Latest Cybersecurity News and Articles


Hong Kong police and Interpol uncover servers used by global phishing syndicate

09 February 2023
Bogus apps impersonated banks, media players, and others to steal data from victims’ smartphones. Registered subscribers for servers were individuals in mainland China, the Philippines, and Cambodia.

Medusa Botnet Returns as Mirai-Based Variant With Ransomware Module

09 February 2023
Medusa is an old malware strain (not to be confused with the same-name Android trojan) being advertised in darknet markets since 2015, which later added HTTP-based DDoS capabilities in 2017.

Crypto Drainer Scam Lures Unwitting Users into Giving Away their Funds

09 February 2023
Threat actors are providing pre-made, counterfeit cryptocurrency webpages that are being used as phishing baits under a malicious campaign dubbed Crypto Drainer to steal assets from wallets. These phishing pages purport to mint non-fungible tokens (NFTs) and use third-party services and applications that are common in the crypto sphere. Investors are recommended to practice caution and refrain from clicking unsafe or unsecured links.

Ukrainian State Authorities Targeted Through Remcos Software-Fueled Cyberattacks

09 February 2023
The mass phishing campaign has been attributed to a threat actor that CERT-UA tracks as UAC-0050, with the agency describing the activity as likely motivated by espionage given the toolset employed.

GoAnywhere MFT Zero-Day Exploited in the Wild; Patch and Exploit Out

09 February 2023
A security researcher from Code White issued a POC exploit code against vulnerable GoAnywhere MFT servers. The exploitation of the bug allows an attacker to perform unauthenticated RCE on compromised systems. The administrative console of the application is needed for this exploit's attack vector. A patch has been made available for the same.

Qakbot Mechanizes Distribution of Malicious OneNote Documents

09 February 2023
Qakbot began using OneNote .one documents (also called “Notebooks” by Microsoft) in their attacks on January 31. On Tuesday, Sophos researchers observed two parallel spam campaigns.

Ireland's Munster Technological University Forced to Cancel All Classes Due to Cyberattack

09 February 2023
The Munster Technological University (MTU) in Ireland announced on Monday that its campuses in Cork would be closed following a “significant IT breach and telephone outage.” A number of learning tools, including Canvas, are reportedly affected.

Sydney Man Sentenced for Blackmailing Optus Customers After Data Breach

09 February 2023
A Sydney man has been sentenced to an 18-month Community Correction Order (CCO) and 100 hours of community service for attempting to take advantage of the Optus data breach last year to blackmail its customers. The unnamed individual, 19 when arrested in October 2022 and now 20, used the leaked records stolen from the security lapse to orchestrate an SMS-based extortion scheme. The suspect

Unpatched Security Flaws Disclosed in Multiple Document Management Systems

09 February 2023
Multiple unpatched security flaws have been disclosed in open source and freemium Document Management System (DMS) offerings from four vendors LogicalDOC, Mayan, ONLYOFFICE, and OpenKM. Cybersecurity firm Rapid7 said the eight vulnerabilities offer a mechanism through which "an attacker can convince a human operator to save a malicious document on the platform and, once the document is indexed

93% of survey respondents currently have data on more than one cloud

09 February 2023
A report by Valtix found that 95% of companies are moving to a multi-cloud environment with 93% of respondents having data on more than one cloud. 

Smart badges use grows globally

09 February 2023
The smart badges market has been projected to reach a value of $50 billion in the next 10 years due to increasing demand for better access control.

UK Politician's Email Hacked by Suspected Russian Threat Actors

09 February 2023
The victim has worked with Parliament’s security team and the National Cyber Security Centre (NCSC) to ensure that all his inboxes are secure. In addition, he confirmed he is no longer actively using the compromised private account.

Money Lover for Android & iOS Leaked Email Addresses, Transactions

09 February 2023
Money Lover allows users to create "shared wallets" with specific users to collaborate in expense logging and monitoring. Transaction data and email addresses associated with shared wallets were found exposed to any authenticated users of the app.

NIST Standardizes Ascon Cryptographic Algorithm for IoT and Other Lightweight Devices

09 February 2023
The U.S. National Institute of Standards and Technology (NIST) has announced that a family of authenticated encryption and hashing algorithms known as Ascon will be standardized for lightweight cryptography applications. "The chosen algorithms are designed to protect information created and transmitted by the Internet of Things (IoT), including its myriad tiny sensors and actuators," NIST said.

How to choose a cyber security ETF (2023)

09 February 2023
EXECUTIVE SUMMARY: People and technology are more interconnected than ever before, and with that, we’ve seen an acute need for cyber security. Data breaches have reached unprecedented levels and seem to have no end in sight. Private business data, employee data, and consumer data are now scattered about the dark web; for sale or liable […] The post How to choose a cyber security ETF (2023) appeared first on CyberTalk.

6 examples of email phishing scams (& how to identify them)

09 February 2023
By George Mack, Content Marketing Manager, Check Point. Did you know that 91% of all cyber attacks begin with a phishing email? Email phishing scams are becoming increasingly common, and for good reason. Phishing emails manipulate our emotions by using techniques such as urgency, fear, and anxiety. Humans can fall for these deceitful tricks, but […] The post 6 examples of email phishing scams (& how to identify them) appeared first on CyberTalk.

Why the cybersecurity talent gap exists and how to solve it

09 February 2023
What is causing the cybersecurity talent shortage, and what can be done to mitigate it? 

SonicWall Warns Web Content Filtering is Broken on Windows 11 22H2

09 February 2023
An inconsistency was identified in Capture Client Windows 3.7.6 and older clients on endpoints running Windows 11 version 22H2. This results in Web Content Filtering policies that enforce blocked categories to be no longer effective on endpoints.