Latest Cybersecurity News and Articles


Chinese Speaking Threat Actors Leveraging Open-Source Tools to Target East Asia

09 February 2023
A series of attacks was discovered infecting organizations in East Asia with SparkRAT, originally an open source tool. TTPs of the attacks point toward the involvement of a Chinese-speaking threat actor dubbed DragonSpark. The Microsoft Security Threat Intelligence team reported about threat actors using SparkRAT for the first time in late December 2022.

Google deletes 50,000 pro-China fake-news vids and blogs

09 February 2023
Dragonbridge ran disinformation campaigns across Google-owned platforms YouTube, Blogger and AdSense. Meta and Twitter have also removed fake content from China that looks and sounds very similar to Dragonbridge's efforts.

Alleged member of ShinyHunters group extradited to the US, could face 116 years in jail

09 February 2023
Sebastien Raoult, a French national who is suspected of being a member of ShinyHunters cybercrime gang known as “Seyzo Kaizen,” has been extradited from Morocco to the United States.

New Mimic Ransomware Abuses Windows' 'Everything' Search Tool

09 February 2023
Researchers at Trend Micro discovered a new ransomware strain, dubbed Mimic, that utilizes the 'Everything' file search tool on Windows to discover files to be targeted for encryption. English and Russian-speaking users are the prime targets. The ransomware supports command-line arguments to narrow down encryption targets. It also makes use of multi-threaded execution to speed up the data encryption process.

Targets of Opportunity: How Ransomware Groups Find Victims

09 February 2023
Organizations in some geographies are more likely to fall victim. Group-IB reports that from July 2021 through June 2022, 43% of known ransomware attacks hit U.S. organizations. Next in line were Germany, the U.K., Canada, Italy, and France.

Sandworm hackers hit Ukraine news agency with 5 data wipers

09 February 2023
As CERT-UA found during the investigation, the threat actors gained remote access to Ukrinform's network around December 7, 2022, and waited more than a month to unleash the malware cocktail.

US Reiterates $10 Million Reward Offer After Disruption of Hive Ransomware

09 February 2023
Following the shutdown of the Hive ransomware operation by law enforcement, the US government has reminded the public that a reward of up to $10 million is offered for information on cybercriminals.

Target says data sold on dark web is ‘outdated,’ likely ‘released by third party’

09 February 2023
Following the posting of an alleged database of customer information on a hacker forum, Target is denying that the data being sold on the dark web is current and says that the information was not taken directly from its systems.

CISA’s Joint Cyber Defense Collaborative to tackle energy, water security in 2023

09 February 2023
The CISA's Joint Cyber Defense Collaborative (JCDC) will be focusing this year on beefing up security in the energy sector and leading the effort to update the National Cyber Incident Response Plan, according to the body’s planning agenda.

OneSpan acquires ProvenDB to address customers’ secure vaulting needs

09 February 2023
ProvenDB has been at the forefront of developing secure storage, leveraging blockchain technology that adds a layer of security to prevent data tampering or alteration of documents.

ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

09 February 2023
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could lead to a denial-of-service (DoS) condition.

DEV-0569 Abuses Google Ads to Breach Network

09 February 2023
The DEV-0569 threat actor was found abusing Google Ads in ongoing advertising campaigns to deploy malware, exfiltrate victims’ passwords, and breach networks for ransomware attacks. Some of the top programs impersonated by adversaries are Rufus, 7-Zip, FileZilla, LightShot, AnyDesk, LibreOffice, VLC, Awesome Miner, WinRAR, and TradingView.

Multiple Vulnerabilities Found In Healthcare Software OpenEMR

09 February 2023
A combination of these vulnerabilities allows remote attackers to execute arbitrary system commands on any OpenEMR server and to steal sensitive patient data. In the worst case, they can compromise the entire critical infrastructure.

Unconsidered benefits of a consolidation strategy every CISO should know

09 February 2023
Pete has 32 years of Security, Network, and MSSP experience and has been a hands-on CISO for the last 17 years and joined Check Point as Field CISO of the Americas. Pete’s cloud security deployments and designs have been rated by Garter as #1 and #2 in the world and he literally “wrote the book” […] The post Unconsidered benefits of a consolidation strategy every CISO should know appeared first on CyberTalk.

5 ways private cloud enhances data privacy for businesses

09 February 2023
Contributed by April Miller, Senior Writer for Rehack.com. Businesses rely on data, but much of this information requires privacy. Whether you’re dealing with proprietary trade secrets, customers’ personally identifiable information (PII) or financial data, you need to ensure that only authorized parties can see or access it. A private cloud is one of the best storage […] The post 5 ways private cloud enhances data privacy for businesses appeared first on CyberTalk.

Do you use OneDrive or Google Drive? Watch out for this malware

09 February 2023
Contributed by George Mack, Content Marketing Manager, Check Point Software. A recent report has revealed that OneDrive is responsible for 30% of all cloud malware downloads, a far higher percentage than most other cloud applications. This is a dramatic increase of almost three times the amount from the previous year. This report highlights the need […] The post Do you use OneDrive or Google Drive? Watch out for this malware appeared first on CyberTalk.

AI + ChatGPT applied to mainstream, hybrid meetings

09 February 2023
David Shim is the Co-Founder and CEO of Read AI, which combines AI and analytics to make hybrid meetings more effective. On average Read identifies 23 meeting hours a month that could be eliminated per employee. Read’s mission is to make every human interaction meaningfully better, smarter, and happier starting with the more than 500 […] The post AI + ChatGPT applied to mainstream, hybrid meetings appeared first on CyberTalk.

A step-by-step guide: How to create a data collection policy

09 February 2023
EXECUTIVE SUMMARY: Data is the new gold. Nearly everyone has clicked ‘accept’ on cookie tracking pop-ups without reading the fine print. In fact, it’s almost become second nature. But employees and consumers have many questions. Where does the data go, who controls it, what are the implications, and how will it be secured? As a […] The post A step-by-step guide: How to create a data collection policy appeared first on CyberTalk.

How a fast-changing threat landscape catalyzed a cyber pandemic

09 February 2023
In this edited interview excerpt from a Nasdaq TradeTalk, Check Point CEO Gil Shwed discusses artificial intelligence, the cyber pandemic, ransomware and so much more. Don’t miss this! What is the big security concern around AI chat technologies, such as ChatGPT? GS: Oh, there are so many. I think that these technologies are producing a […] The post How a fast-changing threat landscape catalyzed a cyber pandemic appeared first on CyberTalk.

Eye-opening data privacy trends and statistics (2023 and beyond)

09 February 2023
EXECUTIVE SUMMARY: Data is one of the most important and valuable assets for businesses. It functions as a guiding light, helping leaders see around corners, make transformative strategy decisions, stay uber competitive, and deliver better tangible business outcomes. In some cases, data is as elevated and celebrated as revenue, customer service excellence, and profitability. However, […] The post Eye-opening data privacy trends and statistics (2023 and beyond) appeared first on CyberTalk.