Latest Cybersecurity News and Articles
14 April 2023
While law enforcement action against Genesis resulted in the seizure of at least 10 clearnet domains, its Tor site is still running, and its administrators have indicated they will set up new infrastructure.
14 April 2023
On Thursday, Eduardo (sirdarckcat) Vela Nava, from Google's product security response team, disclosed a Spectre-related security vulnerability in version 6.2 of the Linux kernel.
14 April 2023
Open source media player software provider Kodi has confirmed a data breach after threat actors stole the company's MyBB forum database containing user data and private messages.
What's more, the unknown threat actors attempted to sell the data dump comprising 400,635 Kodi users on the now-defunct BreachForums cybercrime marketplace.
"MyBB admin logs show the account of a trusted but currently
14 April 2023
The report comes around nine months after the town suffered the ransomware attack, which resulted in the town locking down its IT systems and restricting access to email.
14 April 2023
All currently supported releases up to the most recent versions, Windows 11 22H2 and Windows Server 2022, are included in the list of affected Windows server and client releases.
14 April 2023
With the USA reaching the end of its annual tax season, accountants are scrambling to gather clients' tax documents to complete and file their tax returns, making it an ideal time for threat actors to target tax preparers.
14 April 2023
An improper intent handling issue affecting the Kyocera Android printing app can allow malicious applications to drop malware, as reported by the Japanese Vulnerability Notes (JVN).
14 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The two flaws are listed below -
CVE-2023-20963 (CVSS score: 7.8) - Android Framework Privilege Escalation Vulnerability
CVE-2023-29492 (CVSS score: TBD) - Novi Survey Insecure Deserialization Vulnerability
14 April 2023
In today's fast-paced and ever-changing digital landscape, businesses of all sizes face a myriad of cybersecurity threats. Putting in place the right people, technological tools and services, MSSPs are in a great position to ensure their customers' cyber resilience.
The growing need of SMEs and SMBs for structured cybersecurity services can be leveraged by MSPs and MSSPs to provide strategic
13 April 2023
Google on Thursday outlined a set of initiatives aimed at improving the vulnerability management ecosystem and establishing greater transparency measures around exploitation.
"While the notoriety of zero-day vulnerabilities typically makes headlines, risks remain even after they're known and fixed, which is the real story," the company said in an announcement. "Those risks span everything from
13 April 2023
EXECUTIVE SUMMARY: In 2023, the global cost of cyber attacks is expected to exceed $8 trillion dollars. In 2022, cyber attacks increased by nearly 40%, worldwide, as compared to 2021. From large multi-national corporations to government agencies, many entities need help solving for serious security vulnerabilities to avoid significant security incidents. “The main challenge that […]
The post Strengthening security: A comprehensive, consolidated & collaborative approach appeared first on CyberTalk.
13 April 2023
AhnLab has discovered a fresh attack strategy that spreads Qbot malware through malevolent PDF attachments added to replies or forwarded messages in already-existing emails. Qbot or Qakbot follows a destructive attack pattern, shifting from one tactic to another for maximum profits.
13 April 2023
New joint guidance by CISA and other governmental agencies prompts software manufacturers to ship products that are secure-by-design and -default.
13 April 2023
The Dutch Police, in collaboration with international police organizations, has launched an investigation into Raidforums.com, leading to the platform’s shutdown and the seizure of a dataset containing user information.
13 April 2023
Besides using Telegram as a data exfiltration point, Legion is designed to exploit web servers running content management systems (CMS), PHP, or PHP-based frameworks like Laravel.
13 April 2023
The volume of compromised credit cards offered for sale on cybercrime markets has dropped sharply over the past few years, although UK figures rose, according to Cybersixgill.
13 April 2023
Cybersecurity researchers have detailed the tactics of a "rising" cybercriminal gang called "Read The Manual" (RTM) Locker that functions as a private ransomware-as-a-service (RaaS) provider and carries out opportunistic attacks to generate illicit profit.
"The 'Read The Manual' Locker gang uses affiliates to ransom victims, all of whom are forced to abide by the gang's strict rules,"
13 April 2023
When a victim installs a malicious file from one of these sponsored ads, their device is hijacked by the RedLine infostealer, which can then steal confidential data, disrupt critical infrastructure, and compromise financial accounts.
13 April 2023
Popular instant messaging app WhatsApp on Thursday announced a new account verification feature that ensures that malware running on a user's mobile device doesn't impact their account.
13 April 2023
The vulnerability, tracked as CVE-2023-28808, has been described by the vendor as an access control issue that can be exploited to obtain administrator permissions by sending specially crafted messages to the targeted device.