Latest Cybersecurity News and Articles
10 May 2023
Pakistani cyberespionage group, SideCopy APT, was found targeting employees at India’s Defence Research and Development Organization (DRDO), to pilfer confidential military secrets. Instead of using CACTUSTORCH to deploy code obfuscated via JavaScript and VBScript, SideCopy's latest campaign appears to have utilized SILENTTRINITY,
10 May 2023
Microsoft has rolled out Patch Tuesday updates for May 2023 to address 38 security flaws, including one zero-day bug that it said is being actively exploited in the wild.
Trend Micro's Zero Day Initiative (ZDI) said the volume is the lowest since August 2021, although it pointed out that "this number is expected to rise in the coming months."
Of the 38 vulnerabilities, six are rated Critical and
09 May 2023
Microsoft today released software updates to fix at least four dozen security holes in its Windows operating systems and other software, including patches for two zero-day vulnerabilities that are already being exploited in active attacks.
09 May 2023
EXECUTIVE SUMMARY: Social engineering is one of the most significant and difficult network security challenges to contend with. Due to the discrete nature of social engineering, attacks can occur without anyone in your organization recognizing that anything deceitful has occurred at all. Employees still fall for social engineering scams on a regular basis. This endangers […]
The post Are your employees missing these social engineering red flags? appeared first on CyberTalk.
09 May 2023
U.S. authorities have announced the seizure of 13 internet domains that offered DDoS-for-hire services to other criminal actors.
The takedown is part of an ongoing international initiative dubbed Operation PowerOFF that's aimed at dismantling criminal DDoS-for-hire infrastructures worldwide.
The development comes almost five months after a "sweep" in December 2022 dismantled 48 similar services
09 May 2023
The city continues to recover and restore access to its computer-assisted dispatch system. The city’s municipal court system remains offline, and court hearings and trials have been suspended since Wednesday.
09 May 2023
Over 62% of global CISOs are concerned about being held personally liable for successful cyberattacks that occur on their watch, and a similar share would not join organizations that fail to offer insurance to protect them, according to Proofpoint.
09 May 2023
Pete has 32 years of Security, Network, and MSSP experience and has been a hands-on CISO for the last 17 years and joined Check Point as Field CISO of the Americas. Pete’s cloud security deployments and designs have been rated by Garter as #1 and #2 in the world and he literally “wrote the book” […]
The post Unconsidered benefits of a consolidation strategy every CISO should know appeared first on CyberTalk.
09 May 2023
Lawmakers in Washington and in statehouses around the country are seeking to compel tech companies to prove the age of their users, part of a growing national effort to better protect young children from the harms of the internet.
09 May 2023
A new SolarWinds report details how foreign hackers have become the largest concern among government entities, and how zero-trust strategies have become the most popular defense.
09 May 2023
The Biden-Harris Administration has announced plans to encourage safe artificial intelligence (AI) development to improve national security.
09 May 2023
A public exploit targeting building automation systems has brought KNX security back into the spotlight, with industrial giant Schneider Electric releasing a security bulletin to warn customers about the potential risks.
09 May 2023
The FTC proposed to change a 2020 privacy order with Meta after the FTC alleges that the company has failed to fully comply with the order.
09 May 2023
"These attacks use a specific tactic: targeting the victim companies' support agents via chat applications – in particular, the Comm100 and LiveHelp100 apps," ESET said in a report shared with The Hacker News.
09 May 2023
The U.S. Federal Bureau of Investigation (FBI) this week seized 13 domain names connected to “booter” services that let paying customers launch crippling distributed denial-of-service (DDoS) attacks. Ten of the domains are reincarnations of DDoS-for-hire services the FBI seized in December 2022, when it charged six U.S. men with computer crimes for allegedly operating booters.
09 May 2023
A guide for Chief Information Security Officers (CISOs) was released to manage risks associated with generative AI being used in the workplace.
09 May 2023
A gambling company in the Philippines was the target of a China-aligned threat actor as part of a campaign that has been ongoing since October 2021.
Slovak cybersecurity firm ESET is tracking the series of attacks against Southeast Asian gambling companies under the name Operation ChattyGoblin.
"These attacks use a specific tactic: targeting the victim companies' support agents via chat
09 May 2023
"In this campaign, the SideWinder advanced persistent threat (APT) group used a server-based polymorphism technique to deliver the next stage payload," the BlackBerry Research and Intelligence Team said in a technical report published Monday.
09 May 2023
In the fast-paced cybersecurity landscape, product security takes center stage. DevSecOps swoops in, seamlessly merging security practices into DevOps, empowering teams to tackle challenges. Let's dive into DevSecOps and explore how collaboration can give your team the edge to fight cyber villains.
Application security and product security
Regrettably, application security teams often intervene
09 May 2023
The LockBit 3.0 ransomware group on Monday leaked 600 gigabytes of critical data stolen from Indian lender Fullerton India, two weeks after the group demanded a $3 million ransom from the company.