Latest Cybersecurity News and Articles


GitHub debuts pedigree check for npm packages via Actions

20 April 2023
Developers using GitHub Actions to build software packages for NPM can now add a command flag that will publish details about the code's origin. This feature is intended to further enhance the security of the open-source software supply chain.

Point32Health Confirms Service Disruption Due to Ransomware Attack

20 April 2023
A ransomware attack interrupted access to services provided by one of New England's largest healthcare insurers, though the scope of affected customers and data remains unknown.

Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware Attacks

20 April 2023
Fortra, the company behind Cobalt Strike, shed light on a zero-day remote code execution (RCE) vulnerability in its GoAnywhere MFT tool that has come under active exploitation by ransomware actors to steal sensitive data. The high-severity flaw, tracked as CVE-2023-0669 (CVSS score: 7.2), concerns a case of pre-authenticated command injection that could be abused to achieve code execution. The

ChatGPT's Data Protection Blind Spots and How Security Teams Can Solve Them

20 April 2023
In the short time since their inception, ChatGPT and other generative AI platforms have rightfully gained the reputation of ultimate productivity boosters. However, the very same technology that enables rapid production of high-quality text on demand, can at the same time expose sensitive corporate data. A recent incident, in which Samsung software engineers pasted proprietary code into ChatGPT,

Hackers actively exploit critical RCE bug in PaperCut servers

20 April 2023
Print management software developer PaperCut is warning customers to update their software immediately, as hackers are actively exploiting flaws to gain access to vulnerable servers.

npm Packages Abused; GitHub Enhances Security and Verification of Packages

20 April 2023
GitHub has released features for secure vulnerability reporting and npm package provenance. In other news, the Node.js open source package repository, npm, was overwhelmed with fake packages by malicious actors, which caused a temporary denial-of-service (DoS) attack.

Medusa ransomware crew boasts of Microsoft code leak

20 April 2023
"This leak is of more interest to programmers, since it contains the source codes of the following Bing products, Bing Maps and Cortana," the crew wrote on its website, which was screenshotted and shared by Emsisoft threat analyst Brett Callow.

Daggerfly Cyberattack Campaign Hits African Telecom Services Providers

20 April 2023
Telecommunication services providers in Africa are the target of a new campaign orchestrated by a China-linked threat actor at least since November 2022. The intrusions have been pinned on a hacking crew tracked by Symantec as Daggerfly, and which is also tracked by the broader cybersecurity community as Bronze Highland and Evasive Panda. The campaign makes use of "previously unseen plugins from

NSO Group Used 3 Zero-Click iPhone Exploits Against Human Rights Defenders

20 April 2023
Israeli spyware maker NSO Group deployed at least three novel "zero-click" exploits against iPhones in 2022 to infiltrate defenses erected by Apple and deploy Pegasus, according to the latest findings from Citizen Lab. "NSO Group customers widely deployed at least three iOS 15 and iOS 16 zero-click exploit chains against civil society targets around the world," the interdisciplinary laboratory

Threat Actors Rapidly Adopt Web3 IPFS Technology

20 April 2023
Since the content hosted on IPFS is decentralized and distributed, there are challenges in locating and removing malicious content from the ecosystem, making it akin to bullet-proof hosting.

Massive Abuse of an Abandoned Eval PHP WordPress Plugin

20 April 2023
Researchers started observing attackers making use of an unorthodox type of backdoor and reinfection method which would go completely undetected if website monitoring doesn’t happen to include the database.

Instagram scam promises money in exchange for your image

20 April 2023
This scam is all a spin on the much older fake check scam, covered in detail by the FTC. Some of the variations include personal assistant scams, car wrap scams, and overpayments scams.

ChatGPT Account Takeover Bug Allows Hackers To Gain User's Online Account

20 April 2023
An independent security analyst and bug hunter, Nagli (@naglinagli), recently uncovered a critical security vulnerability in ChatGPT that allow attackers to easily exploit the vulnerability and gain complete control of any ChatGPT user’s account.

Why BISOs should oversee policy & report to CROs

19 April 2023
By Edwin Doyle, Global Cyber Security Strategist. Cyber security policy is a comprehensive framework consisting of guidelines, protocols, principles and regulations that aim to safeguard an organization’s information technology infrastructure, networks and sensitive data from a variety of cyber threats; ranging from inadvertent breaches to malicious attacks. Who owns policy? The Chief Risk Officer, typically […] The post Why BISOs should oversee policy & report to CROs appeared first on CyberTalk.

Peace process accelerated Northern Ireland's rise as global cyber security hub, UK cyber chief says

19 April 2023
Northern Ireland continues to play a critical role in securing UK-wide online resilience 25 years after the pivotal accord was signed.

UK and international partners publish joint guidance to help communities create secure smart cities

19 April 2023
New guide, published during CYBERUK 2023, sets out cyber security best practices for creating connected places.

New analysis highlights strength of Ukraine's defence against “unprecedented” Russian offensive

19 April 2023
Report from the European Cyber Conflict Research Initiative (ECCRI) gives new insights into the role of cyber criminals and political hacktivists in a conflict, and critical questions around industry support to Ukraine's cyber resilience.

WhatsApp and Signal unite against online safety bill amid privacy concerns

19 April 2023
The rival chat apps WhatsApp and Signal have joined forces in a rare show of unity to protest against the online safety bill, which they say could undermine the UK’s privacy and safety.

1.2 Million Records and 800 GB of Data From Philippine Police Impacted in Data Breach

19 April 2023
A database containing more than 1.2 million police records and 800 GB of information on people who work or applied for employment in law enforcement in the Philippines appears to have been breached, according to a cybersecurity researcher.

Climate change, cyber security and saving the planet

19 April 2023
EXECUTIVE SUMMARY: Although the topics of climate change and cyber security seem worlds apart, the reality is that they’re deeply interconnected. The intersection of the two fields is a complex and rapidly evolving domain that demands attention from enterprises across industries and market verticals. In this article, we’ll explore key points pertaining to climate change […] The post Climate change, cyber security and saving the planet appeared first on CyberTalk.