Latest Cybersecurity News and Articles


Malicious NPM, PyPI Packages Stealing User Information

09 February 2023
Taking advantage of the broad use of open source code in application development, malicious actors are increasingly relying on software supply chain attacks to infect both developers and users with malware.

The most used password in 2022 was ‘password’

09 February 2023
A 2022 NordPass study reveals the most common password globally was 'password', which was cracked within less than a second on average.

'No Pineapple' Cyber Espionage Campaign Reveals North Korean Toolkit

09 February 2023
A threat intelligence firm spotted North Korean hackers engaged in technological espionage in a campaign that betrayed recurring elements of the Pyongyang hacking toolkit.

Mapping Threat Intelligence to the NIST Compliance Framework Part 2

09 February 2023
As CTI teams prioritize the intelligence requirements of their business stakeholders, it is beneficial to provide context by mapping the impact of cybersecurity threat intelligence programs to the following NIST core functions.

Researchers Uncover New Bugs in Popular ImageMagick Image Processing Utility

09 February 2023
The two issues, which were identified by Latin American cybersecurity firm Metabase Q in version 7.1.0-49, were addressed in ImageMagick version 7.1.0-52, released in November 2022.

Vulnerability in Cisco industrial appliances is a potential nightmare (CVE-2023-20076)

09 February 2023
CVE-2023-20076 was discovered by the researchers in a Cisco ISR 4431 router – more specifically, in the Cisco IOx application hosting environment, which allows admins to deploy application containers or virtual machines directly on Cisco devices.

Global Derivatives Markets Impacted by LockBit Ransomware Attack on Financial Software Company

09 February 2023
The attack is “impacting the trading and clearing of exchange-traded derivatives by ION customers across global markets,” according to the Futures Industry Association (FIA).

Over 1,800 Android phishing forms for sale on cybercrime market

09 February 2023
A threat actor named InTheBox is promoting on Russian cybercrime forums an inventory of 1,894 web injects (overlays of phishing windows) for stealing credentials and sensitive data from banking, cryptocurrency exchange, and e-commerce apps.

50% of organizations have indirect relationships with 200+ breached fourth-party vendors

09 February 2023
About 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years, according to SecurityScorecard and The Cyentia Institute.

New APT34 Malware Targets The Middle East

09 February 2023
Trend Micro analyzed a cyberespionage campaign targeting organizations in the Middle East in December 2022 using a new backdoor. It abuses compromised email accounts to send stolen data to external mail accounts controlled by attackers.

New Russian-Backed Gamaredon's Spyware Variants Targeting Ukrainian Authorities

09 February 2023
The State Cyber Protection Centre (SCPC) of Ukraine has called out the Russian state-sponsored threat actor known as Gamaredon for its targeted cyber attacks on public authorities and critical information infrastructure in the country.

EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft

09 February 2023
Researchers warn that many electric vehicle (EV) charging management systems are affected by vulnerabilities that could allow hackers to cause disruption, steal energy, or obtain driver information.

The FTX meltdown: Five takeaways for cyber security professionals

09 February 2023
By CyberTalk Staff The FTX bankruptcy saga is sending shockwaves throughout cryptocurrency and DeFi (distributed finance using blockchain) industries. Knowing the factors surrounding the rise and fall of FTX can help security leaders to detect and reduce risks to your security practice when dealing with crypto. Here are five security takeaways: Takeaway #1: How secure […] The post The FTX meltdown: Five takeaways for cyber security professionals appeared first on CyberTalk.

How three Fortune 500 firms are innovating their way out of the talent crisis

09 February 2023
EXECUTIVE SUMMARY: Companies are desperate for cyber security professionals. The cyber threat landscape has shifted, and the risks to organizations’ critical business processes, systems and data are increasing. The future is perhaps more foreboding than ever before. Remaining agile and defeating aggressive attacks without sufficient personnel often feels futile. How can your organization attract and […] The post How three Fortune 500 firms are innovating their way out of the talent crisis appeared first on CyberTalk.

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

09 February 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on February 2 added two security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The first of the two vulnerabilities is CVE-2022-21587 (CVSS score: 9.8), a critical issue impacting versions 12.2.3 to 12.2.11 of the Oracle Web Applications Desktop Integrator product. "Oracle

New High-Severity Vulnerabilities Discovered in Cisco IOx and F5 BIG-IP Products

09 February 2023
F5 has warned of a high-severity flaw impacting BIG-IP appliances that could lead to denial-of-service (DoS) or arbitrary code execution. The issue is rooted in the iControl Simple Object Access Protocol (SOAP) interface and affects the following versions of BIG-IP - 13.1.5 14.1.4.6 - 14.1.5 15.1.5.1 - 15.1.8 16.1.2.2 - 16.1.3, and 17.0.0 "A format string vulnerability exists in iControl SOAP

Atlassian's Jira Software Found Vulnerable to Critical Authentication Vulnerability

09 February 2023
Atlassian has released fixes to resolve a critical security flaw in Jira Service Management Server and Data Center that could be abused by an attacker to pass off as another user and gain unauthorized access to susceptible instances. The vulnerability is tracked as CVE-2023-22501 (CVSS score: 9.4) and has been described as a case of broken authentication with low attack complexity. "An

New High-Severity Vulnerabilities Discovered in F5 BIG-IP Products

09 February 2023
F5 has warned of a high-severity flaw impacting BIG-IP appliances that could lead to denial-of-service (DoS) or arbitrary code execution. The issue is rooted in the iControl Simple Object Access Protocol (SOAP) interface.

Radiant Logic acquires Brainwave GRC to strengthen security posture for customers

09 February 2023
The acquisition will strengthen both Radiant Logic and Brainwave GRC’s respective market positions as identity, analytics, and intelligence experts by offering a new data-centric governance capability and identity data intelligence platform.

Supply Chain Attack by New Malicious Python Package, “web3-essential”

09 February 2023
It was discovered on January 30, 2023, by monitoring an open-source ecosystem. The package was published on January 26, 2023, the same day as its author, ‘Trexon’, joined the repository.