Latest Cybersecurity News and Articles


New Magecart Campaign Uses Multilingual Skimmers; Extracts Personal Data

24 February 2023
A Magecart skimmer was discovered harvesting the victim's IP address and browser user agent in addition to their email, address, phone number, and credit card information. With access to a wide range of personal data and sophisticated monitoring tools, cybercriminals can carry out complex attacks that are difficult to detect and prevent. 

Majority of Android Apps on Google Play Store Provide Misleading Data Safety Labels

24 February 2023
An investigation into data safety labels for Android apps available on the Google Play Store has uncovered "serious loopholes" that allow apps to provide misleading or outright false information. The study, conducted by the Mozilla Foundation as part of its *Privacy Not Included initiative, compared the privacy policies and labels of the 20 most popular paid apps and the 20 most popular free

Venture capital financing of cyber companies slid to $18.5 billion in 2022

24 February 2023
VC financing for cybersecurity startups reached $18.5 billion, representing a steep decline from the $30.3 billion seen in 2021 — but it was still the second-highest year on record.

WinorDLL64: A backdoor from the vast Lazarus arsenal?

24 February 2023
The WinorDLL64 payload serves as a backdoor that most notably acquires extensive system information, provides means for file manipulation, such as exfiltrating, overwriting, and removing files, and executes additional commands.

New RambleOn Android Malware Used Against Journalist

24 February 2023
South Korean researchers stumbled across a novel malware RambleOn that most probably North Korean nation-state actors used against a journalist in the country. Hackers camouflage the spyware as a secure chat app called Fizzle. The app, in reality, requests for the next-stage payload hosted on pCloud and Yandex. It was sent as an APK file over WeChat to the target.

Executives make the case for continued tech investments

23 February 2023
EXECUTIVE SUMMARY: In the past, cyber security executives have received the financial support needed to keep organizations protected against sophisticated attacks. However, current economic conditions have left leaders at all levels rethinking approaches to investments in cyber security tools and services. Economic pressure As is the case for organizational spending across many departments, cyber security […] The post Executives make the case for continued tech investments appeared first on CyberTalk.

Hackers use fake ChatGPT apps to push Windows, Android malware

23 February 2023
Threat actors are exploiting the popularity of OpenAI's ChatGPT chatbot to distribute malware for Windows and Android, or direct unsuspecting victims to credential phishing pages.

Hackers Using Trojanized macOS Apps to Deploy Evasive Cryptocurrency Mining Malware

23 February 2023
Trojanized versions of legitimate applications are being used to deploy evasive cryptocurrency mining malware on macOS systems. Jamf Threat Labs, which made the discovery, said the XMRig coin miner was executed as Final Cut Pro, a video editing software from Apple, which contained an unauthorized modification. "This malware makes use of the Invisible Internet Project (i2p) [...] to download

Trove of L.A. Students’ Mental Health Records Posted to Dark Web After Cyber Hack

23 February 2023
The student psychological evaluations, published to a “dark web” leak site by the Russian-speaking ransomware gang Vice Society, offer a startling degree of personally identifiable information.

Cisco Patches High-Severity Vulnerabilities in ACI Components

23 February 2023
Cisco on Wednesday informed customers about the availability of patches for two high-severity vulnerabilities affecting components of its Application Centric Infrastructure (ACI) software-defined networking solution.

CVSS system criticized for failure to address real-world impact

23 February 2023
Weaknesses in the existing CVSS scoring system have been highlighted through new research, with existing metrics deemed responsible for “overhyping” some vulnerabilities.

NSA best home network practices

23 February 2023
The NSA released a list of cybersecurity best practices designed to help teleworkers protect their home networks from malicious cyber actors.

Imposter HTTP libraries lurk on PyPI

23 February 2023
The descriptions for these packages, for the most part, don't hint at their malicious intent. Some are disguised as real libraries and make flattering comparisons between their capabilities and those of known, legitimate HTTP libraries.

Experts Sound Alarm Over Growing Attacks Exploiting Zoho ManageEngine Products

23 February 2023
Multiple threat actors have been observed opportunistically weaponizing a now-patched critical security vulnerability impacting several Zoho ManageEngine products since January 20, 2023. Tracked as CVE-2022-47966 (CVSS score: 9.8), the remote code execution flaw allows a complete takeover of the susceptible systems by unauthenticated attackers. As many as 24 different products, including Access

Sublime nabs $9.8M for an anti-phishing email security platform built on collective, crowdsourced rules

23 February 2023
Decibel is leading the round, with Slow Ventures and a number of cybersecurity veterans participating, including Sounil Yu, Martin Roesch, Jerry Perullo, Michael Sutton, Rishi Bhargava, Slavik Markovich, Kevin Patrick Mahaffey, and Oliver Friedrichs.

Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing Links

23 February 2023
"The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report.

More vulnerabilities in industrial systems raise fresh concerns about critical infrastructure hacks

23 February 2023
Aslew of new reports about vulnerabilities in operational technology systems are raising fresh concerns about potential weaknesses inside U.S. critical infrastructure organizations.

New S1deload Stealer Malware Hijacks Youtube, Facebook Accounts

23 February 2023
Security researchers with Bitdefender's Advanced Threat Control (ATC) team discovered the new malware and dubbed it S1deload Stealer due to its extensive use of DLL sideloading for evading detection.

Cyberattack on Dole Temporarily Shuts Down Production in North America

23 February 2023
The previously unreported hack — which a source familiar with the incident said was ransomware — led some grocery shoppers to complain on Facebook in recent days that store shelves were missing Dole-made salad kits.

Open source software supply chain has security risks

23 February 2023
The increasing use of open-source packages in application development also creates a path for threat groups that want to use the software supply chain as a backdoor to myriad targets that depend on it.