Latest Cybersecurity News and Articles


CISO insights on ChatGPT: Game-changer or security threat?

18 April 2023
EXECUTIVE SUMMARY: As the AI revolution continues to sweep the world, OpenAI’s ChatGPT tool has emerged as a groundbreaking force in the realm of natural language processing. With applications spanning across industries and organizations, the possibilities sometimes seem limitless. But with the widespread adoption of AI language models, ChatGPT, and adjacent technologies, concerns around data […] The post CISO insights on ChatGPT: Game-changer or security threat? appeared first on CyberTalk.

Ex-Conti Members and Fin7 APT Join Hands for New Domino Backdoor

18 April 2023
The now-defunct Conti ransomware gang members were observed deploying a new malware strain, dubbed Domino, that appears to have been developed by the FIN7 cybercrime organization. Domino has been active in the wild since at least October 2022. Organizations and security teams need a robust Threat Intelligence Platform (TIP) to identify and understand the scope and extent of such attacks.

Introducing DevOpt: A Multifunctional Backdoor Arsenal

18 April 2023
The malware is currently still in development and is receiving continuous improvement updates designed to make it a more potent and effective tool for attackers and a threat to defenders.

FBI warns of juice jacking at public charge stations

18 April 2023
As business travel rises companies need to remind employees of security risks of plugging in any type of portable media or connected cables.

Eighty-one percent of organizations use at least one cloud environment

18 April 2023
Recent cybersecurity trends were analyzed in a report revealing that 68% of organizations experienced a known cyberattack within the last 12 months.

in2al5d p3in4er is Almost Completely Undetectable

18 April 2023
The component that makes Aurora’s delivery stealthy and dangerous is a highly evasive loader we named “in2al5d p3in4er.” It is compiled with Embarcadero RAD Studio and targets endpoint workstations using an advanced anti-VM technique.

New sandbox escape PoC exploit available for VM2 library, patch now

18 April 2023
A security researcher has released, yet another sandbox escape proof of concept (PoC) exploit that makes it possible to execute unsafe code on a host running the VM2 sandbox.

AI tools like ChatGPT expected to fuel BEC attacks

18 April 2023
Across all BEC attacks seen over the past year, 57% of them relied on language as the main attack vector to get them in front of unsuspecting employees, according to Armorblox.

Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

18 April 2023
While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary's use of the SimpleHelp remote support software in June 2022.

IT staffing shortages concern healthcare organizations

18 April 2023
The covid-19 pandemic has greatly affected the healthcare industry, including staffing shortages within IT departments that put organizations at risk.

Hackers Publish Sensitive Employee Data Stolen During CommScope Ransomware Attack

18 April 2023
The North Carolina–based company, which designs and manufactures network infrastructure products for a range of customers, including hospitals, schools, and U.S. federal agencies, was listed on the data leak site of the Vice Society ransomware gang.

YouTube Videos Distributing Aurora Stealer Malware via Highly Evasive Loader

18 April 2023
Cybersecurity researchers have detailed the inner workings of a highly evasive loader named "in2al5d p3in4er" (read: invalid printer) that's used to deliver the Aurora information stealer malware. "The in2al5d p3in4er loader is compiled with Embarcadero RAD Studio and targets endpoint workstations using advanced anti-VM (virtual machine) technique," cybersecurity firm Morphisec said in a report

PowerShell Data Theft: Vice Society Ransomware's Latest Weapon

18 April 2023
Researchers revealed that the Vice Society ransomware group is utilizing a specialized tool based on PowerShell to escape detection and automate the data extraction process. With the adoption of increasingly sophisticated tools, Vice Society has become a formidable threat to organizations globally.

DeFi Protocol Hundred Finance Loses $7M in Latest Exploit

18 April 2023
Hundred Finance confirmed the exploit on April 15, noting that it had contacted the hacker for negotiations. The platform is also working with security teams to resolve the issue and has urged anyone with information on the incident to reach out.

Cyber venture capital funding slows to a trickle, a sharp decline from 2022 investment

18 April 2023
The flow of venture capital funding to cybersecurity firms hit a steep decline in the first quarter of 2023 compared with year-ago figures, lending more credence to the notion the industry may be oversaturated with vendors and overlapping tools.

Goldoson Android Malware Infects Over 100 Million Google Play Store Downloads

18 April 2023
A new Android malware strain named Goldoson has been detected in the official Google Play Store spanning more than 60 legitimate apps that collectively have over 100 million downloads. An additional eight million installations have been tracked through ONE store, a leading third-party app storefront in South Korea. The rogue component is part of a third-party software library used by the apps in

Creative Software Maker Affinity Informs Customers of Forum Breach

18 April 2023
The company said a hacker gained access to forum user data after compromising an administrator’s account. The attacker may have accessed information such as username, reputation, join date, post count, email addresses, and the last used IP address.

New Chameleon Banking Trojan Targets Android Users in Poland and Australia

18 April 2023
The news Chameleon banking trojan is capable of changing app icon and stealing users' passwords, text messages, and other sensitive data. The malware distribution is ongoing since January and specifically targets users in Poland and Australia. Researchers believe that the trojan is still in its early stages of development and comes with limited capabilities, as of now.

Authorisation software firm Cerbos secures $7.5m

18 April 2023
Cerbos is an open-source authorization layer to implement roles and permissions in software applications. Cerbos Cloud streamlines the implementation and management of authorization policies.

DFIR via XDR: How to expedite your investigations with a DFIRent approach

18 April 2023
Rapid technological evolution requires security that is resilient, up to date and adaptable. In this article, we will cover the transformation in the field of DFIR (digital forensics and incident response) in the last couple years, focusing on the digital forensics' aspect and how XDR fits into the picture. Before we dive into the details, let's first break down the main components of DFIR and