Latest Cybersecurity News and Articles
02 May 2023
The Online Safety Bill, the United Kingdom’s landmark effort to regulate social media giants, gives regulator Ofcom the power to require tech companies to identify child sex abuse material in private messages.
02 May 2023
After detecting the security breach, T-Mobile proactively reset account PINs for impacted customers and now offers them two years of free credit monitoring and identity theft detection services through Transunion myTrueIdentity.
02 May 2023
A new Android surveillanceware possibly used by the Iranian government has been used to spy on over 300 individuals belonging to minority groups.
The malware, dubbed BouldSpy, has been attributed with moderate confidence to the Law Enforcement Command of the Islamic Republic of Iran (FARAJA). Targeted victims include Iranian Kurds, Baluchis, Azeris, and Armenian Christian groups.
"The spyware
02 May 2023
The telecom industry has always been a tantalizing target for cybercriminals. The combination of interconnected networks, customer data, and sensitive information allows cybercriminals to inflict maximum damage through minimal effort.
It’s the breaches in telecom companies that tend to have a seismic impact and far-reaching implications — in addition to reputational damage, which can be
02 May 2023
The company said no customer, patient, or insured individuals' data had been accessed in the security breach — at least not according to "the current state of knowledge," according to an April 30 update posted on its temporary website.
02 May 2023

The Office of the Australian Information Commissioner will also be restored to a three-commissioner structure after defunding by CoalitionGet our morning and afternoon news emails, free app or daily news podcastThe federal government will appoint a dedicated privacy commissioner to deal with the increasing threat of data breaches, the attorney general has announced.Mark Dreyfus revealed late on Tuesday evening that the Albanese government would also restore the Office of the Australian Information Commissioner (OAIC) to a three-commissioner structure, saying the appointments were necessary to deal with “the growing threats to data security and the increasing volume and complexity of privacy issues”. Continue reading...
02 May 2023
Insider attacks such as fraud, sabotage, and data theft plague 71% of U.S. businesses, according to Capterra. These schemes can cost companies hundreds of thousands of dollars.
02 May 2023
The "rapid security patch" rollout on Monday hasn’t gone so smoothly. Some customers said that they could not install the update. When TechCrunch tested on an iPhone, iPad, and Mac, the updates downloaded but did not immediately install.
02 May 2023
The North Korean threat actor known as ScarCruft began experimenting with oversized LNK files as a delivery route for RokRAT malware as early as July 2022, the same month Microsoft began blocking macros across Office documents by default.
02 May 2023
The three flaws added to the Known Exploited Vulnerabilities (KEV) catalog are CVE-2023-1389 in TP-Link Archer AX-21, CVE-2021-45046 in Apache Log4j2, and CVE-2023-21839 in Oracle WebLogic Server.
02 May 2023
In yet another instance of how threat actors are abusing Google Ads to serve malware, a threat actor has been observed leveraging the technique to deliver a new Windows-based financial trojan and information stealer called LOBSHOT.
"LOBSHOT continues to collect victims while staying under the radar," Elastic Security Labs researcher Daniel Stepanic said in an analysis published last week.
"One
02 May 2023
The North Korean threat actor known as ScarCruft began experimenting with oversized LNK files as a delivery route for RokRAT malware as early as July 2022, the same month Microsoft began blocking macros across Office documents by default.
"RokRAT has not changed significantly over the years, but its deployment methods have evolved, now utilizing archives containing LNK files that initiate
02 May 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The security vulnerabilities are as follows -
CVE-2023-1389 (CVSS score: 8.8) - TP-Link Archer AX-21 Command Injection Vulnerability
CVE-2021-45046 (CVSS score: 9.0) - Apache Log4j2 Deserialization of Untrusted
01 May 2023

Cyberattack resulted in hacking of 4TB of data including IDs, finance reports, accounting data, client documents and credit card detailsFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastThe Australian commercial law firm HWL Ebsworth has fallen victim to a ransomware attack, with Russian-linked hackers claiming to have obtained client information and employee data.Late last week, the ALPHV/Blackcat ransomware group posted on its website that 4TB of company data had been hacked, including employee CVs, IDs, financial reports, accounting data, client documentation, credit card information, and a complete network map.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...
01 May 2023
US Wellness announced it was the victim of a ransomware attack that may have involved protected health information belonging to members of its wellness clients.
01 May 2023
Capita, the country’s largest outsourcing company, holds contracts to administer the payment systems for pension funds used by more than 4 million individuals in Britain.
01 May 2023
"We are working diligently to investigate the incident, confirm its impact on our systems, and securely restore functionality to our environment as soon as possible," the district said in a statement.
01 May 2023
A total of 1.45 million USDC, along with other tokens, was stolen before being bridged to the Ethereum mainnet on Stargate Finance, where it was eventually swapped for ether (ETH).
01 May 2023
EXECUTIVE SUMMARY: Last week, Microsoft’s cyber security division announced that it is changing its taxonomy for naming hacking groups. Previously, Microsoft assigned cyber criminal organizations the names of chemical elements, as listed in the periodic table. In the new system, Microsoft will assign hacker groups two-word names, including a weather-based descriptor. The new names The […]
The post Microsoft’s next-level nomenclature, naming hacking groups appeared first on CyberTalk.
01 May 2023
In addition, the company said it banned 173,000 bad accounts and fended off over $2 billion in fraudulent and abusive transactions through developer-facing features like Voided Purchases API, Obfuscated Account ID, and Play Integrity API.