Latest Cybersecurity News and Articles


Infoblox Uncovers DNS Malware Toolkit & Urges Companies to Block Malicious Domains

22 April 2023
Infoblox discovered activity from the remote access trojan (RAT) Pupy active in multiple enterprise networks in early April 2023. This C2 communication went undiscovered since April 2022.

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

22 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The three vulnerabilities are as follows - CVE-2023-28432 (CVSS score - 7.5) - MinIO Information Disclosure Vulnerability  CVE-2023-27350 (CVSS score - 9.8) - PaperCut MF/NG Improper Access Control

N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

22 April 2023
The attack against 3CX first came to light on March 29, 2023, when it emerged that Windows and macOS versions of its communication software were trojanized to deliver a C/C++-based data miner named ICONIC Stealer by means of a downloader, SUDDENICON.

Greening your security: Earth Day tips for cyber security experts

21 April 2023
EXECUTIVE SUMMARY: Celebrate Earth Day 2023! Cyber security professionals are recognizing the role that they can play in supporting environmental initiatives and realizing how sustainability intersects with cyber security. In considering the environmental impact of security-related projects, cyber security professionals can not only contribute to a more sustainable future, but also enhance the overall security […] The post Greening your security: Earth Day tips for cyber security experts appeared first on CyberTalk.

Greening your security: Earth Day tips for cyber security experts

21 April 2023
EXECUTIVE SUMMARY: Celebrate Earth Day 2023! Cyber security professionals are recognizing the role that they can play in supporting environmental sustainability initiatives and realizing how sustainability intersects with cyber security. In considering the environmental impact of security-related initiatives, cyber security professionals can not only contribute to a more sustainable future, but also enhance the overall […] The post Greening your security: Earth Day tips for cyber security experts appeared first on CyberTalk.

University websites using MediaWiki, TWiki hacked to serve Fortnite spam

21 April 2023
Researchers observed Wiki and documentation pages being hosted by universities including Stanford, MIT, Berkeley, UMass Amherst, Northeastern, Caltech, among others, were compromised.

GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

21 April 2023
Cybersecurity researchers have disclosed details of a now-patched zero-day flaw in Google Cloud Platform (GCP) that could have enabled threat actors to conceal an unremovable, malicious application inside a victim's Google account.

American Bar Association data breach hits 1.4 million members

21 April 2023
Thursday night, the ABA began notifying members that a hacker was detected on its network on March 17th, 2023, and may have gained access to members' login credentials for a legacy member system decommissioned in 2018.

Data Security Best-Practice in a World of Evolving Risks and Regulations

21 April 2023
In November last year, there were 95 disclosed data security incidents that resulted in 32 million breached records in Europe alone. Globally, there is a far worse picture. High-profile organizations like Twitter, Uber, and Twilio were hit last year.

Multinational ICICI Bank leaks passports and credit card numbers

21 April 2023
Among the leaked data were bank account details, bank statements, credit card numbers, full names, dates of birth, home addresses, phone numbers, emails, personal identification documents, and employees’ and candidates’ CVs.

DHS outlines national security challenges

21 April 2023
The DHS released the Quadrennial Homeland Security Review (QHSR). The QHSR assesses changes to threats facing the nation since the last review.

ChatGPT-Themed Scam Attacks Are on the Rise

21 April 2023
The dark side of this popularity is that ChatGPT is also attracting the attention of scammers seeking to benefit from using wording and domain names that appear related to the site.

VMware Patches Pre-Auth Code Execution Flaw in Logging Product

21 April 2023
The company shipped urgent patches on Thursday to cover critical security defects in the VMware Aria Operations for Logs (formerly vRealize Log Insight) product line and warned of the risk of pre-authentication remote root exploits.

US Teams Up With Partner Nations to Release Smart City Cyber Guidance

21 April 2023
These guidelines, developed by a group of agencies—including the U.S. CISA, the ACSC, and the U.K NCSC—aim to help communities transitioning into "smart cities" fortify the digital networks crucial to delivering basic utilities and services.

Security beyond software: The open source hardware security evolution

21 April 2023
Some ISAs include built-in security features to mitigate vulnerabilities and attacks, such as hardware-based encryption, memory protection, and data execution prevention.

Massive MitID SMS Phishing Campaign Tries to Phish Nordea Bank Customers

21 April 2023
The data analyzed so far suggests that the threat actor takes advantage of the MitID authentication mechanism in order to redirect the customer to a fake webpage for various malicious actions on target.

Fakecalls Android Malware Abuses Legitimate Signing Key to Sign Malicious Apps

21 April 2023
This threat had been disclosed to the company that owns the legitimate key last year and the company has taken precautions. The company confirmed that they have replaced the signing key and currently, all their apps are signed with a new singing key.

Ex-CEO of hacked therapy clinic sentenced for failing to protect patients' session notes

21 April 2023
The court said that the severity of the crime, and the length of time that the highly sensitive data was not adequately protected from falling into the wrong hands, meant that the former CEO "must receive a prison sentence for the act."

Furniture Rental Startup RentoMojo Reports Data Breach Affecting 150,000 Subscribers

21 April 2023
RentoMojo sent an email to its subscribers stating that the firm has detected a security breach and wrote, "Recently, our team identified a security breach that involved unauthorized access to one of our databases."

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

21 April 2023
A large-scale attack campaign discovered in the wild has been exploiting Kubernetes (K8s) Role-Based Access Control (RBAC) to create backdoors and run cryptocurrency miners. "The attackers also deployed DaemonSets to take over and hijack resources of the K8s clusters they attack," cloud security firm Aqua said in a report shared with The Hacker News. The Israeli company, which dubbed the attack