Latest Cybersecurity News and Articles
19 April 2023
A recent report, State of Cyber Security in the Supply Chain 2023, spotlights the key security weaknesses in the supply chain ecosystem.
19 April 2023
The former brings a complete and robust offering in identity, zero trust, and information security. The latter adds substantial reinforcement in the areas of identity security, observability, and consultancy.
19 April 2023
Jaguar Tooth is a malware injected directly into the memory of Cisco routers running older firmware versions. Once installed, the malware exfiltrates information from the router and provides unauthenticated backdoor access to the device.
19 April 2023
The Pakistan-based advanced persistent threat (APT) actor known as Transparent Tribe used a two-factor authentication (2FA) tool used by Indian government agencies as a ruse to deliver a new Linux backdoor called Poseidon.
"Poseidon is a second-stage payload malware associated with Transparent Tribe," Uptycs security researcher Tejaswini Sandapolla said in a technical report published this week.
19 April 2023
The company said the Series A investment was led by Silicon Valley venture outfit Decibel. SpecterOps said the new $25 million cash infusion will be used to expand its services and training products.
19 April 2023
ESET researchers announced to have temporarily disrupted the operations of the RedLine Stealer with the help of GitHub. The two companies teamed up with Flare to curb the operations of the malware operators.
19 April 2023
Recent data breaches across CircleCI, LastPass, and Okta underscore a common theme: The enterprise SaaS stacks connected to these industry-leading apps can be at serious risk for compromise.
CircleCI, for example, plays an integral, SaaS-to-SaaS role for SaaS app development. Similarly, tens of thousands of organizations rely on Okta and LastPass security roles for SaaS identity and access
19 April 2023
The Silicon Valley-based company said the Series B funding will allow Safe Security to capitalize on generative artificial intelligence to help nontechnical leaders better understand their organizations security postures.
19 April 2023
Microsoft believes the Iranian government is now allowing state-sponsored threat actors more freedom when conducting attacks, leading to an overall increase in cyberattacks.
19 April 2023
U.K. and U.S. cybersecurity and intelligence agencies have warned of Russian nation-state actors exploiting now-patched flaws in networking equipment from Cisco to conduct reconnaissance and deploy malware against targets.
The intrusions, per the authorities, took place in 2021 and targeted a small number of entities in Europe, U.S. government institutions, and about 250 Ukrainian victims.
The
19 April 2023
U.S. authorities allege Chinese operatives ran the campaign from 2016 to the present that willfully caused emotional stress on targets of a harassment campaign along with immediate family members.
19 April 2023
By mimicking normal behavior, LOTL attacks make it extremely difficult for IT teams and security solutions to detect any signs of malicious activities. Experienced analysts, however, might be able to pick up on subindicate an LOTL attack.
19 April 2023
In the wrong hands, the data gleaned from the devices – including customer data, router-to-router authentication keys, application lists, and much more – is enough to launch a cyberattack.
19 April 2023
An Iranian government-backed actor known as Mint Sandstorm has been linked to attacks aimed at critical infrastructure in the U.S. between late 2021 to mid-2022.
"This Mint Sandstorm subgroup is technically and operationally mature, capable of developing bespoke tooling and quickly weaponizing N-day vulnerabilities, and has demonstrated agility in its operational focus, which appears to align
19 April 2023
A fresh round of patches has been made available for the vm2 JavaScript library to address two critical flaws that could be exploited to break out of the sandbox protections.
Both the flaws – CVE-2023-29199 and CVE-2023-30547 – are rated 9.8 out of 10 on the CVSS scoring system and have been addressed in versions 3.9.16 and 3.9.17, respectively.
Successful exploitation of the bugs, which allow
18 April 2023
New report from the NCSC assesses the threat to UK industry and society from the use of commercial cyber tools and services.
18 April 2023
This alert highlights the emerging risk posed by state-aligned adversaries following the Russian invasion of Ukraine.
18 April 2023
Alert issued warns of the emerging threat from state-aligned groups and the different forms of activity.
18 April 2023
EXECUTIVE SUMMARY: As the fastest-growing consumer application in history, with more than 100 million monthly active users, ChatGPT has gained the attention of lawmakers and policy analysts around the world. Due to the wave of interest in the technology, the U.S. National Telecommunications and Information Administration (NTIA) is asking for public input regarding how to […]
The post What to know: New AI rules in the U.S. appeared first on CyberTalk.
18 April 2023
For the past seven years, a malware-based proxy service known as "Faceless" has sold anonymity to countless cybercriminals. For less than a dollar per day, Faceless customers can route their malicious traffic through tens of thousands of compromised systems advertised on the service. In this post we'll examine clues left behind over the past decade by the proprietor of Faceless, including some that may help put a face to the name.