Latest Cybersecurity News and Articles


MalVirt Loader Distributes Formbook and XLoader with Unusual Levels of Obfuscation

09 February 2023
Cybercriminals were found distributing virtualized .NET malware loaders, dubbed MalVirt, in a Google Ads-based malvertising campaign to install the Formbook stealer and XLoader. The hackers used KoiVM virtualization technology to obfuscate their implementation and execution in their campaigns. The malware has keylogging, credential stealing, and additional malware loading capabilities.

UK: Quarter of CFOs Have Suffered $1m+ Breaches

09 February 2023
Around a quarter of UK business leaders expect cyber-threats to significantly increase this year, with a similar number of global firms having already suffered costly breaches in the past, according to PwC.

Florida-Based Tallahassee Memorial HealthCare Takes IT Systems Offline After Cyberattack

09 February 2023
In an update provided by the hospital, TMH states that all non-emergency/elective procedures for Monday, February 6 will be canceled and rescheduled. Patients whose appointments were rescheduled will be contacted by their provider or care facility.

CVEs expected to rise in 2023, as organizations still struggle to patch

09 February 2023
The increase is likely because researchers are investing more to uncover vulnerabilities and organizations are also conducting more audits to find flaws in their software inventory.

Hackers Target Switzerland’s Largest University With ‘Professional’ Cyberattack

09 February 2023
The university said on Friday that it is battling to keep the hackers out of critical zones by isolating parts of its IT system. This defense has compromised access to its systems but prevented cyberattackers from encrypting or extracting data.

Inability to prevent bad things from happening seen as the worst part of a security job

09 February 2023
83% of organizations experienced more than one data breach in 2022. However, 97% of respondents feel confident that they are well-equipped with the tools and processes needed to prevent and identify intrusions or breaches, according to Exabeam.

Finland’s Most-Wanted Hacker Nabbed in France

09 February 2023
In late October 2022, Julius “Zeekill” Kivimäki was charged (and “arrested in absentia,” according to the Finns) with attempting to extort money from the Vastaamo Psychotherapy Center.

Mortgage Financial Technologies Company 8Twelve Exposed 717,814 Records Online

09 February 2023
Security researcher Jeremiah Fowler together with the Website Planet research team discovered an open and non-password-protected database that contained 717,814 records and the PII of thousands of Canadian citizens.

Update: 110,000 more users affected in LG Uplus' data breach

09 February 2023
On January 10, the nation's third-largest wireless carrier disclosed that the personal data of 180,000 customers, including their names, birth dates, and phone numbers, had been breached.

Feds Say Cyberattack Caused Suicide Helpline’s Outage

09 February 2023
“On Dec. 1, the voice calling functionality of the 988 Lifeline was rendered unavailable as a result of a cybersecurity incident,” Danielle Bennett, a spokeswoman for the Substance Abuse and Mental Health Services Administration, said in an email.

Top trends for cyber warfare, new report highlights

09 February 2023
EXECUTIVE SUMMARY: In the past decade, the cyber threat landscape has evolved significantly. Just a few short years ago, few businesses had reason to concern themselves with the notion of cyber warfare. However, the boundaries between different cyber threat activities and their meanings have blurred; a cyber attack on a hospital, for example, could be […] The post Top trends for cyber warfare, new report highlights appeared first on CyberTalk.

Linux version of Royal Ransomware targets VMware ESXi servers

09 February 2023
Royal Ransomware is the latest ransomware operation to add support for encrypting Linux devices to its most recent malware variants, specifically targeting VMware ESXi virtual machines.

President Biden appoints Scott Charney as Chair of NSTAC

09 February 2023
President Biden announced the appointees for the National Security Telecommunications Advisory Committee. Scott Charney has been appointed as Chair.

5 mysterious new malware that could burn your business

09 February 2023
EXECUTIVE SUMMARY: IT and security leaders have come to realize that they need to alter the way in which they prepare for tomorrow. The swift evolution of technologies, best practices, threat intelligence and cyber attacks makes staying up on the latest security trends an absolute must. To help you shape your security approach and remain […] The post 5 mysterious new malware that could burn your business appeared first on CyberTalk.

Hackers backdoor Windows devices in Sliver and BYOVD attacks

09 February 2023
A new hacking campaign exploits Sunlogin flaws to deploy the Sliver post-exploitation toolkit and launch Windows Bring Your Own Vulnerable Driver (BYOVD) attacks to disable security software.

OpenSSH Releases Patch for New Pre-Auth Double Free Vulnerability

09 February 2023
"This is not believed to be exploitable, and it occurs in the unprivileged pre-auth process that is subject to chroot(2) and is further sandboxed on most major platforms," OpenSSH disclosed in its release notes on February 2, 2023.

Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping

09 February 2023
A critical vulnerability affecting wireless communication base stations from Baicells Technologies can be exploited to cause disruption in telecom networks or take complete control of data and voice traffic, according to a researcher.

Lazarus Group Exploits Unpatched Zimbra Devices

09 February 2023
WithSecure researchers spotted a new campaign, dubbed No Pineapple, by North Korean Lazarus hackers targeting energy and medical research sectors with the Acres RAT. Lazarus gains access to a flawed Zimbra mail server by abusing RCE flaws tracked as CVE-2022-27925 and CVE-2022-37042.

America’s top cyber diplomat says his Twitter account was hacked

09 February 2023
There did not appear to be any broader fallout from the hacking incident. Nate Fick uses the account sparingly and instead promotes his work through an official State Department account.

Hackers Abuse RCE Vulnerability to Deploy Sliver Backdoor

09 February 2023
Sunlogin security holes are being used by a new hacking effort to launch Windows Bring Your Own Vulnerable Driver (BYOVD) attacks and distribute the Sliver post-exploitation toolkit. The exploitation of the flaw leads to the installation of Gh0st RAT. However, in some cases, hackers installed XMRig CoinMiner instead of Gh0st RAT.