Latest Cybersecurity News and Articles
17 February 2023
Hogwarts Legacy, the much-anticipated Harry Potter video game, has finally landed on gaming platforms. As with all games like this, it comes with a steep price tag, so it's no surprise to see websites peddling cracked versions of the game for free.
17 February 2023
A new variant of the notorious Mirai botnet has been found leveraging several security vulnerabilities to propagate itself to Linux and IoT devices.
Observed during the second half of 2022, the new version has been dubbed V3G4 by Palo Alto Networks Unit 42, which identified three different campaigns likely conducted by the same threat actor.
"Once the vulnerable devices are compromised, they
17 February 2023
Mozilla this week announced the release of Firefox 110 and Firefox ESR 102.8 with patches for 10 high-severity vulnerabilities. The two browser versions also arrived with patches for several medium- and low-severity vulnerabilities.
17 February 2023
Microsoft attributed the Chinese cyberespionage group DEV-0147 to a wave of attacks targeting diplomatic entities in South America. The group is also using the ShadowPad backdoor to maintain persistence. Experts suspect that the group uses phishing and exploits unpatched applications as initial attack vectors.
17 February 2023
Security researcher Yerodin Richards has found an authenticated remote code execution (RCE) vulnerability in Arris routers. This is the type of router that ISPs typically provide in loan for customers’ telephony and internet access.
17 February 2023
The obvious threat is users’ credentials, which are often reused on different sites and, when compromised, can be utilized to either blackmail the victim or become sold on the dark web for other purposes.
17 February 2023
The CISA added actively exploited flaws in Cacti, Microsoft Office, Windows, and iOS to its Known Exploited Vulnerabilities Catalog. Experts recommend also private organizations review the Catalog and address the vulnerabilities in their systems.
17 February 2023
Cisco has rolled out security updates to address a critical flaw reported in the ClamAV open source antivirus engine that could lead to remote code execution on susceptible devices.
Tracked as CVE-2023-20032 (CVSS score: 9.8), the issue relates to a case of remote code execution residing in the HFS+ file parser component.
The flaw affects versions 1.0.0 and earlier, 0.105.1 and earlier, and
16 February 2023
EXECUTIVE SUMMARY: It’s exciting! We are finally getting back to traveling and gathering again, after several years of 100% virtual events. In 2023, take the opportunity to connect, learn and grow with mentors, experts, and industry leaders who you haven’t seen in years. You’ve expanded your knowledge and skills, they’ve expanded their knowledge and skills, […]
The post 10 top cyber security conferences of 2023 appeared first on CyberTalk.
16 February 2023
Skipping patching VMware ESXi bugs? Beware! Hundreds of systems in Europe were found infected with the ESXiArgs ransomware. Hackers reportedly abused a two-year-old RCE bug (CVE-2021-21974) and compromised thousands of servers across the world.
16 February 2023
There’s a new financially motivated campaign utilizing MortalKombat ransomware and the Laplas clipper. While the former is a variant of the Xortist commodity ransomware, the latter is a cryptocurrency hijacker that monitors the Windows clipboard for crypto addresses. The campaign’s focus remained on the U.S., with a handful of victims spread across the U.K, Turkey, and the Philippines.
16 February 2023
After surveying over 700 senior IT and cybersecurity leaders, a cybersecurity trends report revealed that risk management remained a concern.
16 February 2023
By Rachel Teitz, Technical Communications. ChatGPT, the chatbot launched by OpenAI in November 2022, is the hot new thing that everyone is talking about. As ChatGPT itself will tell you, it is “an AI language model capable of generating human-like text based on the input it is given.” Ask it a question, and it will […]
The post ChatGPT, the hackers’ new secret weapon appeared first on CyberTalk.
16 February 2023
A popular npm package with more than 3.5 million weekly downloads has been found vulnerable to an account takeover attack.
"The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password," software supply chain security company Illustria said in a report.
While npm's security protections limit users to have only one active email address
16 February 2023
The prolific SideWinder group has been attributed as the nation-state actor behind attempted attacks against 61 entities in Afghanistan, Bhutan, Myanmar, Nepal, and Sri Lanka between June and November 2021.
Targets included government, military, law enforcement, banks, and other organizations, according to an exhaustive report published by Group-IB, which also found links between the adversary
16 February 2023
The law firm Baker McKenzie has launched a class action lawsuit against Medibank over the health insurer’s massive cyber attack last year that resulted in the personal details of up to 10 million customers being posted on the dark web.
16 February 2023
These new guidelines will help set the course for best practices in handling digital identity for organizations across all sectors. The security risk around digital identities stems from verification.
16 February 2023
Among its most interesting capabilities, Havoc is cross-platform and it bypasses Microsoft Defender on up-to-date Windows 11 devices using sleep obfuscation, return address stack spoofing, and indirect syscalls.
16 February 2023
Silicon Valley investor Costanoa Ventures, one of the co-leads in its Series A, also co-led this recent Series B round with Africa-focused venture capital firm Norrsken22. Lexi Novitske, general partner at Norrsken22, will join the company’s Board.
16 February 2023
Cisco on Wednesday announced updates for endpoint, cloud, and web security products to address a critical vulnerability in the third-party open-source scanning library ClamAV.