Latest Cybersecurity News and Articles


Five Lawsuits Filed in Ransomware Breach Affecting 3.3 Million

23 February 2023
At least five proposed class action lawsuits have been filed in recent days in the wake of a California medical group's February 1 report of a ransomware attack last December that affected more than 3.3 million individuals.

HardBit 2.0 Ransomware Asks for Insurance Policy to Negotiate Ransom

23 February 2023
A report from Varonis revealed its findings about the second version of HardBit ransomware that extorts organizations. Its first version was observed in October 2022. This time, actors were spotted negotiating with certain victims as per their terms of cyber insurance. Victims are given 48 hours to get in touch with hackers, who use a peer-to-peer chat program that is open-source and encrypted.

NSA shares guidance on how to secure your home network

23 February 2023
The guide published by the Defense Department's intelligence agency on Wednesday includes a long list of recommendations, including a short list of highlights urging teleworkers to ensure their devices and software are up to date.

Ukraine’s largest charity wants to raise $1.3 million for ‘cyber offensive’

23 February 2023
The campaign aims to raise $1.3 million to purchase technology and equipment that will help Ukraine’s cyber forces conduct digital operations that could impede Russia’s advances on the real battlefield.

Irish TV broadcaster says attempted hack will affect programming

23 February 2023
In a statement, the company described identifying “an unauthorized attempt to access our systems in recent days” which it said had been “contained, isolated, and terminated.”

Python Developers Warned of Trojanized PyPI Packages Mimicking Popular Libraries

23 February 2023
Cybersecurity researchers are warning of "imposter packages" mimicking popular libraries available on the Python Package Index (PyPI) repository. The 41 malicious PyPI packages have been found to pose as typosquatted variants of legitimate modules such as HTTP, AIOHTTP, requests, urllib, and urllib3. The names of the packages are as follows: aio5, aio6, htps1, httiop, httops, httplat, httpscolor

6 dangerous cyber security vulnerabilities to watch for in 2023

22 February 2023
Contributed by George Mack, Content Marketing Manager, Check Point Software. What is a cyber security vulnerability? A cyber security vulnerability is a weakness in a computer system that malicious actors exploit to gain unauthorized access to sensitive data or resources. These vulnerabilities can exist in various aspects of a system, and can be found in […] The post 6 dangerous cyber security vulnerabilities to watch for in 2023 appeared first on CyberTalk.

Earth Kitsun Return to Target Selected Entities in China and Japan

22 February 2023
Trend Micro reported about a new threat actor that would drop a new backdoor dubbed WhiskerSpy. The cybercriminal group, tracked as Earth Kitsune, is a relatively new threat group that conducts watering hole attacks. The malware is delivered to users when they attempt to watch videos on attacker-compromised websites.

Over 90% of CISOs report frequent 40+ hour work weeks

22 February 2023
A report found that CISOs had high levels of workplace stress. The survey featured small to midsize businesses with teams of five employees or less.

Hackers Ran Amok Across GoDaddy for Three Years

22 February 2023
Internet domain registrar GoDaddy revealed that it has been the victim of a three-year-long campaign that deployed malware on internal systems and pilfered source code. Experts detected that an unauthorized third party had gained access to the company's cPanel hosting servers and installed malware. This resulted in random customer websites being intermittently redirected to malicious sites.

R1Soft Server Backup Manager Vulnerability Exploited to Deploy Backdoor

22 February 2023
During a recent incident response case, Fox-IT found evidence that the R1Soft vulnerability was exploited to gain initial access to a server. The attackers then deployed a malicious database driver that gave them backdoor access.

A Deep Dive into the Evolution of Ransomware Part 1

22 February 2023
Ransomware extortion tactics range from publishing data bit by bit in an attempt to increase pressure on targets through more aggressive measures, making these threats all the harder for organizations and individuals alike to protect against.

ChatGPT is on fire & the AI “gold rush” is here

22 February 2023
EXECUTIVE SUMMARY: This year will be the “Year of AI,” said Founder and CEO of Check Point, Gil Shwed, during a recent keynote presentation. Conversational AI-based chatbots have been around for years, but the release of ChatGPT made every other existent chatbot look like a lumbering dinosaur. Seen as an industry disruptor, ChatGPT also kicked […] The post ChatGPT is on fire & the AI “gold rush” is here appeared first on CyberTalk.

Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers

22 February 2023
ETW is a high-speed tracing facility built into the Windows operating system. It enables the logging of events and system activities by applications, drivers, and the operating system.

Accidental WhatsApp account takeovers? It's a thing

22 February 2023
A stranger may be receiving your private WhatsApp messages, and also be able to send messages to all of your contacts – if you have changed your phone number and didn't delete the WhatsApp account linked to it.

Multilingual Skimmer Fingerprints 'Secret Shoppers' via Cloudflare Endpoint API

22 February 2023
The skimmer uses iframes that are loaded if the current page is the checkout and if the browser's local storage does not include a font item (this is equivalent to using cookies to detect returning visitors).

Google will boost Android security through firmware hardening

22 February 2023
Google has started working to harden the security of Android at the firmware level, a component of the software stack that interacts directly with the various processors of a system on a chip (SoC).

Entitle Nabs $15M Seed Funding for Cloud Permissions Management Tech

22 February 2023
The Israeli security startup has attracted $15 million in early-stage venture capital funding from Glilot Capital Partners to build technology to address entitlement sprawl in the enterprise.

Bypassing Akamai’s Web Application Firewall Using an Injected Content-Encoding Header

22 February 2023
During a recent customer pilot, Praetorian researchers identified an interesting method to bypass the cross-site scripting (XSS) filtering functionality within the Akamai Web Application Firewall (WAF) solution.

Metomic Lands $20 Series A for Data Security Platform

22 February 2023
The London-based company said the $20 million financing was led by Evolution Equity Partners. Venture capital firms Resonance and Connect Ventures also joined as investors.