Latest Cybersecurity News and Articles


New Wave of Zero-Day Attacks Hits PyPI Repository

14 February 2023
Fortinet uncovered a wave of zero-day attacks targeting PyPI packages by a cybercriminal group dubbed Core1337. It has published five packages to the public repository - all designed to launch different types of attacks. All the malicious packages have similar code in the setup.py file, the only major difference between them is the webhook URL. Developers are suggested to stay extra cautious when downloading PyPI packages.

Apple fixes the first zero-day in iPhones and Macs this year

14 February 2023
Apple has released emergency security updates to address a new actively exploited zero-day vulnerability, tracked as CVE-2023-23529, that impacts iOS, iPadOS, and macOS. The flaw is a type confusion issue in WebKit.

Chinese Hackers Targeting South American Diplomatic Entities with ShadowPad

14 February 2023
Microsoft on Monday attributed a China-based cyber espionage actor to a set of attacks targeting diplomatic entities in South America. The tech giant's Security Intelligence team is tracking the cluster under the emerging moniker DEV-0147, describing the activity as an "expansion of the group's data exfiltration operations that traditionally targeted government agencies and think tanks in Asia

Spain, U.S. dismantle phishing gang that stole $5 million in a year

14 February 2023
The cybercrime gang specializes in online scams, employing social engineering, phishing, and smishing to collect sensitive victim details and then use that information to commit financial fraud.

MoneyGram Fraud Victims Get $115m in Compensation

14 February 2023
Nearly 40,000 consumers will be handed their share of the funds, which were forfeited by MoneyGram in 2018 as part of a deferred prosecution agreement (DPA). That action was led by the FTC and the Department of Justice (DoJ).

Valve waited 15 months to patch high-severity flaw. A hacker pounced

14 February 2023
Researchers have unearthed four game modes that could successfully exploit a critical vulnerability that remained unpatched in the popular Dota 2 video game for 15 months after a fix had become available.

Cl0p Exploits GoAnywhere MFT Servers; Impacts Over 130 Orgs

14 February 2023
The Clop ransomware group claimed to have successfully infected more than 130 organizations by abusing the zero-day in Fortra’s GoAnywhere MFT secure file transfer solution. The bug, tracked as CVE-2023-0669, is an RCE issue. The company immediately issued a patch and urged organizations using the software to immediately apply it. Hackers, who failed to share proof, said they did it in just ten days.

Hackers took their Middle Class Tax Refunds and now victims are getting a tax bill

14 February 2023
Many Californians are reporting that scammers drained their inflation relief debit cards before they could use the money. What's worse? They're now finding out they may have to pay income taxes on the money they never received.

Coincover raises $30M to help protect digital assets from hacks and human error

14 February 2023
Coincover, a digital asset protection company, has raised $30 million in funding led by Foundation Capital to protect people and their digital assets from hacks or human error, David Janczewski, CEO and co-founder, shared with TechCrunch.

Tor Network Hit By a Series of Ongoing DDoS Attacks

14 February 2023
The Tor Project’s Executive Director, Isabela Dias Fernandes, reported on Tuesday that the network has been targeted by a wave of DDoS attacks for at least the past seven months.

Top 5 Valentine’s Day cyber scams

14 February 2023
EXECUTIVE SUMMARY: One wrong click to heartache? Valentine’s Day is a serious, seasonal opportunity for scammers. This Valentine’s Day, red roses, heart-shaped boxes of candies, heart-themed cards, and other popular, expressive, and traditional gifts are expected to collectively account for $26 billion in retail revenue. This reflects a two billion dollar increase over last year’s […] The post Top 5 Valentine’s Day cyber scams appeared first on CyberTalk.

Massive HTTP DDoS Attack Hits Record High of 71 Million Requests/Second

14 February 2023
Web infrastructure company Cloudflare on Monday disclosed that it thwarted a record-breaking distributed denial-of-service (DDoS) attack that peaked at over 71 million requests per second (RPS). "The majority of attacks peaked in the ballpark of 50-70 million requests per second (RPS) with the largest exceeding 71 million," the company said, calling it a "hyper-volumetric" DDoS attack. It's also

Patch Now: Apple's iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day Flaw

13 February 2023
Apple on Monday rolled out security updates for iOS, iPadOS, macOS, and Safari to address a zero-day flaw that it said has been actively exploited in the wild. Tracked as CVE-2023-23529, the issue relates to a type confusion bug in the WebKit browser engine that could be activated when processing maliciously crafted web content, culminating in arbitrary code execution. The iPhone maker said the

New TA866 Threat Group Selectively Targets U.S. and German Organizations

13 February 2023
Proofpoint security experts uncovered a threat actor, tracked as TA886, infecting companies in the U.S. and Germany with the new WasabiSeed and Screenshotter malware. The custom malware can perform surveillance and steal data. Hackers push their malware via phishing emails that include Microsoft Publisher (.pub) attachments with malicious macros or PDFs containing URLs that download JavaScript files.

Christopher Walcutt promoted to Chief Security Officer at DirectDefense

13 February 2023
Christopher Walcutt has been promoted to Chief Security Officer at DirectDefense. Walcutt will partner with internal teams across all levels.

Enigma InfoStealer Steals Sensitive Data From Crypto Firms

13 February 2023
Trend Micro spotted an active campaign that leverages a fake employment bait against the cryptocurrency industry in Eastern Europe. Hackers are reportedly deploying Enigma Stealer which is a modified version of the Stealerium information stealer. The infection chain begins with a malicious RAR archive distributed through phishing attempts or via social media.

Earth Zhulong Group Uses ShellFang Loader to Target Vietnam

13 February 2023
Information on the sophisticated APT group Earth Zhulong, which targets Vietnamese organizations, has recently come to light. The gang, which has been active since 2020, is thought to be connected to the hacker collective 1937CN from China. Organizations are suggested to stay alert and leverage best practices such as the use of anti-malware and firewalls to stay protected.

7 tips for National Clean Out Your Computer Day

13 February 2023
EXECUTIVE SUMMARY: Looking to maximize your productivity and save time while working? Whether you have hundreds of audio recordings, RFPs, client documents, data sheets, drafts of publications, photos, or a smattering of each, keeping your computer organized can go a long way in enabling you be your best self at work. National Clean Out Your […] The post 7 tips for National Clean Out Your Computer Day appeared first on CyberTalk.

NewsPenguin Waddles into Pakistani Organizations

13 February 2023
A previously unknown threat group, named NewsPenguin, was found targeting organizations in Pakistan with the upcoming Pakistan International Maritime Expo & Conference (PIMEC-2023) as bait. The researchers stated that the goal of the cybercriminal group is solely focused on cyberespionage, with no financial motivation. 

Vulnerabilities open Korenix JetWave industrial networking devices to attack

13 February 2023
Three vulnerabilities found in a variety of Korenix JetWave industrial access points and LTE cellular gateways may allow attackers to either disrupt their operation or to use them as a foothold for further attacks, CyberDanube researchers have found.