Latest Cybersecurity News and Articles


New Chameleon Android Malware Mimics Banking, Government, and Crypto Apps

18 April 2023
The mobile malware was discovered by cybersecurity firm Cyble, which reports seeing distribution through compromised websites, Discord attachments, and Bitbucket hosting services.

Montana on cusp of becoming first state to block TikTok downloads

18 April 2023
The bill, SB 419, makes it illegal for app stores to give users the option to download the app and also illegal for the company to operate within the state. The bill does not, however, make it illegal for people who already have TikTok to use it.

An Analysis of the BabLock Ransomware

18 April 2023
Although primarily based on LockBit, the ransomware is a hodgepodge of other different ransomware parts pieced together into what Trend Micro security researchers now call BabLock.

Update: Black Basta claims it's selling off stolen Capita data

18 April 2023
Black Basta, the extortionists who claimed they were the ones who lately broke into Capita, have reportedly put up for sale sensitive details, including bank account information, addresses, and passport photos, stolen from the IT outsourcing giant.

Phishing Attacks Surge as Threat Actors Leverage New AI Tools

18 April 2023
Phishing campaigns worldwide rose nearly 50% in 2022 compared to 2021 driven partly by phishing kits and new AI tools accessible to threat actors, according to zero trust security vendor Zscaler’s ThreatLabz Phishing Report.

Iranian Hackers Using SimpleHelp Remote Support Software for Persistent Access

18 April 2023
The Iranian threat actor known as MuddyWater is continuing its time-tested tradition of relying on legitimate remote administration tools to commandeer targeted systems. While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary's use of the SimpleHelp remote support software in June 2022. MuddyWater,

Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose

18 April 2023
Israeli spyware vendor QuaDream is allegedly shutting down its operations in the coming days, less than a week after its hacking toolset was exposed by Citizen Lab and Microsoft.

HHS updates cybersecurity best practices, shares free workforce training

18 April 2023
The Health Industry Cybersecurity Practices (HICP), one of the most critical cybersecurity resources for healthcare provider organizations, has been updated with two additional volumes and supporting mitigation resources.

LockBit Ransomware Now Targeting Apple macOS Devices

18 April 2023
Threat actors behind the LockBit ransomware operation have developed new artifacts that can encrypt files on devices running Apple's macOS operating system. The development, which was reported by the MalwareHunterTeam over the weekend, appears to be the first time a big-game ransomware crew has created a macOS-based payload. Additional samples identified by vx-underground show that the macOS

APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on Cisco routers

17 April 2023
APT28 accesses poorly maintained Cisco routers and deploys malware on unpatched devices using CVE-2017-6742.

UK and US issue warning about APT28 actors exploiting poorly maintained Cisco routers

17 April 2023
Joint advisory calls on organisations to secure devices to prevent network attacks.

Collaboration only way to respond to cyber threats says renowned tech entrepreneur

17 April 2023
The interview with Hermann Hauser will be aired later this week at the NCSC's cyber security conference CYBERUK, held in Belfast.

7 tips for tackling cyber security technical debt

17 April 2023
EXECUTIVE SUMMARY: The cyber risk landscape is evolving. Novel attack types are appearing at an unprecedented rate. Cyber criminals are constantly seeking new ways to infiltrate networks, paralyze systems, steal data and drive their own financial gains. As organizations race to keep up with emerging threats, it’s all-too-common for security leaders to ignore the growing […] The post 7 tips for tackling cyber security technical debt appeared first on CyberTalk.

Understanding the Threat of Titan Stealer Malware

17 April 2023
The malware spreads through methods like phishing, malicious ads, and cracked software. It also uses a technique called process hollowing to inject the malicious code into a legitimate process called AppLaunch.exe.

China-linked APT41 group spotted using open-source red teaming tool GC2

17 April 2023
In October 2022, threat actors sent phishing emails that contained links to a password-protected file hosted in Drive. The final payload was the Go-written GC2 tool that gets commands from Google Sheets and exfiltrates data to Google Drive.

ZeroFox to Acquire Threat Intelligence Firm LookingGlass for $26 Million

17 April 2023
ZeroFox (ZFOX), which advertises itself as an external cybersecurity solutions provider, on Monday, announced that it’s in the process of acquiring threat intelligence and attack surface management company LookingGlass.

New Captcha Protected Phishing Attack Targets Access to Payroll Files

17 April 2023
The phishing attack is hosted on a landing page at payroll-microsoft365-access-panel-2023[.]softr[.]app/ which redirects to azaleastays[.]com/devr365web2023/ once a button is clicked.

Twitter no longer exists, it’s just X Corp. now

17 April 2023
EXECUTIVE SUMMARY: In a move sparking intense speculation, Twitter technically “no longer exists” after a merge with X Corp., according to a document submitted to a California court earlier this month. What the change means for Twitter is unclear. In the past, Twitter’s owner, Elon Musk, suggested that purchasing the company would accelerate plans to […] The post Twitter no longer exists, it’s just X Corp. now appeared first on CyberTalk.

Cybersecurity leaders reflect on Samsung, ChatGPT incidents

17 April 2023
After it was discovered that three Samsung employees shared company information with ChatGPT, cybersecurity leaders are sharing their thoughts. 

FIN7 and Ex-Conti Cybercrime Gangs Join Forces in Domino Malware Attacks

17 April 2023
The latest intrusion wave, spotted by IBM Security X-Force two months ago, involves the use of Dave Loader, a crypter previously attributed to the Conti group (aka Gold Blackburn, ITG23, or Wizard Spider), to deploy the Domino backdoor.