Latest Cybersecurity News and Articles
15 February 2023
Microsoft researchers released in-depth analyses of the threat ecology of the Russian-affiliated Nobelium group and how it exploited MagicWeb to perform a complex authentication bypass for Active Directory Federated Services (AD FS). Microsoft first spotted MagicWeb in August 2022, when a Microsoft customer fell victim to a post-compromise capability of MagicWeb.
15 February 2023
Researchers have identified a template injection technique against the open-source SaltStack IT configuration and orchestration platform, as well as common misconfiguration issues, which could allow attackers to gain over the organization's network.
15 February 2023
Check Point has released its Global Threat Index report for January 2023, which shows AgentTesla returning to the third spot (from the ninth in December 2022) in the January 2023 Most Wanted Malware list.
15 February 2023
On Friday, the orchestra and the Kimmel Center said ticket sales were affected by a cyberattack, without providing further details. A spokesperson for the Philadelphia Orchestra did not respond to a request for comment.
15 February 2023
Increasing geopolitical tensions, vulnerabilities in critical infrastructure, and a patchwork of needed regulations are some of the factors contributing to a host of cybersecurity threats facing the public and private sectors in the new year.
15 February 2023
In an ideal world, security and development teams would be working together in perfect harmony. But we live in a world of competing priorities, where DevOps and security departments often butt heads with each other.
Agility and security are often at odds with each other— if a new feature is delivered quickly but contains security vulnerabilities, the SecOps team will need to scramble the release
15 February 2023
Cybersecurity researchers have unearthed a new piece of evasive malware dubbed Beep that's designed to fly under the radar and drop additional payloads onto a compromised host.
"It seemed as if the authors of this malware were trying to implement as many anti-debugging and anti-VM (anti-sandbox) techniques as they could find," Minerva Labs researcher Natalie Zargarov said.
"One such technique
15 February 2023
Android devices manufactured by top firms are being delivered with pre-installed malware in China, revealed researchers from the Universities of Edinburgh and Dublin. The apps were created to covertly exfiltrate user and device data, including system information, geolocation, user profiles, and call histories. Even those who left the country are exposed to surveillance threats.
15 February 2023
The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823).
15 February 2023
Zscaler acquires Canonic Security to prevent organizations’ growing risks of SaaS supply chain attacks. Canonic’s solution allows cybersecurity and IT teams to gain visibility and streamline SaaS application governance and enforcement.
15 February 2023
The Mountain View, California-based company warned that security problems exist on three of its most popular software products — Photoshop, Illustrator, and After Effects.
15 February 2023
Google announced on Tuesday that it's officially rolling out Privacy Sandbox on Android in beta to eligible mobile devices running Android 13.
"The Privacy Sandbox Beta provides new APIs that are designed with privacy at the core, and don't use identifiers that can track your activity across apps and websites," the search and advertising giant said. "Apps that choose to participate in the Beta
15 February 2023
By Antoinette Hodes, a Check Point Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO. She has worked as an engineer in IT for over 25 years. She is a strong customer advocate, who connects people & processes with technology by matching the clients’ business needs with […]
The post The 2 biggest regulatory challenges for the internet of “any” thing (IoT) appeared first on CyberTalk.
14 February 2023
Microsoft on Tuesday released security updates to address 75 flaws spanning its product portfolio, three of which have come under active exploitation in the wild.
The updates are in addition to 22 flaws the Windows maker patched in its Chromium-based Edge browser over the past month.
Of the 75 vulnerabilities, nine are rated Critical and 66 are rated Important in severity. 37 out of 75 bugs are
14 February 2023
EXECUTIVE SUMMARY: Pepsi Bottling Ventures, the largest bottler of Pepsi-Cola beverages in the United States, is responsible for manufacturing, selling and distributing a variety of popular consumer brands. The company operates 18 bottling facilities across North and South Carolina, Virginia, Maryland and Delaware. On the 23rd of December, a network intrusion occurred, resulting in a […]
The post Pepsi Bottling Ventures breached, extensive employee data stolen appeared first on CyberTalk.
14 February 2023
Microsoft is sending the world a whole bunch of love today, in the form of patches to plug dozens of security holes in its Windows operating systems and other software. This year's special Valentine's Day Patch Tuesday includes fixes for a whopping three different "zero-day" vulnerabilities that are already being used in active attacks.
14 February 2023
Cybercriminals are becoming more adept at creating a sense of urgency for victims and motivating them to engage in their agenda, reveals the Avast Q4 2022 report. Refund and invoice fraud saw a 22% jump in December 2022, with perpetrators utilizing emails originating from a trustworthy organization to create the illusion of unauthorized charges and false receipts.
14 February 2023
Research on the risks of industrial wireless IoT was released finding that they can provide a path to internal operational technology (OT) networks.
14 February 2023
According to Sucuri’s research, the backdoor redirects users to sites that show fraudulent views of Google AdSense ads. The company’s SiteCheck remote scanner has detected more than 10,890 infected sites.
14 February 2023
The threat actors behind the black hat redirect malware campaign have scaled up their campaign to use more than 70 bogus domains mimicking URL shorteners and infected over 10,800 websites.
"The main objective is still ad fraud by artificially increasing traffic to pages which contain the AdSense ID which contain Google ads for revenue generation," Sucuri researcher Ben Martin said in a report