Latest Cybersecurity News and Articles
09 February 2023
U.S. government and industry authorities are warning the healthcare sector of a surge in distributed denial-of-service attacks in recent days against hospitals and other medical entities instigated by Russian nuisance hacking group KillNet.
09 February 2023
Antoinette Hodes is a Check Point Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO. She has worked as an engineer in IT for over 25 years. She is a strong customer advocate, who connects people & processes with technology by matching the clients’ business needs with […]
The post Why CISOs need to adopt a prevention-first strategy for IoT appeared first on CyberTalk.
09 February 2023
Guardz today emerged from stealth mode with $10 million raised in a seed funding round led by Hanaco Ventures, with additional investment from iAngels, Cyverse Capital, and GKFF Ventures.
09 February 2023
The UNC2565 hacker group appears to have restructured its GOOTLOADER (or Gootkit) malware by adding new components and implementing new obfuscation techniques. Gootkit is used by adversaries to drop additional malicious payloads, such as SunCrypt, REvil (Sodinokibi) ransomware, Kronos trojan, and Cobalt Strike, on compromised systems.
09 February 2023
The development team behind the open-source password management software KeePass is disputing what is described as a newly found vulnerability that allows attackers to stealthily export the entire database in plain text.
09 February 2023
Contributed by Diana Polansky, Cloud Security Product Marketing Manager, and Sergio Silva, Product Incubation Manager. When we started to plan our goals for the new year, we took the time to think about your goals as well – and we don’t mean your personal New Year’s goals, like going to the gym more often. We […]
The post Choosing Check Point as an application security vendor appeared first on CyberTalk.
09 February 2023
Two more supply chain security flaws have been disclosed in AMI MegaRAC Baseboard Management Controller (BMC) software, nearly two months after three security vulnerabilities were brought to light in the same product.
Firmware security firm Eclypsium said the two shortcomings were held back until now to provide AMI additional time to engineer appropriate mitigations.
The issues, collectively
09 February 2023
Microsoft on Tuesday said it took steps to disable fake Microsoft Partner Network (MPN) accounts that were used for creating malicious OAuth applications as part of a malicious campaign designed to breach organizations' cloud environments and steal email.
"The applications created by these fraudulent actors were then used in a consent phishing campaign, which tricked users into granting
09 February 2023
A new malvertising campaign has surfaced that abuses Google Ads to target users searching for password managers and, in fact, directed them to fake sponsored websites. Previously, the FBI had warned about the explosion of such attacks that impersonated websites involved in finances and duped users into sharing their login credentials and financial data.
09 February 2023
Given that the content is written in Spanish, this campaign targets Spanish-speaking people. It shows a blurred picture of a statement that tricks the user into clicking the "Enable Content" button for a clearer view which actually enables macros.
09 February 2023
Atlantic General Hospital in Maryland is experiencing network disruptions and outages after a significant ransomware attack deployed this weekend, according to local news outlet WMDT47.
09 February 2023
Container technology has gained traction among businesses due to the increased efficiency it provides. In this regard, organizations widely use Kubernetes for deploying, scaling, and managing containerized applications. Organizations should audit Kubernetes to ensure compliance with regulations, find anomalies, and identify security risks. The Wazuh open source platform plays a critical role in
09 February 2023
While it's true that DORA will primarily impact entities operating in the financial sector, DORA's regulations focus on establishing greater cyber-resilience, and will, therefore, also impact information technology roles and companies.
09 February 2023
“At first glance, the email seems to be a legitimate communication from DocuSign, with the sender name being manipulated by the attacker, reading Docusign,” reads the technical write-up by Armorblox.
09 February 2023
ASEC stumbled across phishing emails warning users that their accounts would be shut down unless they perform a particular action. Hackers used Google's favicon feature to trick users into revealing their credentials. The account credentials entered on the phishing page were sent to a C2 whose address was the same domain as a previous campaign observed by the researchers.
09 February 2023
Security researchers at Imperva have suggested that over a quarter of all cyber-attacks (28%) in the UK have hit the financial services and insurance (FSI) industry in the last 12 months.
09 February 2023
The Brazilian threat actors behind an advanced and modular point-of-sale (PoS) malware known as Prilex have reared their head once again with new updates that allow it to block contactless payment transactions.
Russian cybersecurity firm Kaspersky said it detected three versions of Prilex (06.03.8080, 06.03.8072, and 06.03.8070) that are capable of targeting NFC-enabled credit cards, taking its
09 February 2023
The security directive, issued Friday, “reinforces existing requirements on handling sensitive security information and personally identifiable information,” a TSA spokesperson said.
09 February 2023
The Series A round was led by Standard Investments, with participation from Munich Re Ventures, Moore Strategic Ventures, Xerox Ventures, INT3, Bessemer Venture Partners, and Zeev Ventures — bringing its total raised to $53 million.
09 February 2023
Recently EclecticIQ Threat Research Team spotted samples of Godfather imitating Google Protect apps and fooling users into believing they are protected by an Android service. After successful infection, Godfather obtains the permissions for Accessibility Service and collects the default user agent, country code of the network operator, Bot ID, list of installed apps, Android version, device model, and others.