Latest Cybersecurity News and Articles


Report: Supplier cyber weaknesses impact big business

19 April 2023
A recent report, State of Cyber Security in the Supply Chain 2023, spotlights the key security weaknesses in the supply chain ecosystem.

Allurity acquires CloudComputing and Securix to expand into new markets

19 April 2023
The former brings a complete and robust offering in identity, zero trust, and information security. The latter adds substantial reinforcement in the areas of identity security, observability, and consultancy.

US, UK Agencies Warn of Nation-State Hackers Using Custom Malware on Cisco Routers

19 April 2023
Jaguar Tooth is a malware injected directly into the memory of Cisco routers running older firmware versions. Once installed, the malware exfiltrates information from the router and provides unauthenticated backdoor access to the device.

Pakistani Hackers Use Linux Malware Poseidon to Target Indian Government Agencies

19 April 2023
The Pakistan-based advanced persistent threat (APT) actor known as Transparent Tribe used a two-factor authentication (2FA) tool used by Indian government agencies as a ruse to deliver a new Linux backdoor called Poseidon. "Poseidon is a second-stage payload malware associated with Transparent Tribe," Uptycs security researcher Tejaswini Sandapolla said in a technical report published this week.

SpecterOps Scores $25M Funding to Secure ID Attack Paths

19 April 2023
The company said the Series A investment was led by Silicon Valley venture outfit Decibel. SpecterOps said the new $25 million cash infusion will be used to expand its services and training products.

Experts temporarily disrupted the RedLine Stealer operations

19 April 2023
ESET researchers announced to have temporarily disrupted the operations of the RedLine Stealer with the help of GitHub. The two companies teamed up with Flare to curb the operations of the malware operators.

Uncovering (and Understanding) the Hidden Risks of SaaS Apps

19 April 2023
Recent data breaches across CircleCI, LastPass, and Okta underscore a common theme: The enterprise SaaS stacks connected to these industry-leading apps can be at serious risk for compromise. CircleCI, for example, plays an integral, SaaS-to-SaaS role for SaaS app development. Similarly, tens of thousands of organizations rely on Okta and LastPass security roles for SaaS identity and access

Safe Security Raises $50M to Bring ML to Risk Quantification

19 April 2023
The Silicon Valley-based company said the Series B funding will allow Safe Security to capitalize on generative artificial intelligence to help nontechnical leaders better understand their organizations security postures.

Microsoft: Iranian hackers behind retaliatory cyberattacks on US orgs

19 April 2023
Microsoft believes the Iranian government is now allowing state-sponsored threat actors more freedom when conducting attacks, leading to an overall increase in cyberattacks.

U.S. and U.K. Warn of Russian Hackers Exploiting Cisco Router Flaws for Espionage

19 April 2023
U.K. and U.S. cybersecurity and intelligence agencies have warned of Russian nation-state actors exploiting now-patched flaws in networking equipment from Cisco to conduct reconnaissance and deploy malware against targets. The intrusions, per the authorities, took place in 2021 and targeted a small number of entities in Europe, U.S. government institutions, and about 250 Ukrainian victims. The

DoJ: China ran troll farm targeting US-based Chinese dissidents

19 April 2023
U.S. authorities allege Chinese operatives ran the campaign from 2016 to the present that willfully caused emotional stress on targets of a harassment campaign along with immediate family members.

Living Off the Land (LOTL) attacks: Detecting ransomware gangs hiding in plain sight

19 April 2023
By mimicking normal behavior, LOTL attacks make it extremely difficult for IT teams and security solutions to detect any signs of malicious activities. Experienced analysts, however, might be able to pick up on subindicate an LOTL attack.

Discarded, not destroyed: Old routers reveal corporate secrets

19 April 2023
In the wrong hands, the data gleaned from the devices – including customer data, router-to-router authentication keys, application lists, and much more – is enough to launch a cyberattack.

Iranian Government-Backed Hackers Targeting U.S. Energy and Transit Systems

19 April 2023
An Iranian government-backed actor known as Mint Sandstorm has been linked to attacks aimed at critical infrastructure in the U.S. between late 2021 to mid-2022. "This Mint Sandstorm subgroup is technically and operationally mature, capable of developing bespoke tooling and quickly weaponizing N-day vulnerabilities, and has demonstrated agility in its operational focus, which appears to align

Critical Flaws in vm2 JavaScript Library Can Lead to Remote Code Execution

19 April 2023
A fresh round of patches has been made available for the vm2 JavaScript library to address two critical flaws that could be exploited to break out of the sandbox protections. Both the flaws – CVE-2023-29199 and CVE-2023-30547 – are rated 9.8 out of 10 on the CVSS scoring system and have been addressed in versions 3.9.16 and 3.9.17, respectively. Successful exploitation of the bugs, which allow

Cyber experts warn of rising threat from irresponsible use of commercial hacking tools over the next five years

18 April 2023
New report from the NCSC assesses the threat to UK industry and society from the use of commercial cyber tools and services.

Heightened threat of state-aligned groups against western critical national infrastructure

18 April 2023
This alert highlights the emerging risk posed by state-aligned adversaries following the Russian invasion of Ukraine.

NCSC warns of emerging threat to critical national infrastructure

18 April 2023
Alert issued warns of the emerging threat from state-aligned groups and the different forms of activity.

What to know: New AI rules in the U.S.

18 April 2023
EXECUTIVE SUMMARY: As the fastest-growing consumer application in history, with more than 100 million monthly active users, ChatGPT has gained the attention of lawmakers and policy analysts around the world. Due to the wave of interest in the technology, the U.S. National Telecommunications and Information Administration (NTIA) is asking for public input regarding how to […] The post What to know: New AI rules in the U.S. appeared first on CyberTalk.

Giving a Face to the Malware Proxy Service ‘Faceless’

18 April 2023
For the past seven years, a malware-based proxy service known as "Faceless" has sold anonymity to countless cybercriminals. For less than a dollar per day, Faceless customers can route their malicious traffic through tens of thousands of compromised systems advertised on the service. In this post we'll examine clues left behind over the past decade by the proprietor of Faceless, including some that may help put a face to the name.