credentials and escalate privileges, cybersecurity firm Flashpoint reports.

UK competition watchdog launches review of AI market

04 May 2023
UK competition watchdog launches review of AI market CMA to look at underlying systems of artificial intelligence tools amid concerns over false informationBusiness live – latest updatesThe UK competition watchdog has launched a review of the artificial intelligence market, as it warned of threats from AI tools including the distribution of false or misleading information.In an announcement that comes as global regulators increase scrutiny of the technology, the Competition and Markets Authority said it would look at the underlying systems, or foundation models, behind AI tools such as ChatGPT. Continue reading...

Merck cyber coverage upheld in NotPetya decision, seen as victory for policyholders

04 May 2023
A court victory in the closely watched insurance case is expected to stabilize a turbulent market and provide some assurance for organizations amid a rise in nation-state activity.