Latest Cybersecurity News and Articles
24 February 2023
A Magecart skimmer was discovered harvesting the victim's IP address and browser user agent in addition to their email, address, phone number, and credit card information. With access to a wide range of personal data and sophisticated monitoring tools, cybercriminals can carry out complex attacks that are difficult to detect and prevent.
24 February 2023
An investigation into data safety labels for Android apps available on the Google Play Store has uncovered "serious loopholes" that allow apps to provide misleading or outright false information.
The study, conducted by the Mozilla Foundation as part of its *Privacy Not Included initiative, compared the privacy policies and labels of the 20 most popular paid apps and the 20 most popular free
24 February 2023
VC financing for cybersecurity startups reached $18.5 billion, representing a steep decline from the $30.3 billion seen in 2021 — but it was still the second-highest year on record.
24 February 2023
The WinorDLL64 payload serves as a backdoor that most notably acquires extensive system information, provides means for file manipulation, such as exfiltrating, overwriting, and removing files, and executes additional commands.
24 February 2023
South Korean researchers stumbled across a novel malware RambleOn that most probably North Korean nation-state actors used against a journalist in the country. Hackers camouflage the spyware as a secure chat app called Fizzle. The app, in reality, requests for the next-stage payload hosted on pCloud and Yandex. It was sent as an APK file over WeChat to the target.
23 February 2023
EXECUTIVE SUMMARY: In the past, cyber security executives have received the financial support needed to keep organizations protected against sophisticated attacks. However, current economic conditions have left leaders at all levels rethinking approaches to investments in cyber security tools and services. Economic pressure As is the case for organizational spending across many departments, cyber security […]
The post Executives make the case for continued tech investments appeared first on CyberTalk.
23 February 2023
Threat actors are exploiting the popularity of OpenAI's ChatGPT chatbot to distribute malware for Windows and Android, or direct unsuspecting victims to credential phishing pages.
23 February 2023
Trojanized versions of legitimate applications are being used to deploy evasive cryptocurrency mining malware on macOS systems.
Jamf Threat Labs, which made the discovery, said the XMRig coin miner was executed as Final Cut Pro, a video editing software from Apple, which contained an unauthorized modification.
"This malware makes use of the Invisible Internet Project (i2p) [...] to download
23 February 2023
The student psychological evaluations, published to a “dark web” leak site by the Russian-speaking ransomware gang Vice Society, offer a startling degree of personally identifiable information.
23 February 2023
Cisco on Wednesday informed customers about the availability of patches for two high-severity vulnerabilities affecting components of its Application Centric Infrastructure (ACI) software-defined networking solution.
23 February 2023
Weaknesses in the existing CVSS scoring system have been highlighted through new research, with existing metrics deemed responsible for “overhyping” some vulnerabilities.
23 February 2023
The NSA released a list of cybersecurity best practices designed to help teleworkers protect their home networks from malicious cyber actors.
23 February 2023
The descriptions for these packages, for the most part, don't hint at their malicious intent. Some are disguised as real libraries and make flattering comparisons between their capabilities and those of known, legitimate HTTP libraries.
23 February 2023
Multiple threat actors have been observed opportunistically weaponizing a now-patched critical security vulnerability impacting several Zoho ManageEngine products since January 20, 2023.
Tracked as CVE-2022-47966 (CVSS score: 9.8), the remote code execution flaw allows a complete takeover of the susceptible systems by unauthenticated attackers.
As many as 24 different products, including Access
23 February 2023
Decibel is leading the round, with Slow Ventures and a number of cybersecurity veterans participating, including Sounil Yu, Martin Roesch, Jerry Perullo, Michael Sutton, Rishi Bhargava, Slavik Markovich, Kevin Patrick Mahaffey, and Oliver Friedrichs.
23 February 2023
"The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report.
23 February 2023
Aslew of new reports about vulnerabilities in operational technology systems are raising fresh concerns about potential weaknesses inside U.S. critical infrastructure organizations.
23 February 2023
Security researchers with Bitdefender's Advanced Threat Control (ATC) team discovered the new malware and dubbed it S1deload Stealer due to its extensive use of DLL sideloading for evading detection.
23 February 2023
The previously unreported hack — which a source familiar with the incident said was ransomware — led some grocery shoppers to complain on Facebook in recent days that store shelves were missing Dole-made salad kits.
23 February 2023
The increasing use of open-source packages in application development also creates a path for threat groups that want to use the software supply chain as a backdoor to myriad targets that depend on it.