Latest Cybersecurity News and Articles


Gcore Thwarts Massive 650 Gbps DDoS Attack on Free Plan Client

22 February 2023
At the beginning of January, Gcore faced an incident involving several L3/L4 DDoS attacks with a peak volume of 650 Gbps. Attackers exploited over 2000 servers belonging to one of the top three cloud providers worldwide and targeted a client who was using a free CDN plan. However, due to Gcore’s distribution of infrastructure and a large number of peering partners, the attacks were mitigated,

U.S. Cybersecurity Agency CISA Adds Three New Vulnerabilities in KEV Catalog

22 February 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The list of shortcomings is as follows - CVE-2022-47986 (CVSS score: 9.8) - IBM Aspera Faspex Code Execution Vulnerability CVE-2022-41223 (CVSS score: 6.8) - Mitel MiVoice Connect Code Injection

VMware Patches Critical Vulnerability in Carbon Black App Control Product

21 February 2023
VMware on Tuesday released patches to address a critical security vulnerability affecting its Carbon Black App Control product. Tracked as CVE-2023-20858, the shortcoming carries a CVSS score of 9.1 out of a maximum of 10 and impacts App Control versions 8.7.x, 8.8.x, and 8.9.x. The virtualization services provider describes the issue as an injection vulnerability. Security researcher Jari

Check Point CEO on company growth, ChatGPT and more

21 February 2023
In this edited interview excerpt from the TechCheck Podcast, Check Point CEO Gil Shwed shares insights into his company’s growth, expectations for 2023, and provides perspectives on the groundbreaking technology that is ChatGPT. Don’t miss this. And if you like what you read, be sure to watch the full interview. Welcome! Let’s start with the […] The post Check Point CEO on company growth, ChatGPT and more appeared first on CyberTalk.

Adm. Michael Rogers joins security advisory board

21 February 2023
Duality Technologies has appointed Adm. Michael Rogers to their board of advisors. Adm. Michael Rogers has military and federal security experience. 

Apple Updates Advisories as Security Firm Discloses New Class of Vulnerabilities

21 February 2023
Trellix published a blog post on Tuesday to describe these flaws, which the firm says are part of a new class of bugs that can allow attackers to bypass code signing on macOS and iOS systems.

Major corporations’ credentials stolen in data center incident

21 February 2023
EXECUTIVE SUMMARY: In an incident that highlights the broad-based vulnerability of computer networks everywhere, cyber criminals recently got ahold of login credentials for data centers in Asia that are used by leading global businesses. As a result, cyber criminals may be able to execute advanced espionage activities, sabotage, or other malicious activities. The data caches […] The post Major corporations’ credentials stolen in data center incident appeared first on CyberTalk.

MyloBot Botnet Spreading Rapidly Worldwide, Infecting Over 50,000 Devices Daily

21 February 2023
A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the United States, Indonesia, and Iran, according to BitSight.

Scrut Automation Raises $7.5 Million for GRC Platform

21 February 2023
India-based Scrut Automation has announced raising $7.5 million in a new funding round that will help the company improve its governance, risk, and compliance (GRC) automation platform and expand its presence in the United States.

Hackers Scored Corporate Giants’ Logins for Asian Data Centers

21 February 2023
The information included credentials in varying numbers for some of the world’s biggest companies, including Alibaba Group, Amazon, Apple, BMW AG, Goldman Sachs Group, Huawei Technologies, Microsoft, and Walmart, according to Resecurity.

DNA Diagnostic Center fined $400,000 for 2021 data breach

21 February 2023
The DNA testing company will pay a penalty of $400,000 to the attorneys general of Pennsylvania and Ohio for a data breach in 2021 that affected 2.1 million individuals nationwide, according to a settlement deal with the states’ attorneys general.

Newly Identified Earth Yako APT Observed Targeting Japanese Entities

21 February 2023
Trend Micro experts observed several targeted attacks against researchers of academic organizations and think tanks in Japan and attributed the campaign to Earth Yako. Previous to this, Earth Yako APT group has been abusing legitimate services such as Dropbox, GitHub, and Protonmail to expand its campaign to East Asia. 

ChatGPT is bringing advancements and challenges for cybersecurity

21 February 2023
ChatGPT is a gold mine of insight that removes much of the work involved in research and problem-solving by enabling users to access the entire corpus of the public internet with just one set of instructions.

Feigning sickness is the most common romance scammer tactic

21 February 2023
The FTC released data regarding the common lies sold by romance scammers, whose scams cost nearly 70,000 consumers $1.3 billion in 2022.

MyloBot Botnet Spreading Rapidly Worldwide: Infecting Over 50,000 Devices Daily

21 February 2023
A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the U.S., Indonesia, and Iran. That's according to new findings from BitSight, which said it's "currently seeing more than 50,000 unique infected systems every day," down from a high of 250,000 unique hosts in 2020. Furthermore, an analysis of MyloBot's infrastructure has found

Complexity, volume of cyber attacks lead to burnout in security teams

21 February 2023
The rapid evolution of cybercrime is weighing on security teams substantially more than it did last year, leading to widespread burnout and potential regulatory risk, according to Magnet Forensics.

HardBit 2.0 Engages in Clever Ransom Negotiation Based on Cyber Insurance Coverage

21 February 2023
Seemingly improving upon their initial release, HardBit version 2.0 was introduced toward the end of November 2022, with samples seen throughout the end of 2022 and into 2023.

The Future of Network Security: Predictive Analytics and ML-Driven Solutions

21 February 2023
As the digital age evolves and continues to shape the business landscape, corporate networks have become increasingly complex and distributed. The amount of data a company collects to detect malicious behaviour constantly increases, making it challenging to detect deceptive and unknown attack patterns and the so-called "needle in the haystack". With a growing number of cybersecurity threats,

Researchers Warn of ReverseRAT Backdoor Targeting Indian Government Agencies

21 February 2023
Cybersecurity firm ThreatMon attributed the activity to a threat actor tracked as SideCopy. SideCopy is a threat group of Pakistani origin that overlaps with another actor called Transparent Tribe.

Ireland: Tusla to begin contacting 20,000 people whose data was compromised during HSE cyberattack

21 February 2023
The child and family agency Tusla is to begin contacting around 20,000 people whose data was compromised during the 2021 cyberattack on the Health Service Executive (HSE), Ireland's public healthcare system.