Latest Cybersecurity News and Articles
24 April 2023
As generative AI tools like OpenAI ChatGPT and Google Bard continue to dominate the headlines—and pundits debate whether the technology has taken off too quickly without necessary guardrails—cybercriminals are showing no hesitance in exploiting them.
24 April 2023
The threat actor targets government and diplomatic entities in the CIS. The few victims discovered in other regions (Middle East or Southeast Asia) turn out to be foreign representations of CIS countries, illustrating Tomiris’s narrow focus.
24 April 2023
Attack trends such as brute forcing, carding, credential stuffing, inventory hoarding, scalping and web scraping were analyzed in a recent report.
24 April 2023
The most severe of the two issues is CVE-2022-36963 (CVSS score of 8.8), which is described as a command injection bug in SolarWinds’ infrastructure monitoring and management solution.
24 April 2023
ViperSoftX, a type of information-stealing software, has been primarily reported as focusing on cryptocurrencies, making headlines in 2022 for its execution technique of hiding malicious code inside log files.
24 April 2023
In this exclusive CyberTalk.org interview, Idan Eden, the ESG Manager for Check Point, shares her expertise on the rapidly growing importance of ESG in corporate decision-making. As a highly knowledgeable ESG Manager, Idan is at the forefront of this trend. She helps Check Point build an ESG strategy that not only reduces risks and enhances […]
The post The ESG Manager role & the importance of Environmental, Social & Governance strategy appeared first on CyberTalk.
24 April 2023
The Russian-speaking threat actor behind a backdoor known as Tomiris is primarily focused on gathering intelligence in Central Asia, fresh findings from Kaspersky reveal.
"Tomiris's endgame consistently appears to be the regular theft of internal documents," security researchers Pierre Delcher and Ivan Kwiatkowski said in an analysis published today. "The threat actor targets government and
24 April 2023
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) software by means of a Bring Your Own Vulnerable Driver (BYOVD) attack.
"The AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying
24 April 2023
The impacted product provides a data interface between remote field devices and the control center through a cellular network. According to CISA, the product is used worldwide in industries such as energy, transportation, and water and wastewater.
24 April 2023
Across all industries, these vulnerabilities, composed of unprotected or compromised assets, data, and credentials, have proven to be an increasing challenge for organizations to detect and secure.
24 April 2023
Eurocontrol confirmed its website has been "under attack" since April 19, and said "pro-Russian hackers" had claimed responsibility for it. "The attack is causing interruptions to the website and web availability," a spokesperson told The Register.
24 April 2023
CISA has released a joint guide on cybersecurity best practices intended to help communities navigate through the complexities of becoming a smart city.
24 April 2023
A recent review by Wing Security, a SaaS security company that analyzed the data of over 500 companies, revealed some worrisome information. According to this review, 84% of the companies had employees using an average of 3.5 SaaS applications that were breached in the previous 3 months. While this is concerning, it isn't much of a surprise. The exponential growth in SaaS usage has security and
24 April 2023
Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to surreptitiously backdoor websites as part of an ongoing campaign, Sucuri revealed in a report published last week.
The plugin in question is Eval PHP, released by a developer named flashpixx. It allows users to insert PHP code pages and posts of WordPress sites that's then executed every time the posts are
24 April 2023
Trigona ransomware operators are targeting unsecured and internet-exposed Microsoft SQL (MS-SQL) servers, discovered AhnLab. They breach servers via brute-force attacks to crack account credentials. Before encryption, the attackers claim to steal sensitive documents that will be added to dark web leak sites if the ransom is not paid.
24 April 2023
Black Basta ransomware and extortion gang claims responsibility for the attack and has posted sensitive documents and data over the weekend, including ID documents, tax documents, sales and purchase agreements, and more.
24 April 2023
Just as criminals in the physical world are known to insert themselves into criminal investigations, cybercriminals read publicly available Open Source Intelligence (OSINT) and analyst reports.
24 April 2023
CYFIRMA detected a cyberattack in Kashmir, India, linked to the DoNot APT group that used third-party file-sharing websites to spread malware disguised as chat apps named Ten Messenger and Link Chat QQ. The malware's source code was well obfuscated and protected with the Pro Guard code obfuscator utility. It is suggested to implement multiple layers of security to minimize the impact of this threat.
24 April 2023
Money mules, individuals whose bank accounts are used by fraudsters to transfer money, are becoming an increasingly prominent aspect of cybercriminals’ economic business models too.
24 April 2023
Halcyon announced that it raised $44 million in a Series A funding round (plus $6 million in debt) led by SYN Ventures and Corner Ventures, with participation from Dell Technologies Capital.