Latest Cybersecurity News and Articles


Scams are Rising and Rising Fast - Shows FTC 2022 Data

01 March 2023
According to new data from the FTC, U.S. consumers lost $8.8 billion to online fraud in 2022, with investment scams and imposter scams topping the list, causing $3.8 billion and $2.6 billion in losses, respectively. Among the top five fraud schemes, imposter scams topped the list, followed by online shopping scams; prizes, lotteries, and sweepstakes scams; investment scams; and job opportunities. 

Thousands of Asian Texans targeted in driver’s license breach

01 March 2023
The state shipped thousands of Texas driver’s licenses to an international organized crime group in a security lapse that is still under investigation, Department of Public Safety Chief Steve McCraw said Monday.

White House Orders Removal of TikTok on Government Devices Within 30 Days

01 March 2023
The White House is giving all federal agencies 30 days to wipe TikTok off all government devices, as the Chinese-owned social media app comes under increasing scrutiny in Washington over security concerns.

Online Shopping Cart Software Vulnerable: German BSI Report

01 March 2023
An assessment of online shopping cart software used by e-commerce sites performed by the German cybersecurity agency found a slew of vulnerabilities, including code so old it's no longer supported as well as vulnerable JavaScript libraries.

Parallax RAT Targeting Cryptocurrency Firms with Sophisticated Injection Techniques

01 March 2023
Cryptocurrency companies are being targeted as part of a new campaign that delivers a remote access trojan called Parallax RAT. The malware "uses injection techniques to hide within legitimate processes, making it difficult to detect," Uptycs said in a new report. "Once it has been successfully injected, attackers can interact with their victim via Windows Notepad that likely serves as a

Looking Deep into TA569 and its SocGholish Payload

01 March 2023
Proofpoint security analysts have seen changes in the TTPs used by TA569 The changes entail a rise in injection types and a switch to different payloads. The threat group has been observed repeatedly reinfecting websites that have already undergone mitigation for malicious injections. This technique is known as strobing. Researchers have published domain rules for TA569-controlled domains that can be monitored and blocked to prevent the download of malware payloads.

Cracking the code: How to avoid 7 common mistakes in corporate information security

28 February 2023
EXECUTIVE SUMMARY: In today’s digital landscape, corporations are tasked with the responsibility of safeguarding their data from ever-evolving cyber threats. Many corporations still fall prey to avoidable mistakes when it comes to cyber security. These types of errors can result in significant corporate reputational damage, financial losses, and legal ramifications. In this article, we’ll delve […] The post Cracking the code: How to avoid 7 common mistakes in corporate information security appeared first on CyberTalk.

ChromeLoader Operators Hide Malware in VHD Files for Game Cracks

28 February 2023
Researchers spotted a new ChromeLoader malware campaign that is being propagated via VHD files named after popular games, such as ROBLOX, Elden Ring, Call of Duty, Pokemon, Animal Crossing, and others. x hijacks browser searches to show advertisements and later modifies the browser setting and collects credentials and browser data.

26.6 million login credentials obtained by cybercriminals since 2018

28 February 2023
Since 2018, five million people globally had data stolen. A study found that 26.6 million usernames and passwords were obtained by cybercriminals.

Your security staff keep leaving…Fix it now before it causes a breach!

28 February 2023
By Pete Nicoletti, Check Point Field CISO, Americas. Nearly half of cyber security leaders will change jobs by 2025 due to stress and workplace burnout. Here are some tips/advice that I can share with other cyber security professionals to help manage this issue. Get actionable insights into stress and burnout below and put them into […] The post Your security staff keep leaving…Fix it now before it causes a breach! appeared first on CyberTalk.

Clasiopa Group Uses Distinct Toolset to Targeting Asian Research Organizations

28 February 2023
A hacker group, dubbed Clasiopa by the analysts at Broadcom company Symantec, is reportedly launching attacks against organizations in the materials research sector. The group boasts a unique toolset, including the custom Atharvan backdoor. Criminals have also used modified versions of the publicly available Lilith RAT and the Thumbsender hacking tool in this attack.

CISO learning and training: Key insights for security leaders

28 February 2023
Liat Doron is the Vice President of Learning and Training at Check Point Software Technologies. In this exclusive CyberTalk.org interview, Check Point’s Vice President of Learning and Training, Liat Doron, discusses her extraordinary career, leadership opportunities, leadership learning, and how to leverage new educational opportunities to meet evolving business and cyber security needs. Please share […] The post CISO learning and training: Key insights for security leaders appeared first on CyberTalk.

Hackers Claim They Breached T-Mobile More Than 100 Times in 2022

28 February 2023
Three different cybercriminal groups claimed access to internal networks at communications giant T-Mobile in more than 100 separate incidents throughout 2022, new data suggests. In each case, the goal of the attackers was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user's text messages and phone calls to another device.

RIG Exploit Kit Still Infects Enterprise Users via Internet Explorer

28 February 2023
The RIG Exploit Kit is undergoing its most successful period, attempting roughly 2,000 intrusions daily and succeeding in about 30% of cases, the highest ratio in the service's long operational history.

Update: Threat actors leak Activision employee data on hacking forum

28 February 2023
The threat actors claim to have obtained 19,444 unique records from an Activision Azure database and are offering it for free. The leaked data contains names, phone numbers, job titles, locations, and email addresses of Activision employees.

US National Cyber Strategy Pushes Regulation, Aggressive Hack-Back Operations

28 February 2023
The strategy, created by the Office of the National Cyber Director (ONCD), also gives high-level authorization to law enforcement and intelligence agencies to hack into foreign networks to prevent attacks or to retaliate against APT campaigns.

Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites

28 February 2023
The vulnerability is tracked as CVE-2023-26009 in the Houzez plugin and CVE-2023-26540 in the theme. The vendor was informed about the security hole and patched it with the release of versions 2.6.4 (plugin) and 2.7.2 (theme).

Doug Clare hired as ICS Head of Cyber Strategy

28 February 2023
Doug Clare has been appointed Head of Cyber Strategy at ISS Corporate Solutions, Inc. Clare has more than 25 years of cyber risk experience.

CISA Director says tech makers must take more responsibility for safety, design choices

28 February 2023
The head of the CISA called the status quo in cybersecurity today “unsustainable,” saying companies, consumers, and government must collectively shift their expectations to make software and hardware manufacturers responsible for insecure products.

Bitdefender Releases Free Decryptor for MortalKombat Ransomware Strain

28 February 2023
Romanian cybersecurity company Bitdefender has released a free decryptor for a new ransomware strain known as MortalKombat. MortalKombat is a new ransomware strain that emerged in January 2023. It's based on commodity ransomware dubbed Xorist and has been observed in attacks targeting entities in the U.S., the Philippines, the U.K., and Turkey. Xorist, detected since 2010, is distributed as a