Latest Cybersecurity News and Articles


Report: Pentagon Personnel Use Unauthorized, Unsafe Apps on Work Devices

16 February 2023
The Defense Department’s inspector general found that unsanctioned apps downloaded onto government-issued mobile devices “could pose operational and cybersecurity risks to DOD information and information systems.”

Hyundai Says Its Cars Will No Longer Be Easy to Steal Using Viral TikTok Instructions

16 February 2023
Hyundai will issue a software patch that the company says will thwart would-be thieves from stealing its cars using instructions from viral TikTok videos, according to a company announcement.

ESXiArgs Ransomware Hits Over 500 New Targets in European Countries

16 February 2023
More than 500 hosts have been newly compromised en masse by the ESXiArgs ransomware strain, most of which are located in France, Germany, the Netherlands, the U.K., and Ukraine. The findings come from attack surface management firm Censys, which discovered "two hosts with strikingly similar ransom notes dating back to mid-October 2022, just after ESXi versions 6.5 and 6.7 reached end of life."

GitHub Copilot update stops AI model from revealing secrets

16 February 2023
GitHub has updated the AI model of Copilot, a programming assistant that generates real-time source code and function recommendations in Visual Studio, and says it's now safer and more powerful.

Splunk Enterprise Updates Patch High-Severity Vulnerabilities

16 February 2023
The most severe vulnerabilities are CVE-2023-22939 and CVE-2023-22935 (CVSS score of 8.1), two issues that could lead to the bypass of search processing language (SPL) safeguards for risky commands.

Google lets a few Android devices into its Privacy Sandbox

16 February 2023
Google on Tuesday began rolling out a beta test of its Privacy Sandbox software for a small portion of Android 13 devices to learn how its purportedly privacy-protecting ad tech actually performs.

OT Network Security Myths Busted in a Pair of Hacks

16 February 2023
As IT and OT network lines continue to blur in the rapidly digitalized industrial sector, new vulnerabilities and threats imperil conventional OT security measures that once isolated and guarded physical processes from cyberattacks.

Intel issues patches for SGX vulnerabilities

16 February 2023
Intel's Software Guard Extensions (SGX) are under the spotlight again after the chipmaker disclosed several newly discovered vulnerabilities affecting the tech, and recommended users update their firmware.

Passport Breach Hits Over 500 Cricket Stars, From Wasim Akram To Ian Bell

16 February 2023
The data appears to relate to teams involved in both the Pakistan Super League and the Abu Dhabi T10 competitions. Often, cricketers have to provide their passports and other personal data to event organizers.

Medibank class action launched after massive hack put private information of millions on dark web

15 February 2023
Medibank class action launched after massive hack put private information of millions on dark web Law firm Baker McKenzie says company failed to protect privacy of customers in Australia and overseasFollow our Australia news live blog for the latest updatesGet our morning and afternoon news emails, free app or daily news podcastThe law firm Baker McKenzie has launched a class action lawsuit against Medibank over the health insurer’s massive cyber attack last year that resulted in the personal details of up to 10 million customers being posted on the dark web.In what became the largest breach of its kind to date in Australia, the hack on Medibank resulted in the personal details of 9.7 million current and former customers, including 5.1 million Medibank customers, 2.8 million ahm customers and 1.8 million international customers, being leaked.Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup Continue reading...

How Concerned Should You be about Your Hardware Wallet?

15 February 2023
Security company Unciphered successfully breached OneKey, the maker of hardware wallets for cryptocurrencies, in a matter of seconds, underlining security gaps in the emerging crypto world. Unciphered posted a video on YouTube demonstrating its ability to exploit a critical flaw that enabled it to infiltrate a OneKey Mini. It is important that organizations routinely scan their system for bugs and security gaps.

Everything you need to know – Netflix password sharing

15 February 2023
EXECUTIVE SUMMARY: Netflix once tweeted “Love is sharing a password,” but the company is breaking up with password sharing. At that point in time, the company’s strategy focused on getting eyeballs glued to screens. Netflix didn’t much care about who shared passwords, as long as millions of people were watching Netflix shows and movies. But […] The post Everything you need to know – Netflix password sharing appeared first on CyberTalk.

Organizations fought an average of 29.3 attacks daily in late 2022

15 February 2023
2022 Radware threat analysis report defined DDoS attack profiles by gains in number, frequency, volume, power, duration and complexity.

Dark Caracal APT Reappears with a New Version of Bandook Spyware

15 February 2023
Lookout Security published a report describing the activities of a new APT actor dubbed Dark Caracal that has claimed hundreds of infections in more than a dozen countries since March of 2022. The APT is currently using a new version of Bandook spyware to target Windows systems. Organizations in vulnerable regions organizations must watch out for IOCs associated with the threat actors and the malware to take necessary preventive measures.

Here’s how hackers use ClickFunnels to deliver malware

15 February 2023
By George Mack, Content Marketing Manager, Check Point. ClickFunnels is a platform that provides entrepreneurs and small businesses with the tools needed to create online sales funnels. ClickFunnels’ tools include landing pages, which are designed to capture the information of potential customers; video sales pages, which host videos that are designed to sell; checkout systems, […] The post Here’s how hackers use ClickFunnels to deliver malware appeared first on CyberTalk.

Recently Patched IBM Aspera Faspex Vulnerability Exploited in the Wild

15 February 2023
The security hole, tracked as CVE-2022-47986 and classified as ‘high severity’, is a YAML deserialization flaw that can be exploited by a remote attacker for arbitrary code execution using specially crafted API calls.

Passwordless authentication startup Descope lands $53M seed round

15 February 2023
The money came from Lightspeed Venture Partners and GGV Capital, with additional funds contributed by Dell Technologies Capital, TechAviv, J Ventures, Cerca, Unusual Ventures, Silicon Valley CISO Investments, and several individual investors.

SideWinder APT Attacks Regional Targets in New Campaign

15 February 2023
The suspected state-sponsored group – also known as Rattlesnake, Hardcore Nationalist (HN2) and T-APT4 – comes under the spotlight in a new report from Group-IB, Old snake, new skin: Analysis of SideWinder APT activity between June and November 2021.

Tonga is the latest Pacific Island nation hit with ransomware

15 February 2023
Tonga Communications Corporation (TCC) — one of two telecoms companies in the country — published a notice on Facebook saying the attack may slow down administrative operations.

Vladislav “Vlad” Rudnitsky hired as CISO for Kaufman Rossin

15 February 2023
Vladislav Rudnitsky has been hired as Kaufman Rossin's CISO and will be responsible for safeguarding the firm’s systems, data and applications.