Latest Cybersecurity News and Articles


Hybrid work environments are stressing CISOs

13 April 2023
The impact of the hybrid workforce on security posture, as well as the risks introduced by this way of working, are posing concerns for CISOs and driving them to develop new strategies for hybrid work security, according to Red Access.

Lazarus Hacker Group Evolves Tactics, Tools, and Targets in DeathNote Campaign

13 April 2023
The North Korean threat actor known as the Lazarus Group has been observed shifting its focus and rapidly evolving its tools and tactics as part of a long-running activity called DeathNote. While the nation-state adversary is known for its persistent attacks on the cryptocurrency sector, it has also targeted automotive, academic, and defense sectors in Eastern Europe and other parts of the world

Russian hackers ‘target security cameras inside Ukraine coffee shops’

13 April 2023
Russians hackers have logged into private security cameras in Ukraine coffee shops to collect intelligence on aid convoys passing by, a top US security official said on Tuesday.

FDA to medical device manufacturers: ‘Get your house in order’

13 April 2023
By October 1, the Food and Drug Administration will have tackled two critical medical device security issues: new submissions designed without security in mind and SBOMs to direct network defenders on where these vulnerabilities lie.

RedLine Stealer Spotted in a New Campaign Leveraging ChatGPT

13 April 2023
Cybercriminals were found using ChatGPT and Google Bard's popularity to spread the RedLine Stealer malware in at least 10 countries and steal private user information. The highest number of impacted users are in Greece, followed by those in India, the U.S. Mexico, and Bangladesh.

CISA to unveil secure-by-design principles this week amid push for software security

13 April 2023
The CISA plans to release an overview of the Biden administration’s secure-by-design principles Thursday, providing the technology industry with a roadmap to hold software producers and other manufacturers accountable for product security.

Fake Chrome Updates Used for Malware Distribution

13 April 2023
If you get a Google Chrome automatic update failure pop-up on your screen, be cautious. It might just be hackers waiting to compromise your systems to mine Monero. The campaign began in November 2022, however, went a little aggressive after February 2023.

ChatGPT Security: OpenAI's Bug Bounty Program Offers Up to $20,000 Prizes

13 April 2023
OpenAI, the company behind the massively popular ChatGPT AI chatbot, has launched a bug bounty program in an attempt to ensure its systems are "safe and secure." To that end, it has partnered with the crowdsourced security platform Bugcrowd for independent researchers to report vulnerabilities discovered in its product in exchange for rewards ranging from "$200 for low-severity findings to up to

UK and international partners share advice to help turn the dial on tech product security

12 April 2023
New guide calls on manufacturers to ensure technology products are made secure by design and by default.

Were you caught up in the latest data breach? Here's how to tell

12 April 2023
Wondering if your information was posted online from a data breach? Here's how to check if your accounts are at risk and what to do next.

Blue-chip insights: The value of a CIO & CDO alliance

12 April 2023
EXECUTIVE SUMMARY: The partnership between the Chief Information Officer (CIO) and the Chief Data Officer (CDO) is critical in today’s data-driven business landscape. The CIO is responsible for technology infrastructure and development, while the CDO oversees an organization’s information strategy, information governance initiatives, and ensures that data remains actionable. In short, the CIO and the […] The post Blue-chip insights: The value of a CIO & CDO alliance appeared first on CyberTalk.

A leak of files could be America’s worst intelligence breach in a decade

12 April 2023
The leaked files, which include military assessments on the war in Ukraine and CIA reports on a range of global issues, came to widespread attention when some appeared on Telegram, a messaging app widely used in Russia.

Why the EU Should Stop Talking About Digital Sovereignty

12 April 2023
Instead of pursuing digital sovereignty, the EU should adopt the concept of digital responsibility, which emphasizes fostering cybersecurity partnerships with trusted organizations outside of government.

Fortinet Patches Critical Vulnerability in Data Analytics Solution

12 April 2023
Cybersecurity solutions provider Fortinet this week announced the release of security updates across multiple products, including patches for a critical vulnerability in FortiPresence.

Announcing the deps.dev API: critical dependency data for secure supply chains

12 April 2023
As part of Google’s ongoing efforts to improve open-source security, the Open Source Insights team has built a reliable view of software metadata across five packaging ecosystems.

Following the Lazarus group by tracking DeathNote campaign

12 April 2023
This threat cluster linked to the North Korean threat actor Lazarus is also known as Operation DreamJob or NukeSped. It's dubbed DeathNote after its malware payloads named Dn.dll or Dn64.dll.

FTX bankruptcy filing highlights security failures

12 April 2023
Debtors claim that the defunct cryptocurrency exchange FTX lacked any dedicated security personnel and failed to implement critical access controls for billions of dollars in assets.

Criminals Pose as Chinese Authorities to Target US-based Chinese Community

12 April 2023
Criminals exploit widely publicized efforts by the People’s Republic of China government to harass and facilitate the repatriation of individuals living in the United States to build plausibility for their fraud.

How machine learning algorithms detect ransomware attacks

12 April 2023
By Zac Amos, Features Editor, Rehack.com. How can businesses and users stay ahead of the ever-evolving risk of ransomware attacks? An increasing number of cyber attacks occur every year, posing a serious threat to users’ privacy and financial well-being. Fortunately, machine learning can give users an edge over hackers using pattern recognition and behavioral analysis. Leveraging pattern […] The post How machine learning algorithms detect ransomware attacks appeared first on CyberTalk.

IRS acting CIO: Securing software supply chain remains a challenge for agencies

12 April 2023
Finding the right balance between encouraging innovation within development teams and securing the software supply chain remains a challenge for federal agencies, according to the acting chief information officer of the IRS.