Latest Cybersecurity News and Articles


CISA Issues Warning on Active Exploitation of ZK Java Web Framework Vulnerability

28 February 2023
Tracked as CVE-2022-36537 (CVSS score: 7.5), the issue impacts ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1, and allows threat actors to retrieve sensitive information via specially crafted requests.

CISA Issues Warning on Active Exploitation of ZK Java Web Framework Vulnerability

28 February 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity flaw affecting the ZK Framework to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Tracked as CVE-2022-36537 (CVSS score: 7.5), the issue impacts ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1, and allows threat actors to retrieve sensitive

Trojanized macOS Apps Distribute Cryptojacking Malware

28 February 2023
A malicious version of Final Cut Pro that largely went unnoticed by antivirus engines is being used by cybercriminals to mine cryptocurrency on macOS systems. There have been dozens of uploads from 2019 and 2021 that were injected with a malicious payload to surreptitiously mine cryptocurrency. Despite an earlier iteration being a known quantity to the security community, most of the security products from different vendors could not detect malicious applications.

LastPass Reveals Second Attack Resulting in Breach of Encrypted Password Vaults

28 February 2023
LastPass, which in December 2022 disclosed a severe data breach that allowed threat actors to access encrypted password vaults, said it happened as a result of the same adversary launching a second attack on its systems. The company said one of its DevOps engineers had their personal home computer breached and infected with a keylogger as part of a sustained cyber attack that exfiltrated

5 tips to optimize your data center

27 February 2023
By Zac Amos, Features Editor, Rehack.com. Pursuing data center optimization is an excellent way to remain competitive in an increasingly crowded marketplace. Taking the right steps can reduce costs, minimize risks, and help the facility maintain productivity. These five tips offer an excellent start. 1. Create a digital twin of the data center One of the challenging […] The post 5 tips to optimize your data center appeared first on CyberTalk.

The war in Eastern Europe: One year later

27 February 2023
EXECUTIVE SUMMARY: Russia’s invasion of Ukraine marked the unexpected escalation of an eight-year conflict that began with Russia’s annexation of Crimea in 2014. This illegal annexation represented the first time that a European state had seized a foreign territory since World War II. Ukraine was once a cornerstone of the Soviet Union, representing the second-most […] The post The war in Eastern Europe: One year later appeared first on CyberTalk.

Thousands of Cloud Servers Targeted by the Mysterious Nevada Group

27 February 2023
An unidentified group of ransomware hackers, dubbed Nevada Group, has targeted the computer networks of almost 5,000 victims across the U.S. and Europe. Hackers ask for two Bitcoins (which is around $50,000) and their ransom notes are publicly visible. The CISA has released a simple workaround to nullify the attack, allowing some of the victims to regain their data.

Attackers Abuse SM Platforms to Deliver S1deload Stealer

27 February 2023
Bitdefender disclosed an active malware campaign targeting Facebook and YouTube users with S1deload Stealer, using adult themes as bait. The new information stealer compromises user credentials and exploits system resources to mine BEAM cryptocurrency. The malware has the ability to propagate its malicious links to a compromised user’s followers. Between July and December 2022, about 600 individuals fell victim to it.

Risk committee survey shows flaws in enterprise risk management

27 February 2023
A survey of 100 committee members analyzed third-party risk. Eighty-four percent of respondents said that risk “misses” resulted in disruptions.

When Low-Tech Hacks Cause High-Impact Breaches – Krebs on Security

27 February 2023
The attackers are usually careful to do nothing with the phishing domain until they are ready to initiate a vishing call to a potential victim. And when the attack or call is complete, they disable the website tied to the domain.

TA569: SocGholish and Beyond

27 February 2023
TA569 leverages many types of injections, traffic distribution systems (TDS), and payloads including, but not limited to, SocGholish. In addition to serving as an initial access broker, these injects imply it may be running a pay-per-install service.

Fake Amazon Prime email abuses LinkedIn's URL shortener

27 February 2023
Over the last few days, scammers have been sending out phishing emails that disguise bogus URLs with something called Slinks—shortened Linkedin URLs. Now, they're being used in a scam based on Amazon's popular Prime membership.

Researchers Share New Insights Into RIG Exploit Kit Malware's Operations

27 February 2023
The RIG exploit kit (EK) touched an all-time high successful exploitation rate of nearly 30% in 2022, new findings reveal. "RIG EK is a financially-motivated program that has been active since 2014," Swiss cybersecurity company PRODAFT said in an exhaustive report shared with The Hacker News. "Although it has yet to substantially change its exploits in its more recent activity, the type and

Nine Danish Hospitals Suffer Cyberattack From ‘Anonymous Sudan’

27 February 2023
Copenhagen’s health authority said on Twitter that although the websites for the hospitals were down, medical care at the facilities was unaffected by the attacks. It later added the sites were back online after “a couple of hours.”

Chromium bug allowed SameSite cookie bypass on Android devices

27 February 2023
A recently patched bug in the open-source Chromium browser project could allow malicious actors to bypass a security feature that protects sensitive cookies on Android browsers.

Senators introduce cybersecurity insurance act for small businesses

27 February 2023
Senators introduce legislation to protect consumers and small businesses from cyberattacks by providing clear cyber insurance policy information.

Shocking Findings from the 2023 Third-Party App Access Report

27 February 2023
Spoiler Alert: Organizations with 10,000 SaaS users that use M365 and Google Workspace average over 4,371 additional connected apps. SaaS-to-SaaS (third-party) app installations are growing nonstop at organizations around the world. When an employee needs an additional app to increase their efficiency or productivity, they rarely think twice before installing. Most employees don’t even realize

Labor plan to beef up government’s cyber powers faces Senate block

27 February 2023
Labor plan to beef up government’s cyber powers faces Senate block A paper expanding on greater ability to intervene during hacks – especially on private companies – causes alarm among Coalition and GreensFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastLabor could face Senate difficulties if it tries to dramatically expand the government’s powers to directly intervene in companies’ IT systems during cyber-attacks.Under existing laws – which were controversial when introduced by the former Coalition government – the Australian Signals Directorate has the ability to “step in” as a “last resort” in some emergency situations, but only for critical infrastructure assets. Continue reading...

Microsoft recommending you scan more Exchange server files

27 February 2023
In particular, the software giant said this week that sysadmins should now include the Temporary ASP.NET files, Inetsrv folders, and the PowerShell and w3wp processes on the list of files and folders to be run through antivirus systems.

Stanford University Discloses Data Breach - Ph.D. Admission Data Leaked

27 February 2023
This incident occurred due to the misconfiguration of the folder settings, which led to the availability of the 2022-23 application files for admission to the program on the department’s website.