Latest Cybersecurity News and Articles


Three out of top four attack vectors are connected to authentication

03 April 2023
With digitized systems, secure authentication has become a priority. Research found that insecure authentication is a primary cause of data breaches.

71% of employees store sensitive work passwords on personal phones

03 April 2023
Security leaders were surveyed on the use of personal devices for work-related tasks, balancing corporate security and employee privacy.

A Serial Tech Investment Scammer Takes Up Coding?

03 April 2023
John Clifton Davies, a 60-year-old con man from the United Kingdom who fled the country in 2015 before being sentenced to 12 years in prison for fraud, has enjoyed a successful life abroad swindling technology startups by pretending to be a billionaire investor. Davies' newest invention appears to be "CodesToYou," which purports to be a "full cycle software development company" based in the U.K.

Service NSW Breach Exposes Data of Thousands of Customers

03 April 2023
An update released to the “My services” dashboard on March 20 resulted in the data breach, Service NSW chief executive officer Greg Wells said in an email to affected customers shared with AAP on Monday.

People drive women’s feelings of exclusion in cybersecurity

03 April 2023
A recent report by Women in CyberSecurity on the state of inclusion of women in cybersecurity shows 68% cite leadership as a source of exclusion.

Microsoft OneNote Starts Blocking Dangerous File Extensions

03 April 2023
Just like other Office applications, OneNote has been abused for malware delivery, especially since OneNote documents allow attackers to attach files that would be executed with few warnings to the user.

Outsourcer Capita Claims to Have Contained "Cyber Incident"

03 April 2023
Business process outsourcing giant Capita claimed today that a “cyber incident” it experienced on Friday has been largely contained, with services in the process of being restored.

Endpoint security: Challenges, solutions and best practices

03 April 2023
By Anas Baig, product manager and cyber security expert with Securiti. Doing business in the public sphere leaves entities open to malicious attacks. A study conducted by the Ponemon Institute highlights how almost 70% of organizations have been affected by malicious attacks at least once. Many of those companies suffered more than one incident. Ransomware […] The post Endpoint security: Challenges, solutions and best practices appeared first on CyberTalk.

Lumen falls victim to 2 ransomware attacks

03 April 2023
In a recent Securities and Exchange Commission filing, Lumen Technologies, Inc. reported it was the victim of two ransomware attacks.

Managing the risks of unstructured data growth

03 April 2023
Much of the data in the cloud is unstructured and highly vulnerable to cyber threats. Unstructured data can include anything from emails and FedEx receipts to sensor data and social media feeds.

New Money Message Ransomware Demands Million-Dollar Ransoms

03 April 2023
The new ransomware strain was first reported by a victim on the BleepingComputer forums on March 28, 2023, with Zscaler's ThreatLabz soon after sharing information on Twitter.

Bank of England Warns of Potential Cyberattacks on Financial System

03 April 2023
The Bank of England has issued a stern warning to banks, insurers, and market infrastructure companies to take immediate steps to bolster their defenses against a potential major cyberattack.

Western Digital Hit by Network Security Breach Disrupting Critical Services

03 April 2023
While Western Digital did not reveal the exact services that are impacted, the My Cloud status page shows that cloud, proxy, web, authentication, emails, and push notification services are down.

Chinese E-Commerce Giant Pinduoduo Allegedly Spys on Users

03 April 2023
"E-commerce giant Pinduoduo has taken violations of privacy and data security to the next level," CNN reported, citing multiple cybersecurity experts from Asia, Europe, and the United States.

Crypto-Stealing OpcJacker Malware Targets Users with Fake VPN Service

03 April 2023
The most noteworthy capabilities of OpcJacker include keylogging, taking screenshots, stealing sensitive data from browsers, loading additional modules, and replacing cryptocurrency addresses in the clipboard for hijacking purposes.

German Police Raid DDoS-Friendly Host ‘FlyHosting’ – Krebs on Security

03 April 2023
News of a raid on FlyHosting first surfaced Thursday in a Telegram chat channel that is frequented by people interested or involved in the DDoS-for-hire industry, where a user by the name Dstatcc broke the news to Fly Hosting customers.

Western Digital Hit by Network Security Breach - Critical Services Disrupted!

03 April 2023
Data storage devices maker Western Digital on Monday disclosed a "network security incident" that involved unauthorized access to its systems. The breach is said to have occurred on March 26, 2023, enabling an unnamed third party to gain access to a "number of the company's systems." Following the discovery of the hack, Western Digital said it has initiated incident response efforts and enlisted

Fake Ransomware Gang Targets U.S. Organizations With Empty Data Leak Threats

03 April 2023
Fake extortionists are piggybacking on data breaches and ransomware incidents, threatening U.S. companies with publishing or selling allegedly stolen data unless they get paid.

Italian Watchdog Bans OpenAI's ChatGPT Over Data Protection Concerns

03 April 2023
The Italian data protection watchdog, Garante per la Protezione dei Dati Personali (aka Garante), has imposed a temporary ban of OpenAI's ChatGPT service in the country, citing data protection concerns. To that end, it has ordered the company to stop processing users' data with immediate effect, stating it intends to investigate the company over whether it's unlawfully processing such data in

"It's The Service Accounts, Stupid": Why Do PAM Deployments Take (almost) Forever To Complete

03 April 2023
Privileged Access Management (PAM) solutions are regarded as the common practice to prevent identity threats to administrative accounts. In theory, the PAM concept makes absolute sense: place admin credentials in a vault, rotate their passwords, and closely monitor their sessions. However, the harsh reality is that the vast majority of PAM projects either become a years-long project, or even