Latest Cybersecurity News and Articles


46 percent of organizations faced synthetic identity fraud in 2022

27 April 2023
New AI technologies have raised a number of security concerns as artificially created audio and video makes it easier to commit identity fraud.

RTM Locker's First Linux Ransomware Strain Targeting NAS and ESXi Hosts

27 April 2023
The Linux flavor is specifically geared to single out ESXi hosts by terminating all virtual machines running on a compromised host prior to commencing the encryption process.

Charming Kitten Spreads BellaCiao Malware for Concentrated Attacks

27 April 2023
Iranian state-sponsored attacker group Charming Kitten introduced a new malware, named BellaCiao, to target individuals across Europe, the Middle East, the U.S., and India. Bitdefender Labs attached every sample of the malware to a distinct victim, suggesting that the group performed highly personalized attacks.

Hackers to show they can take over a European Space Agency satellite

27 April 2023
Cybersecurity researchers will show this week how they seized control of a European Space Agency (ESA) satellite in a demonstration that has been described as the world’s first ethical satellite hacking exercise.

Power Play: Iranian Hackers Execute Attacks with PowerLess Backdoor

27 April 2023
An updated version of PowerLess, a Windows backdoor, has been detected being used by Educated Manticore, a state-sponsored threat actor from Iran, to carry out phishing attacks against Israel. The bait document appears to contain academic information about Iraq from a genuine non-profit organization.

LimeRAT Malware Analysis: Extracting the Config

27 April 2023
Remote Access Trojans (RATs) have taken the third leading position in ANY. RUN's Q1 2023 report on the most prevalent malware types, making it highly probable that your organization may face this threat. Though LimeRAT might not be the most well-known RAT family, its versatility is what sets it apart. Capable of carrying out a broad spectrum of malicious activities, it excels not only in data

Facebook Ads Fuel Evolving Stealer Campaign With Over 500K Estimated Infections

27 April 2023
This threat actor is creating new business profiles, as well as hijacking real, reputable profiles with even millions of followers, and bombards people’s Facebook feeds with malicious click-bates promising adult-rated photo album downloads for free.

PrestaShop fixes bug that lets any backend user delete databases

27 April 2023
The open-source e-commerce platform PrestaShop has released a new version that addresses a critical-severity vulnerability allowing any back-office user to write, update, or delete SQL databases regardless of their permissions.

RTM Locker's First Linux Ransomware Strain Targeting NAS and ESXi Hosts

27 April 2023
The threat actors behind RTM Locker have developed a ransomware strain that's capable of targeting Linux machines, marking the group's first foray into the open source operating system. "Its locker ransomware infects Linux, NAS, and ESXi hosts and appears to be inspired by Babuk ransomware's leaked source code," Uptycs said in a new report published Wednesday. "It uses a combination of ECDH on

Cisco discloses XSS zero-day flaw in server management tool

27 April 2023
Tracked as CVE-2023-20060, the bug was found in the web-based management interface of Cisco PCD 14 and earlier by Pierre Vivegnis of the NATO Cyber Security Centre (NCSC).

BlueNoroff APT Group Targets macOS Users With New RustBucket Malware

27 April 2023
A security company reported that BlueNoroff (a subgroup of Lazarus APT) has introduced a new macOS malware strain it is calling RustBucket. The malware allows attackers to download and execute various payloads. For the first-stage infection, the malware arrives packaged as an unsigned application, whereas it masquerades as a legitimate Apple bundle identifier during the second stage that is signed with an ad-hoc signature.

HiddenAds Spread via Android Gaming Apps on Google Play Store

27 April 2023
These HiddenAds applications discovered on the Google Play Store and installed by at least 35 million users worldwide, have been found to send packets stealthily for advertising revenue in bulk.

Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p Ransomware

27 April 2023
Microsoft has confirmed that the active exploitation of PaperCut servers is linked to attacks designed to deliver Cl0p and LockBit ransomware families. The tech giant's threat intelligence team is attributing a subset of the intrusions to a financially motivated actor it tracks under the name Lace Tempest (formerly DEV-0950), which overlaps with other hacking groups like FIN11, TA505, and Evil

Clop, LockBit ransomware gangs behind PaperCut server attacks

27 April 2023
Today, Microsoft disclosed that the Clop and LockBit ransomware gangs are behind recent attacks on PaperCut servers and using them to steal corporate data from vulnerable servers.

Google Cloud Platform Flaw 'GhostToken' Offers Ghost Entry to Attackers

26 April 2023
Google patched a security hole dubbed GhostToken that affects all the users of Google Cloud Platform (GCP). This flaw enables attackers to gain access to user accounts through the installation of malicious OAuth applications obtained from either the Google Marketplace or third-party providers. Criminals can hide malicious apps by abusing this flaw.

Google Ads Abused to Distribute New LOBSHOT Malware

26 April 2023
Elastic Security Labs has uncovered LOBSHOT, a previously unknown hVNC malware, that impersonates legitimate software for financial gain and is promoted through malvertising, such as Google Ads, to extend their reach and perpetrate their attacks. It targets 32 Chrome extensions, nine Edge wallet extensions, and 11 Firefox wallet extensions, enabling threat actors to steal cryptocurrency assets.

Scammers Use Over 3,000 Fake Facebook Profiles to Lure Victims

26 April 2023
Group-IB spotted a new phishing campaign targeting Facebook users, leveraging 3,200 fake profiles, in an attempt to steal account credentials from public figures, businesses, celebs, and others. The profiles were either created by the actors or were genuinely hacked accounts of users. Of these fake profiles, 1,200 were created in March alone. Users are urged to practice digital hygiene.

Mirai Botnet Variant Explores TP-Link to Grow its Army of DDoS Devices

26 April 2023
The Mirai botnet operators were seen abusing CVE-2023-1389, a vulnerability in the TP-Link Archer A21 (AX1800) WiFi router, and trying to make those devices part of their future DDoS attacks. The initial study of the attack infrastructure revealed targeted devices in the Eastern Europe region, however, the attack campaign could be spreading worldwide. The vulnerability was patched last month by TP-Link.

Google disrupts the CryptBot info-stealing malware operation

26 April 2023
To hinder the spread of CryptBot, a federal court has granted Google a temporary restraining order which allows the company to disrupt the distributors and their infrastructure.

Access management made easy, boosting security with user provisioning

26 April 2023
EXECUTIVE SUMMARY: What is user provisioning? User provisioning enables management teams to control access to business resources, strengthening data security by limiting unnecessary access and allowing only authorized personnel to log in. User provisioning technology can assist management teams in enabling access, managing accounts and revoking access as needed. It simplifies the process of handling […] The post Access management made easy, boosting security with user provisioning appeared first on CyberTalk.