Latest Cybersecurity News and Articles


Scattered Spider Shifts Focus from BPOs and Telecos to IT and Gaming Companies

09 February 2023
A CrowdStrike report revealed that the Scattered Spider threat actors are still actively targeting video game and tech companies, after attacking 130 organizations in 2022. There are fake domains impersonating video game makers Roblox and Zynga; IT giants Intuit, Salesforce, Comcast, and Grubhub; and customer service provider TaskUs.

NewsPenguin, a Previously Unknown Threat Actor, Targets Pakistan with Advanced Espionage Tool

09 February 2023
The Canadian cybersecurity company said the attacks are designed to target marine-related entities and the event's visitors by tricking the message recipients into opening the seemingly harmless Microsoft Word document.

AmerisourceBergen Healthcare Company Has Been Breached

09 February 2023
The Lorenz gang chose to get inside organizations’ networks by leveraging critical flaws in Mitel telephony systems. After the initial access, the threat actor remains silent for months and then exfiltrates and encrypts files using a backdoor.

PayPal and Twitter Abused in Turkey Relief Donation Scams

09 February 2023
As government, businesses and charity organizations step up to raise funds and aid victims of this ecological disaster, threat actors are wasting no time in targeting unsuspecting donors.

NewsPenguin Threat Actor Emerges with Malicious Campaign Targeting Pakistani Entities

09 February 2023
A previously unknown threat actor dubbed NewsPenguin has been linked to a phishing campaign targeting Pakistani entities by leveraging the upcoming international maritime expo as a lure. "The attacker sent out targeted phishing emails with a weaponized document attached that purports to be an exhibitor manual for PIMEC-23," the BlackBerry Research and Intelligence Team said. PIMEC, short for

FBI Media Alert: Valentine's Day in New Mexico Means Love - and Scams

09 February 2023
Romance scam perpetrators are usually men targeting older women who are divorced, widowed, elderly, or disabled—but scammers do not discriminate. To facilitate the investment and demonstrate the ROI, victims are directed to fake websites.

THN Webinar – Learn How to Comply with New Cyber Insurance Identity Security Requirements

09 February 2023
The Hacker News is thrilled to announce the launch of our new educational webinar series, in collaboration with the leading cybersecurity companies in the industry! Get ready to dive into the world of enterprise-level security with expert guests who will share their vast knowledge and provide you with valuable insights and information on various security topics. Whether you're a seasoned

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices

09 February 2023
A set of 38 security vulnerabilities has been uncovered in wireless industrial internet of things (IIoT) devices from four different vendors that could pose a significant attack surface for threat actors looking to exploit operational technology (OT) environments. "Threat actors can exploit vulnerabilities in Wireless IIoT devices to gain initial access to internal OT networks," Israeli

US NIST unveils winning encryption algorithm for IoT data protection

09 February 2023
Small IoT devices are becoming increasingly popular and omnipresent, used in wearable tech, smart home applications, etc. However, they are still used to store and handle sensitive personal information, such as health data, and financial details.

10 secrets for successful digital transformations

09 February 2023
EXECUTIVE SUMMARY: Digitize to survive and thrive? Digital transformations account for 40% of all business technology spending, and the digital transformation era is expected continue well into 2023. As enterprises become digital-at-scale, building on strategies and investments to meet new demands, drive growth and enhance customer experiences, businesses may wish to appraise how digital transformations are […] The post 10 secrets for successful digital transformations appeared first on CyberTalk.

GAO Calls for Action to Protect Cybersecurity of Critical Energy, Communications Networks

09 February 2023
The GAO's assessment also calls on the Cybersecurity and Infrastructure Agency (CISA) to improve coordination and incident management among all levels of government—local, regional, and national—to protect against ransomware cyberattacks.

Unpatched Security Flaws Disclosed in Multiple Document Management Systems

09 February 2023
A typical attack pattern would be to steal the session cookie that a locally logged in administrator is authenticated with, and reuse that session cookie to impersonate that user to create a new privileged account.

Weee! Grocery Service Confirms Data Breach Affecting 1.1 Million

09 February 2023
The leaked database contains Weee! customers' first and last names, email addresses, phone numbers, device type (iOS/PC/Android), order notes, and other data the delivery platform uses.

Russian e-Commerce Giant Elevel Exposed Buyers’ Delivery Addresses

09 February 2023
The dataset with seven million data entries leaked two years’ worth of sensitive data, including names, surnames, phone numbers, email addresses, and delivery addresses of customers.

Chrome 110 Patches 15 Vulnerabilities

09 February 2023
Of the externally reported bugs, three are rated ‘high severity’. These include a type confusion flaw in the V8 engine, an inappropriate implementation issue in full screen mode, and an out-of-bounds read vulnerability in WebRTC.

Malicious Dota 2 Game Mods Infected Players with Malware

09 February 2023
While the threat actor made it very easy to detect the bundled backdoor in the first game mode published on the Steam Store, the twenty lines of code malicious code included with the three newer game mods were much harder to spot.

New Graphiron Info-stealer Used in Attacks Against Ukraine

09 February 2023
The Graphiron malware allows operators to harvest a wide range of information from the infected systems, including system info, credentials, screenshots, and files. The malicious code is written in the Go programming language.

Tor and I2P Networks Hit by Wave of Ongoing DDoS Attacks

09 February 2023
The Tor network and I2P peer-to-peer network has been dealing with massive DDoS attack. Tor's team said it will keep tweaking the network's defenses to address this ongoing issue. The goal of these ongoing attacks is unknown.

Titan Stealer: A New Golang-Based Information Stealer Malware Emerges

09 February 2023
A new Golang-based information stealer malware dubbed Titan Stealer is being advertised by threat actors through their Telegram channel. "The stealer is capable of stealing a variety of information from infected Windows machines, including credential data from browsers and crypto wallets, FTP client details, screenshots, system information, and grabbed files," Uptycs security researchers

Realtek Vulnerability Under Attack: Over 134 Million Attempts to Hack IoT Devices

09 February 2023
Researchers are warning about a spike in exploitation attempts weaponizing a critical remote code execution flaw in Realtek Jungle SDK since the start of August 2022. According to Palo Alto Networks Unit 42, the ongoing campaign is said to have recorded 134 million exploit attempts as of December 2022, with 97% of the attacks occurring in the past four months. Close to 50% of the attacks