Latest Cybersecurity News and Articles


Hackers Exploiting 5-year-old Unpatched Vulnerability in TBK DVR Devices

03 May 2023
Threat actors are actively exploiting an unpatched five-year-old flaw impacting TBK digital video recording (DVR) devices, according to an advisory issued by Fortinet FortiGuard Labs. The vulnerability in question is CVE-2018-9995 (CVSS score: 9.8), a critical authentication bypass issue that could be exploited by remote actors to gain elevated permissions. "The 5-year-old vulnerability (

CISA Issues Advisory on Critical RCE Affecting ME RTU Remote Terminal Units

03 May 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday released an Industrial Control Systems (ICS) advisory about a critical flaw affecting ME RTU remote terminal units. The security vulnerability, tracked as CVE-2023-2131, has received the highest severity rating of 10.0 on the CVSS scoring system for its low attack complexity. "Successful exploitation of this

Hacktivism and the new age of cyber warfare

02 May 2023
By Sergey Shykevich, Threat Intelligence Group Manager, Check Point. Hacktivism has traditionally been associated with loosely managed underground cyber criminal entities. These decentralized and unstructured groups are typically composed of individuals cooperating in support of specific agendas. Over the course of the last year, and following developments in the Russian-Ukrainian conflict, the hacktivist ecosystem has […] The post Hacktivism and the new age of cyber warfare appeared first on CyberTalk.

Promising Jobs at the U.S. Postal Service, ‘US Job Services’ Leaks Customer Data

02 May 2023
A sprawling online company based in Georgia that has made tens of millions of dollars purporting to sell access to jobs at the United States Postal Service (USPS) has exposed its internal IT operations and database of nearly 900,000 customers. The leaked records indicate the network's chief technology officer in Pakistan has been hacked for the past year, and that the entire operation was created by the principals of a Tennessee-based telemarketing firm that has promoted USPS employment websites since 2016.

47% of security leaders use six to 10 communication tools at once

02 May 2023
A survey asked how organizations are responding to emerging threat vectors created by cloud-based communication and collaboration applications.

The future is now! Mind-bending highlights from RSA 2023

02 May 2023
EXECUTIVE SUMMARY: At this year’s RSA Conference, we witnessed some of the brightest minds in cyber security gathered to discuss the latest trends, innovations, challenges and solutions in the field of cyber security. The U.S. event was held in San Francisco, and attracted over 45,000 attendees, making it one of the largest cyber security conferences […] The post The future is now! Mind-bending highlights from RSA 2023 appeared first on CyberTalk.

9 out of 10 companies detected software supply chain security risks

02 May 2023
More than 70% of companies confirm current application security solutions fail to protect from software supply chain security risks, according to a recent report.

Earth Longzhi Returns With New Tricks to Target Organizations in Taiwan, Thailand, the Philippines, and Fiji

02 May 2023
The campaign, which came after months of inactivity, was found to abuse a Windows Defender executable for DLL sideloading and exploit a vulnerable driver, zamguard.sys, to disable security products through a bring-your-own-vulnerable-driver attack.

AI-generated messages claiming to be loved ones are most successful

02 May 2023
The quick rise in various artificial intelligence (AI) platforms have caused a number of security concerns, including online voice scams.

Ransomware Gang Claims Data Theft From Edison Learning

02 May 2023
The Royal ransomware is claiming to have infiltrated public school management and virtual learning provider Edison Learning, posting on its dark web data leak site on Wednesday, April 26, that it had stolen 20GB of the company’s data.

Over half of maintainers unaware of new security standards initiatives

02 May 2023
A report found that open source maintainers are being asked to take on additional work to meet government and industry standards despite little pay.

UK Gun Owners May be Targeted After Rifle Association Breach

02 May 2023
“All our IT systems are fully operational, no funds have been lost and we will communicate fully to our members on the conclusion of the police investigation. We can confirm that this attack has not affected the membership portal...,” the NSRA said.

Data loss costs go up, and not just from ransom shakedowns

02 May 2023
According to BakerHostetler, the average ransom paid hit $600,688, up from $511,957 the year before, though still below the peak of $794,620 in pandemic-ravaged 2020. About 40 percent of victims paid a ransom.

Bluefield University, BridgeValley Community and Technical College, and Penncrest School District Suffer Cyberattacks

02 May 2023
This week, thousands of students at several U.S. schools, such as Bluefield University, BridgeValley Community and Technical College, Penncrest School District, and Truman State University, are feeling the impact of ransomware and other cyberattacks.

Researchers Uncover New BGP Flaws in Popular Internet Routing Protocol Software

02 May 2023
Cybersecurity researchers have uncovered weaknesses in a software implementation of the Border Gateway Protocol (BGP) that could be weaponized to achieve a denial-of-service (DoS) condition on vulnerable BGP peers. The three vulnerabilities reside in version 8.4 of FRRouting, a popular open source internet routing protocol suite for Linux and Unix platforms. It's currently used by several

The warning signs for security analyst burnout and ways to prevent

02 May 2023
Security analysts face the demanding task of investigating and resolving increasing volumes of alerts daily, while adapting to an ever-changing threat landscape and keeping up with new technology.

Fortinet warns of a spike in attacks against TBK DVR devices

02 May 2023
FortiGuard Labs researchers are warning of a spike in malicious attacks targeting TBK DVR devices. Threat actors are attempting to exploit a five-year-old authentication bypass issue, tracked as CVE-2018-9995 (CVSS score of 9.8), in TBK DVR devices.

Data-driven insights help prevent decisions based on fear

02 May 2023
Organizations have strengthened security measures and become more resilient, but threat actors are still finding ways through, according to BakerHostetler. A reduction in ransomware matters in 2022 reversed course by the end of the year.

Australian Law Firm HWL Ebsworth Hit by Russian-linked Ransomware Attack

02 May 2023
Late last week, the ALPHV/Blackcat ransomware group posted on its website that 4TB of company data had been hacked, including employee CVs, IDs, financial reports, accounting data, client documentation, credit card data, and a complete network map.

Security leaders weigh in on school district ransomware attack

02 May 2023
A Minneapolis school district is still dealing with ramifications after being the victim of a ransomware attack earlier this year. Security leaders share their thoughts.