Latest Cybersecurity News and Articles
22 February 2023
At the beginning of January, Gcore faced an incident involving several L3/L4 DDoS attacks with a peak volume of 650 Gbps. Attackers exploited over 2000 servers belonging to one of the top three cloud providers worldwide and targeted a client who was using a free CDN plan. However, due to Gcore’s distribution of infrastructure and a large number of peering partners, the attacks were mitigated,
22 February 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The list of shortcomings is as follows -
CVE-2022-47986 (CVSS score: 9.8) - IBM Aspera Faspex Code Execution Vulnerability
CVE-2022-41223 (CVSS score: 6.8) - Mitel MiVoice Connect Code Injection
21 February 2023
VMware on Tuesday released patches to address a critical security vulnerability affecting its Carbon Black App Control product.
Tracked as CVE-2023-20858, the shortcoming carries a CVSS score of 9.1 out of a maximum of 10 and impacts App Control versions 8.7.x, 8.8.x, and 8.9.x.
The virtualization services provider describes the issue as an injection vulnerability. Security researcher Jari
21 February 2023
In this edited interview excerpt from the TechCheck Podcast, Check Point CEO Gil Shwed shares insights into his company’s growth, expectations for 2023, and provides perspectives on the groundbreaking technology that is ChatGPT. Don’t miss this. And if you like what you read, be sure to watch the full interview. Welcome! Let’s start with the […]
The post Check Point CEO on company growth, ChatGPT and more appeared first on CyberTalk.
21 February 2023
Duality Technologies has appointed Adm. Michael Rogers to their board of advisors. Adm. Michael Rogers has military and federal security experience.
21 February 2023
Trellix published a blog post on Tuesday to describe these flaws, which the firm says are part of a new class of bugs that can allow attackers to bypass code signing on macOS and iOS systems.
21 February 2023
EXECUTIVE SUMMARY: In an incident that highlights the broad-based vulnerability of computer networks everywhere, cyber criminals recently got ahold of login credentials for data centers in Asia that are used by leading global businesses. As a result, cyber criminals may be able to execute advanced espionage activities, sabotage, or other malicious activities. The data caches […]
The post Major corporations’ credentials stolen in data center incident appeared first on CyberTalk.
21 February 2023
A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the United States, Indonesia, and Iran, according to BitSight.
21 February 2023
India-based Scrut Automation has announced raising $7.5 million in a new funding round that will help the company improve its governance, risk, and compliance (GRC) automation platform and expand its presence in the United States.
21 February 2023
The information included credentials in varying numbers for some of the world’s biggest companies, including Alibaba Group, Amazon, Apple, BMW AG, Goldman Sachs Group, Huawei Technologies, Microsoft, and Walmart, according to Resecurity.
21 February 2023
The DNA testing company will pay a penalty of $400,000 to the attorneys general of Pennsylvania and Ohio for a data breach in 2021 that affected 2.1 million individuals nationwide, according to a settlement deal with the states’ attorneys general.
21 February 2023
Trend Micro experts observed several targeted attacks against researchers of academic organizations and think tanks in Japan and attributed the campaign to Earth Yako. Previous to this, Earth Yako APT group has been abusing legitimate services such as Dropbox, GitHub, and Protonmail to expand its campaign to East Asia.
21 February 2023
ChatGPT is a gold mine of insight that removes much of the work involved in research and problem-solving by enabling users to access the entire corpus of the public internet with just one set of instructions.
21 February 2023
The FTC released data regarding the common lies sold by romance scammers, whose scams cost nearly 70,000 consumers $1.3 billion in 2022.
21 February 2023
A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the U.S., Indonesia, and Iran.
That's according to new findings from BitSight, which said it's "currently seeing more than 50,000 unique infected systems every day," down from a high of 250,000 unique hosts in 2020.
Furthermore, an analysis of MyloBot's infrastructure has found
21 February 2023
The rapid evolution of cybercrime is weighing on security teams substantially more than it did last year, leading to widespread burnout and potential regulatory risk, according to Magnet Forensics.
21 February 2023
Seemingly improving upon their initial release, HardBit version 2.0 was introduced toward the end of November 2022, with samples seen throughout the end of 2022 and into 2023.
21 February 2023
As the digital age evolves and continues to shape the business landscape, corporate networks have become increasingly complex and distributed. The amount of data a company collects to detect malicious behaviour constantly increases, making it challenging to detect deceptive and unknown attack patterns and the so-called "needle in the haystack". With a growing number of cybersecurity threats,
21 February 2023
Cybersecurity firm ThreatMon attributed the activity to a threat actor tracked as SideCopy. SideCopy is a threat group of Pakistani origin that overlaps with another actor called Transparent Tribe.
21 February 2023
The child and family agency Tusla is to begin contacting around 20,000 people whose data was compromised during the 2021 cyberattack on the Health Service Executive
(HSE), Ireland's public healthcare system.