Latest Cybersecurity News and Articles


Malicious Google Ads Sneak AWS Phishing Sites into Search Results

10 February 2023
The security firm reports seeing Portuguese used as a language in the JavaScript code comments and variables, while the root page of the blogger domain mimics a Brazilian dessert business.

Bogus URL Shorteners Redirect Thousands of Hacked Sites in AdSense Fraud Campaign

10 February 2023
If a user enters any of the bogus domain names in a browser, it will be redirected to a real URL shortening service: Bitly, Cuttly, or ShortUrl.at, which makes it look like they are just alternative domains for the well-known services.

3 Overlooked Cybersecurity Breaches

10 February 2023
Here are three of the worst breaches, attacker tactics and techniques of 2022, and the security controls that can provide effective, enterprise security protection for them. #1: 2 RaaS Attacks in 13 Months Ransomware as a service is a type of attack in which the ransomware software and infrastructure are leased out to the attackers. These ransomware services can be purchased on the dark web from

Hacker Develops New 'Screenshotter' Malware to Find High-value Targets

10 February 2023
The threat actor targets victims using phishing emails that include Microsoft Publisher (.pub) attachments with malicious macros, URLs linking to .pub files with macros, or PDFs containing URLs that download dangerous JavaScript files.

Largest Canadian Bookstore Indigo Shuts Down Site After Cyberattack

10 February 2023
Although it is still early in the investigation and the company has not released any information about the method used to breach its systems, the hackers may have used data collected by information-stealing malware to gain access to Indigo’s network.

U.K. and U.S. Sanction 7 Russians for TrickBot, Ryuk, and Conti Ransomware Attacks

10 February 2023
In a first-of-its-kind coordinated action, the U.K. and U.S. governments on Thursday levied sanctions against seven Russian nationals for their affiliation to the TrickBot, Ryuk, and Conti cybercrime operation. The individuals designated under sanctions are Vitaly Kovalev (aka Alex Konor, Bentley, or Bergen), Maksim Mikhailov (aka Baget), Valentin Karyagin (aka Globus), Mikhail Iskritskiy (aka

Android 14 to block malware from abusing sensitive permissions

10 February 2023
A highlighted security feature in Android 14 is to block the installation of malicious apps that target older API levels (Android versions), which allows easier abuse of sensitive permissions.

Reddit Suffers Security Breach Exposing Internal Documents and Source Code

10 February 2023
Popular social news aggregation platform Reddit has disclosed that it was the victim of a security incident that enabled unidentified threat actors to gain unauthorized access to internal documents, code, and some unspecified business systems. The company blamed it on a "sophisticated and highly-targeted phishing attack" that took place on February 5, 2023, targeting its employees. The attack

A Hackers Pot of Gold: Your MSP's Data

09 February 2023
A single ransomware attack on a New Zealand managed service provider (MSP) disrupted several of its clients' business operations overnight, most belonging to the healthcare sector. According to the country's privacy commissioner, "a cyber security incident involving a ransomware attack" in late November upended the daily operations of New Zealand's health ministry when it prevented the staff

Gootkit Malware Adopts New Tactics to Attack Healthcare and Finance Firms

09 February 2023
The Gootkit malware is prominently going after healthcare and finance organizations in the U.S., U.K., and Australia, according to new findings from Cybereason. The cybersecurity firm said it investigated a Gootkit incident in December 2022 that adopted a new method of deployment, with the actors abusing the foothold to deliver Cobalt Strike and SystemBC for post-exploitation. "The threat actor

OpenSSL Fixes Multiple New Security Flaws with Latest Update

09 February 2023
The OpenSSL Project has released fixes to address several security flaws, including a high-severity bug in the open source encryption toolkit that could potentially expose users to malicious attacks. Tracked as CVE-2023-0286, the issue relates to a case of type confusion that may permit an adversary to "read memory contents or enact a denial-of-service," the maintainers said in an advisory. The

How to Spot a Nefarious Cryptocurrency Platform

09 February 2023
It’s not unheard of for criminals to use multinational banks to launder money. But if you invest in crypto and your platform gets sanctioned overnight, you might not be able to recover your coins the next day.

QakNote Campaign Leverages OneNote to Infect Victims with QBot

09 February 2023
A large-scale QakNote campaign is ongoing that drops QBot banking trojan on systems via malicious Microsoft OneNote attachments. The phishing emails contain OneNote files that have an embedded HTML application (HTA file) that retrieves the QBot malware payload. The adoption signals “a much more automated, streamlined fashion” as opposed to previous small-scale malware attacks.

OpenSSL Fixes Multiple New Security Flaws with Latest Update

09 February 2023
The vulnerability is rooted in the way the popular cryptographic library handles X.509 certificates, and is likely to impact only those applications that have a custom implementation for retrieving a certificate revocation list (CRL) over a network.

Quasar RAT Propagated via Private Home Trading System

09 February 2023
A private Home Trading System is used to spread the Quasar RAT virus, according to ASEC. In other cases, phoney investment firms that passed for real ones persuaded customers to install a fake HTS so they could steal their money. Quasar RAT comes with remote command execution and uploading and downloading files features. 

Enigma Stealer Targets Cryptocurrency Industry with Fake Jobs

09 February 2023
The initial stage of Enigma, Interview conditions.word.exe, is a downloader written in C++. Its primary objective is to download, deobfuscate, decompress, and launch the secondary stage payload.

Must-know ways to overcome the much-dreaded ‘freeze’ response

09 February 2023
EXECUTIVE SUMMARY: Despite CISOs’ formidable training efforts on behalf of teams, a commonly overlooked phenomenon is the human tendency to freeze amidst a crisis. Building your incident response operations around this ingrained aspect of psychology can help prevent your teams from seizing up during intense and urgent situations. In the event of an intrusion or […] The post Must-know ways to overcome the much-dreaded ‘freeze’ response appeared first on CyberTalk.

U.S., U.K. Sanction 7 Men Tied to Trickbot Hacking Group

09 February 2023
Authorities in the United States and United Kingdom today levied financial sanctions against seven men accused of operating "Trickbot," a cybercrime-as-a-service platform based in Russia that has enabled countless ransomware attacks and bank account takeovers since its debut in 2016. The U.S. Department of the Treasury says the Trickbot group is associated with Russian intelligence services, and that this alliance led to the targeting of many U.S. companies and government entities.

Medusa Botnet Goes Through a Major Transformation

09 February 2023
Researchers at Cyble uncovered a new Medusa DDoS botnet version based on the leaked Mirai source code. With this, it has appropriated Mirai's DDoS attack choices and Linux targeting capabilities. It comes with a ransomware module and Telnet brute-forcer. Additionally, a dedicated portal now advertises Medusa as a malware-as-a-service for DDoS or mining.

Ransomware attacks took slight dip in 2022

09 February 2023
The NCC Group's 2022 Annual Threat Monitor Report found that there were slightly less attacks than 2021 with a 5% decrease in ransomware activity.