Latest Cybersecurity News and Articles
09 February 2023
Bogus apps impersonated banks, media players, and others to steal data from victims’ smartphones. Registered subscribers for servers were individuals in mainland China, the Philippines, and Cambodia.
09 February 2023
Medusa is an old malware strain (not to be confused with the same-name Android trojan) being advertised in darknet markets since 2015, which later added HTTP-based DDoS capabilities in 2017.
09 February 2023
Threat actors are providing pre-made, counterfeit cryptocurrency webpages that are being used as phishing baits under a malicious campaign dubbed Crypto Drainer to steal assets from wallets. These phishing pages purport to mint non-fungible tokens (NFTs) and use third-party services and applications that are common in the crypto sphere. Investors are recommended to practice caution and refrain from clicking unsafe or unsecured links.
09 February 2023
The mass phishing campaign has been attributed to a threat actor that CERT-UA tracks as UAC-0050, with the agency describing the activity as likely motivated by espionage given the toolset employed.
09 February 2023
A security researcher from Code White issued a POC exploit code against vulnerable GoAnywhere MFT servers. The exploitation of the bug allows an attacker to perform unauthenticated RCE on compromised systems. The administrative console of the application is needed for this exploit's attack vector. A patch has been made available for the same.
09 February 2023
Qakbot began using OneNote .one documents (also called “Notebooks” by Microsoft) in their attacks on January 31. On Tuesday, Sophos researchers observed two parallel spam campaigns.
09 February 2023
The Munster Technological University (MTU) in Ireland announced on Monday that its campuses in Cork would be closed following a “significant IT breach and telephone outage.” A number of learning tools, including Canvas, are reportedly affected.
09 February 2023
A Sydney man has been sentenced to an 18-month Community Correction Order (CCO) and 100 hours of community service for attempting to take advantage of the Optus data breach last year to blackmail its customers.
The unnamed individual, 19 when arrested in October 2022 and now 20, used the leaked records stolen from the security lapse to orchestrate an SMS-based extortion scheme.
The suspect
09 February 2023
Multiple unpatched security flaws have been disclosed in open source and freemium Document Management System (DMS) offerings from four vendors LogicalDOC, Mayan, ONLYOFFICE, and OpenKM.
Cybersecurity firm Rapid7 said the eight vulnerabilities offer a mechanism through which "an attacker can convince a human operator to save a malicious document on the platform and, once the document is indexed
09 February 2023
A report by Valtix found that 95% of companies are moving to a multi-cloud environment with 93% of respondents having data on more than one cloud.
09 February 2023
The smart badges market has been projected to reach a value of $50 billion in the next 10 years due to increasing demand for better access control.
09 February 2023
The victim has worked with Parliament’s security team and the National Cyber Security Centre (NCSC) to ensure that all his inboxes are secure. In addition, he confirmed he is no longer actively using the compromised private account.
09 February 2023
Money Lover allows users to create "shared wallets" with specific users to collaborate in expense logging and monitoring. Transaction data and email addresses associated with shared wallets were found exposed to any authenticated users of the app.
09 February 2023
The U.S. National Institute of Standards and Technology (NIST) has announced that a family of authenticated encryption and hashing algorithms known as Ascon will be standardized for lightweight cryptography applications.
"The chosen algorithms are designed to protect information created and transmitted by the Internet of Things (IoT), including its myriad tiny sensors and actuators," NIST said.
09 February 2023
EXECUTIVE SUMMARY: People and technology are more interconnected than ever before, and with that, we’ve seen an acute need for cyber security. Data breaches have reached unprecedented levels and seem to have no end in sight. Private business data, employee data, and consumer data are now scattered about the dark web; for sale or liable […]
The post How to choose a cyber security ETF (2023) appeared first on CyberTalk.
09 February 2023
By George Mack, Content Marketing Manager, Check Point. Did you know that 91% of all cyber attacks begin with a phishing email? Email phishing scams are becoming increasingly common, and for good reason. Phishing emails manipulate our emotions by using techniques such as urgency, fear, and anxiety. Humans can fall for these deceitful tricks, but […]
The post 6 examples of email phishing scams (& how to identify them) appeared first on CyberTalk.
09 February 2023
What is causing the cybersecurity talent shortage, and what can be done to mitigate it?
09 February 2023
An inconsistency was identified in Capture Client Windows 3.7.6 and older clients on endpoints running Windows 11 version 22H2. This results in Web Content Filtering policies that enforce blocked categories to be no longer effective on endpoints.