Latest Cybersecurity News and Articles


Access management made easy, boosting security with user provisioning

26 April 2023
EXECUTIVE SUMMARY: What is user provisioning? User provisioning enables management teams to control access to business resources, strengthening data security by limiting unnecessary access and allowing only authorized personnel to log in. User provisioning technology can assist management teams in enabling access, managing accounts and revoking access as needed. It simplifies the process of handling […] The post Access management made easy, boosting security with user provisioning appeared first on CyberTalk.

The Anatomy of a Scalping Bot: NSB Was Copped!

26 April 2023
For the past eight years, NSB has been used by bot operators to acquire limited edition and hard-to-find items from over 100 online shops. It's considered one of the best scalping bots available on the market, with an annual price of $499.

One out of every 10 attacks targeted non-production environments

26 April 2023
Datadog released its 2023 State of Application Security Report analyzing the current vulnerabilities and threats targeting DevOps organizations.

Chinese Hackers Spotted Using Linux Variant of PingPull in Targeted Cyberattacks

26 April 2023
The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033. That's according to findings from Palo Alto Networks Unit 42, which discovered recent malicious cyber activity carried out by the group targeting South Africa and Nepal. Alloy Taurus is the constellation-themed moniker assigned to a

FIN7 Hackers Caught Exploiting Recent Veeam Backup & Replication Vulnerability

26 April 2023
At the end of March 2023, WithSecure caught FIN7 attacks that exploited internet-facing servers running Veeam Backup & Replication software to execute payloads on the compromised environment.

Teenagers, young adults pose prevalent cyberthreat to US, Mandiant says

26 April 2023
A group of teenagers and individuals in their 20s from the U.S. and the U.K are among the most prevalent threat actors today, Mandiant Consulting CTO Charles Carmakal said Monday at an off-site media briefing during the RSA Conference.

Charming Kitten APT Uses BellaCiao Malware to Target Victims in US, Europe, Middle East, and India

26 April 2023
This malware is tailored to suit individual targets and exhibits a higher level of complexity, evidenced by a unique communication approach with its command-and-control (C2) infrastructure.

Attackers are logging in instead of breaking in

26 April 2023
Cyberattackers leveraged more than 500 unique tools and tactics in 2022, according to Sophos. The data was analyzed from more than 150 Sophos Incident Response (IR) cases.

EMV payments grew more than 350 percent in the last year

26 April 2023
When it comes to preventing theft and fraud, security leaders need to consider how different transaction methods require different security measures. 

Bill proposes new DHS centers for testing security of critical government tech

26 April 2023
The Critical Technology Security Centers Act of 2023 introduced Tuesday by Rep. Ritchie Torres (D-N.Y.) would create two cybersecurity-focused offices to evaluate and test the security of critical technology used by the federal government.

Charming Kitten's New BellaCiao Malware Discovered in Multi-Country Attacks

26 April 2023
The prolific Iranian nation-state group known as Charming Kitten targeted multiple victims in the U.S., Europe, the Middle East and India with a novel malware dubbed BellaCiao, adding to its ever-expanding list of custom tools. Discovered by Bitdefender Labs, BellaCiao is a "personalized dropper" that's capable of delivering other malware payloads onto a victim machine based on commands received

Evasive Panda APT Group Delivers Malware via Updates for Popular Chinese Software

26 April 2023
ESET Research uncovered a campaign by the APT group known as Evasive Panda targeting an international NGO in China with malware delivered through updates of popular Chinese software.

ViperSoftX Upgraded with Sophisticated Anti-Detection Techniques

26 April 2023
There has been a significant number of victims in the consumer and enterprise sectors in Australia, Japan, and the U.S. after information-stealer ViperSoftX adopted new anti-detection capabilities. The enterprise sector made up over 40% of the total number of affected victims. The latest version of the info-stealer comes with the capability to steal passwords from two password managers such as KeePass 2 and 1Password.

Report reveals 65% of cyberattacks targeted at U.S.

26 April 2023
A new report reveals an increase in cyberattacks directed at financial institutions, food retailers and healthcare providers, with 60% of all attacks targeting these three key industries.

Attackers Use Containers for Financial Gains via TrafficStealer

26 April 2023
In a recent analysis, Trend Micro came across an unfamiliar program running in the background on their honeypot. It was meant to generate money by driving traffic to specific websites and engaging with ads.

Most SaaS adopters exposed to browser-borne attacks

26 April 2023
Organizations in the cloud are exposed to web-borne attacks. 87% of all-SaaS adopters and 79% of CISOs in a hybrid environment experienced a web-borne security threat in the past 12 months, according to a global survey by LayerX.

Chinese Hackers Using MgBot Malware to Target International NGOs in Mainland China

26 April 2023
The advanced persistent threat (APT) group referred to as Evasive Panda has been observed targeting an international non-governmental organization (NGO) in Mainland China with malware delivered via update channels of legitimate applications like Tencent QQ. The attack chains are designed to distribute a Windows installer for MgBot malware, ESET security researcher Facundo Muñoz said in a new

Chinese Hackers Deploy New Linux Malware Variants for Espionage

26 April 2023
Chinese APT group Gallium is deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.'

Browser Security Survey: 87% of SaaS Adopters Exposed to Browser-borne Attacks

26 April 2023
The browser serves as the primary interface between the on-premises environment, the cloud, and the web in the modern enterprise. Therefore, the browser is also exposed to multiple types of cyber threats and operational risks.  In light of this significant challenge, how are CISOs responding? LayerX, Browser Security platform provider, has polled more than 150 CISOs across multiple verticals and

NetRise raises $8 million to advance XIoT security technology

26 April 2023
NetRise announced $8 million in funding, led by Squadra Ventures, with participation by existing major investors Miramar Digital Ventures, Sorenson Ventures, and DNX Ventures.