Latest Cybersecurity News and Articles


Update: San Bernardino County sheriff's office struggling to recover from ‘malware’ incident

26 April 2023
The attack began when an officer clicked on a malicious link, according to ABC7. Officials did not say whether data had been stolen during the attack. No ransomware group has come forward to claim the attack.

Quickpass Rebrands to CyberQP, Raises $12M to Help MSPs with Privileged Access Management

26 April 2023
The company raised an additional $12M from its financial partner, Arthur Ventures, to continue to bring Privileged Access Management to MSPs. According to CEO Mateo Barraza, the rebranding was necessary to accurately portray the company's mission.

Russian hacktivist threat on Canada’s pipelines is ‘call to action,’ top cyber official says

26 April 2023
The incident was revealed in a trove of leaked U.S. intelligence materials that included an apparently intercepted conversation between a hacking group known as Zarya and an officer at Russia’s Federal Security Service (FSB).

Apache Superset Vulnerability: Insecure Default Configuration Exposes Servers to RCE Attacks

26 April 2023
The maintainers of the Apache Superset open source data visualization software have released fixes to plug an insecure default configuration that could lead to remote code execution. The vulnerability, tracked as CVE-2023-27524 (CVSS score: 8.9), impacts versions up to and including 2.0.1 and relates to the use of a default SECRET_KEY that could be abused by attackers to authenticate and access

Token Gets $30M Funding for Biometrics MFA Smart Ring

26 April 2023
The new money comes in the form of a $20M secured note and a $10M convertible note and provides working capital and a runway for Token to compete in a crowded market for enterprise authentication products.

GuLoader returns with a rotten shipment

26 April 2023
In this instance, a fake shipping notification in Italian was observed, humorously reflecting GuLoader's Italian origins. Unlike previous cases, GuLoader was not concealed within a Zip file but rather an ISO file.

Prison Time for 11 Involved in India's Cosmos Bank Heist

26 April 2023
A judicial magistrate first class court in Pune on April 15 passed an order convicting eleven accused of stealing in August 2018 up to $1.76 million from Cosmos Cooperative Bank.

VMware Releases Critical Patches for Workstation and Fusion Software

26 April 2023
VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution.

VMware Releases Critical Patches for Workstation and Fusion Software

26 April 2023
VMware has released updates to resolve multiple security flaws impacting its Workstation and Fusion software, the most critical of which could allow a local attacker to achieve code execution. The vulnerability, tracked as CVE-2023-20869 (CVSS score: 9.3), is described as a stack-based buffer-overflow vulnerability that resides in the functionality for sharing host Bluetooth devices with the

PaperCut Vulnerability Exploited in Active Attacks

25 April 2023
While cybercriminals are exploiting the pair of bugs in PaperCut MF/NG print management software, researchers at cybersecurity firm Horizon3 revealed information about one of the bugs, identified as CVE-2023-27350, and also shared a PoC exploit code. The bug can be effectively exploited by criminals to dodge detection and run arbitrary code on susceptible PaperCut servers. Trend Micro is poised to release further details on the bugs on May 10th.

Beware of Infected (Fake) Installers: BumbleBee Malware Alert

25 April 2023
A recent discovery by cybersecurity experts has revealed a new BumbleBee loader infection campaign that utilizes Google advertisements to promote trojanized versions of widely-used applications. It attempted to spread via fake installers of well-known software such as Zoom, Cisco AnyConnect, ChatGPT, and Citrix Workspace. 

Ongoing OCX#HARVESTER Campaign Targeting Financial Organizations

25 April 2023
Security analysts uncovered a new attack campaign, tracked as OCX#HARVESTER, wherein malicious payloads used as part of the campaign were found related to the More_eggs backdoor. Based on the targeted victims and the modus operandi of the More_eggs malware, researchers associated the campaign with FIN6 APT. 

Inaugural Attacks Exploit Kubernetes RBAC to Deploy Backdoor

25 April 2023
Cloud security firm Aqua uncovered a massive crypto-mining campaign that creates backdoors and runs miners using Kubernetes (K8s) Role-Based Access Control (RBAC). In this attack, threat actors also check for the presence of other miner malware on the server and then establish persistence using the RBAC. Additionally, they deploy DaemonSets to access resources of the K8s clusters.

Decoy Dog: An Enterprise-targeting Malware Toolkit

25 April 2023
Decoy Dog, a new enterprise-targeting malware toolkit, is using DNS query dribbling and strategic domain aging techniques to bypass security checks and target enterprises. Researchers have shared IOCs on its public GitHub repository which can be helpful for security teams.

Fakecalls Gets Sneakier, Abuses Stolen App Keys

25 April 2023
Fakecalls banking trojan has been targeting South Korean organizations via fake apps; this time it is abusing legitimate app signing keys to bypass signature-based detection techniques. To avoid detection, the malware uses a packer to encrypt its source code. Stay safe by downloading apps from the official stores and reliable sources only.

10 new and dangerous malware threats to watch out for (2023 edition)

25 April 2023
EXECUTIVE SUMMARY: Discover 10 of the most dangerous malware threats and learn how to identify, prevent and defend against attacks. Malware-based attacks pose a significant risk to 80% of small-to-medium sized businesses, while larger organizations are becoming increasingly vulnerable to dangerous and damaging incidents. Stay informed in order to safeguard your organization. Types of malware […] The post 10 new and dangerous malware threats to watch out for (2023 edition) appeared first on CyberTalk.

Insecure Default Configuration in Apache Superset Leads to Remote Code Execution

25 April 2023
Researchers found that a majority of internet-exposed instances of Apache Superset – at least 2000 (two-thirds of all servers) – are running with a dangerous default configuration. This means many of these servers are effectively open to the public.

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

25 April 2023
The top 10 countries with the most organizations having vulnerable SLP instances are the U.S., the U.K., Japan, Germany, Canada, France, Italy, Brazil, the Netherlands, and Spain.

Security leaders weigh in on CommScope breach

25 April 2023
Last week hackers published data stolen from CommScope through a ransomware attack. Among the stolen data was employee’s Social Security numbers and bank account details.

Iranian Hackers Launch Sophisticated Attacks Targeting Israel with PowerLess Backdoor

25 April 2023
The attack chain documented by Check Point begins with an ISO disk image file that makes use of Iraq-themed lures to drop a custom in-memory downloader that ultimately launches the PowerLess implant.