Latest Cybersecurity News and Articles


Dutch Police Arrest 3 Hackers Involved in Massive Data Theft and Extortion Scheme

27 February 2023
The Dutch police announced the arrest of three individuals in connection with a "large-scale" criminal operation involving data theft, extortion, and money laundering. The suspects include two 21-year-old men from Zandvoort and Rotterdam and an 18-year-old man without a permanent residence. The arrests were made on January 23, 2023. It's estimated that the hackers stole personal data belonging

MyloBot Proxy Botnet Infects 50,000 Unique Systems Per Day

27 February 2023
BitSight uncovered an advanced botnet that has been able to compromise thousands of systems in the U.S., India, Indonesia, and Iran. Dubbed MyloBot, its infrastructure has connections to BHProxies, a residential proxy service. The highly sophisticated malware was first spotted in the wild in 2017 and is known for its anti-analysis techniques.

Full-Featured Stealc Info-stealer Gains Popularity

27 February 2023
SEKOIA has shared IOCs, along with YARA and Suricata rules, to detect a potential information-stealer named Stealc. Researchers have already identified more than 40 C2 domains and several dozens of malware samples, hinting that Stealc is already gaining popularity within the cybercrime community. To combat attacks from such info-stealers, organizations are recommended to implement strong security controls with multi-layered visibility and security solutions.

PureCrypter Loader Found Infecting Government Entities with Various Malware

27 February 2023
Security researchers at Menlo Labs laid bare an attack campaign featuring the PureCrypter downloader to target government entities. The evasive threat campaign is disseminated via Discord by an unidentified threat actor. The attack campaign leverages the domain of a compromised non-profit organization as a C2 channel to deliver its secondary payload.

When Low-Tech Hacks Cause High-Impact Breaches

26 February 2023
Web hosting giant GoDaddy made headlines this month when it disclosed that a multi-year breach allowed intruders to steal company source code, siphon customer and employee login credentials, and foist malware on customer websites. Media coverage understandably focused on GoDaddy's admission that it suffered three different cyberattacks over as many years at the hands of the same hacking group.  But it's worth revisiting how this group typically got in to targeted companies: By calling employees and tricking them into navigating to a phishing website.

Hydrochasma: An Emerging Threat to Asia's Medical and Shipping Industries

25 February 2023
A previously unseen threat group, dubbed Hydrochasma, was found targeting medical labs and shipping companies in Asia in a cyberespionage campaign that started in October 2022. It did not employ any custom malware but instead heavily relied on publicly available and living-off-the-land tools. So far, hackers have not been observed exfiltrating any data.

CISA Sounds Alarm on Cybersecurity Threats Amid Russia's Invasion Anniversary

24 February 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations and individuals to increase their cyber vigilance, as Russia's military invasion of Ukraine officially enters one year.

Cyberattacks hit data centers to steal information from global companies

24 February 2023
Cyberattacks targeting multiple data centers in several regions globally have been observed over the past year and a half, resulting in the exfiltration of information pertaining to some of the world's biggest companies.

What to know: Protecting employee data in your workplace

24 February 2023
As a networking and security professional, J. ( J-Dot) Bendonis has actively been securely connecting people through technology for over 20 years. At Check Point, he’s been assisting and educating his customers about their options surrounding cyber security; ranging from best practices to advanced architecture and future design states. In this informative and exclusive CyberTalk […] The post What to know: Protecting employee data in your workplace appeared first on CyberTalk.

Who’s Behind the Botnet-Based Service BHProxies?

24 February 2023
A security firm has discovered that a five-year-old crafty botnet known as Mylobot appears to be powering a residential proxy service called BHProxies, which offers paying customers the ability to route their web traffic anonymously through compromised computers. Here’s a closer look at Mylobot, and a deep dive into who may be responsible for operating the BHProxies service.

Research predicts major cybersecurity workforce shifts in coming years

24 February 2023
Analysts have predicted major cybersecurity workforce shifts. According to research, nearly half of cybersecurity leaders will change jobs by 2025.

Economic shocks & swarms of cyber criminals

24 February 2023
EXECUTIVE SUMMARY: In times of high inflation, businesses and consumers aren’t the only ones feeling adverse effects. During periods of economic uncertainty, even cyber criminals feel the pinch. For instance, cryptocurrencies –which are critical in facilitating ransomware payments– have dropped in value. As a result, cyber criminals are becoming more brazen in their efforts, driving […] The post Economic shocks & swarms of cyber criminals appeared first on CyberTalk.

How healthcare providers ensure safe and seamless continuity of care

24 February 2023
The growing number of successful cyberattacks has urged healthcare organizations to take steps in protecting their systems from threat actors.

Rishi Sunak faces calls to ban TikTok use by government officials

24 February 2023
Rishi Sunak faces calls to ban TikTok use by government officials PM under pressure to follow EU and US in taking step over fears Chinese-owned app poses cybersecurity riskRishi Sunak has been urged to ban government officials from using TikTok in line with moves by the EU and US, amid growing cybersecurity fears over China.Officials in Europe and the US have been told to limit the use of the Chinese-owned social video app over concerns that data can be accessed by Beijing. Continue reading...

Threat Actors Weaponize Old Bugs to Launch Ransomware Attacks

24 February 2023
Latest report by Cyware, along with Cyber Security Works (CSW), Ivanti, and Securin, stated that out of 344 total threats detected in 2022, 56 new vulnerabilities were associated with ransomware threats. Attackers can leverage kill chains to exploit these bugs across 81 unique products. The Log4Shell flaw affects around 176 products from 21 vendors, including Oracle, Red Hat, Apache, Novell, and Amazon.

Woman of the Week! Achieving success in cyber security

24 February 2023
Coletta Vigh, Check Point’s Head of Worldwide Channel Strategy and Growth Initiatives, was recently honored as the Woman of the Week through the Women of the Channel Leadership Network. In this edited interview excerpt, read about her career trajectory and how she’s managed to continuously reach new heights of success in the cyber security sector. […] The post Woman of the Week! Achieving success in cyber security appeared first on CyberTalk.

PureCrypter Malware Downloader Targets Government Entities Through Discord

24 February 2023
Menlo Labs has uncovered an unknown threat actor that’s leveraging an evasive threat campaign distributed via Discord that features the PureCrypter downloader and targets government entities.

Google Teams Up with Ecosystem Partners to Enhance Security of SoC Processors

24 February 2023
Google said it's working with ecosystem partners to harden the security of firmware that interacts with Android. While the Android operating system runs on what's called the application processor (AP), it's just one of the many processors of a system-on-chip (SoC) that cater to various tasks like cellular communications and multimedia processing. "Securing the Android Platform requires going

CyberSmart secures $15.3m for SME cybersecurity software

24 February 2023
CyberSmart’s Series B was led by Oxx, with further contributions from British Patient Capital, IQ Capital, Eos Venture Partners, Legal & General Capital, Seedcamp, and Winton Ventures.

Australian Retailer's Customer Data Compromised at Former Third-Party Supplier

24 February 2023
The Good Guys' customer data, including phone numbers and email addresses, have been compromised in a third-party breach that industry observers say is yet another reminder for businesses to scrutinize their suppliers' security practices.