Latest Cybersecurity News and Articles


Researchers Uncover New Bugs in Popular ImageMagick Image Processing Utility

09 February 2023
Cybersecurity researchers have disclosed details of two security flaws in the open source ImageMagick software that could potentially lead to a denial-of-service (DoS) and information disclosure. The two issues, which were identified by Latin American cybersecurity firm Metabase Q in version 7.1.0-49, were addressed in ImageMagick version 7.1.0-52, released in November 2022. A

The best AWS security practices for 2023

09 February 2023
EXECUTIVE SUMMARY: As organizations have transitioned from basic cloud environments to distributed, and considerably more complex cloud-native environments, the cloud security strategies of 5 years ago have become outdated. To enact a better cloud security strategy that allows you to stay a step ahead of cyber criminals, here’s what you need to know… Are you […] The post The best AWS security practices for 2023 appeared first on CyberTalk.

New Threat: Stealthy HeadCrab Malware Compromised Over 1,200 Redis Servers

09 February 2023
At least 1,200 Redis database servers worldwide have been corralled into a botnet using an "elusive and severe threat" dubbed HeadCrab since early September 2021. "This advanced threat actor utilizes a state-of-the-art, custom-made malware that is undetectable by agentless and traditional anti-virus solutions to compromise a large number of Redis servers," Aqua security researcher Asaf Eitani 

Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking

09 February 2023
Researcher Rustam Amin informed the CISA that he had identified critical and high-severity vulnerabilities in Econolite EOS, a traffic controller software developed for the Econolite Cobalt and other advanced transportation controllers (ATC).

Porsche halts NFT launch, phishing sites fill the void

09 February 2023
Porsche cut its minting of a new NFT collection short after a dismal turnout and backlash from the crypto community, allowing threat actors to fill the void by creating phishing sites that steal digital assets from cryptocurrency wallets.

Are Your Employees Thinking Critically About Their Online Behaviors?

09 February 2023
When employees understand how their day-to-day online behaviors — no matter how small — can expose sensitive data, they're less likely to introduce risk in the first place.

Threat Actors Abuse Microsoft's Verified Publisher Status

09 February 2023
Security experts at Proofpoint disclosed that cyber adversaries are using malicious OAuth applications to abuse Microsoft's "verified publisher" status. The activity is intended to gain access to the cloud environments of targeted organizations, pilfer data, and also scan through users' mailboxes, calendars, files, and more. The early signs of the campaign, involving consent phishing, were spotted in December 2022.

Crypto scam apps infiltrate Apple App Store and Google Play

09 February 2023
Operators of high-yielding investment scams known as "pig butchering" have found a way to bypass the defenses in Google Play and Apple's App Store, the official repositories for Android and iOS apps.

Cybersecurity budgets are going up. So why aren't breaches going down?

09 February 2023
Over the past few years, cybersecurity has become a major concern for businesses around the globe. With the total cost of cybercrime in 2023 forecasted to reach $8 Trillion – with a T, not a B – it’s no wonder that cybersecurity is top of mind for leaders across all industries and regions. However, despite growing attention and budgets for cybersecurity in recent years, attacks have only become

North Korean Hackers Exploit Unpatched Zimbra Devices in 'No Pineapple' Campaign

09 February 2023
A new intelligence gathering campaign linked to the prolific North Korean state-sponsored Lazarus Group leveraged known security flaws in unpatched Zimbra devices to compromise victim systems. That's according to Finnish cybersecurity company WithSecure (formerly F-Secure), which codenamed the incident No Pineapple. Targets of the malicious operation included a healthcare research organization

Why Attackers Target the Financial Services Industry

09 February 2023
The financial services industry is consistently the most targeted industry across the board. The potential for large payouts and valuable data for use or resale are the most common reasons for targeting the financial services industry.

Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’

09 February 2023
Dutch cyber authorities said Wednesday that several hospital websites in the Netherlands and Europe were likely targeted by a pro-Kremlin hacking group because of their countries’ support for Ukraine.

Gem Security wants to secure your cloud infrastructure, raises $11M

09 February 2023
The New York- and Tel Aviv-based startup, which is building a cloud security platform, is coming out of stealth today and announced an $11 million seed funding round led by Team8.

New Sh1mmer Exploit Allows Root Level Access for ChromeOS

09 February 2023
A new exploit, dubbed SH1MMER, has been devised to unenroll enterprise- or school-managed Chromebooks from administrative control, letting a user bypass admin restrictions. The exploit uses publicly leaked Return Merchandise Authorization (RMA) shims to modify the management of enrollment of devices. Google is working with hardware partners to address it.

New 'Passion' DDoS-as-a-Service Platform Used in Recent Attacks on Hospitals

09 February 2023
Radware discovered the Passion platform, and although its origins are unknown, the operation has distinctive ties with Russian hacking groups, suck as Killnet, MIRAI, Venom, and Anonymous Russia.

Who Does Your CISO Report To?

09 February 2023
In the past, many CISOs primarily focused on compliance and risk management. However, today’s CISOs are expected to be strategic thought leaders who can help their organizations navigate the ever-changing landscape of cybersecurity threats.

New Russian-Backed Gamaredon's Spyware Variants Targeting Ukrainian Authorities

09 February 2023
The State Cyber Protection Centre (SCPC) of Ukraine has called out the Russian state-sponsored threat actor known as Gamaredon for its targeted cyber attacks on public authorities and critical information infrastructure in the country. The advanced persistent threat, also known as Actinium, Armageddon, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, and UAC-0010, has a track record of 

Novel State-of-the-Art Redis Malware Discovered in a Global Campaign

09 February 2023
Discovered by Aqua Security researchers Nitzan Yaakov and Asaf Eitani, who dubbed it HeadCrab, the malware has so far taken control of at least 1,200 Redis servers, which are then used to scan for more targets online.

Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing

09 February 2023
No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute. Just as cybercrime networks are getting stronger and larger, so too must collaboration between private companies and law enforcement.

Hackers Use New IceBreaker Malware to Breach Gaming Companies

09 February 2023
Researchers at incident response firm Security Joes believe that the IceBreaker backdoor is the work of a new advanced threat actor that uses "a very specific social engineering technique," which could lead to a more clear picture of who they are.