Latest Cybersecurity News and Articles
09 May 2023
Experts at Cleafy disclosed nearly a four-year-long online fraud campaign that infected Windows systems in organizations using drIBAN, a web inject kit. Criminals attempted to alter legitimate banking transfers by changing the beneficiary details and redirecting the funds to their accounts. Organizations are suggested to be well aware of the evolving threats and make continuous efforts to enhance their security posture.
09 May 2023
"Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem," Alex Matrosov, founder and CEO of firmware security firm Binarly, said in a tweet over the weekend.
09 May 2023
The idea with E2E encryption is that data is kept confidential between the encryptor and the intended receiver. This might seem an obvious requirement, but not all so-called secure systems offer this level of protection.
09 May 2023
A newly discovered malware named KEKW has been found to be distributed through malicious open-source Python .whl (Wheel) files. This malware combines infostealers with clipper activities, allowing it to steal sensitive information from compromised systems and hijack cryptocurrency transactions.
09 May 2023
In such attacks (also known as push bombing or MFA push spam), cybercriminals flood the targets with mobile push notifications asking them to approve attempts to log into their corporate accounts using stolen credentials.
09 May 2023
Organizations need to be able to match the ingenuity and resources of cybercriminals to better defend themselves against the increasing number of threats and attacks that could paralyze their business.
09 May 2023
VulCheck developed a new PoC exploit against the critical PaperCut bug earmarked CVE-2023-27350 that is capable of evading all known detection rules. The bug affects PaperCut MF or NG versions 8.0 and above, whose exploitation paves the way for unauthenticated RCE attacks. The bug has previously been exploited in ransomware attacks by Cl0p and LockBit groups.
09 May 2023
The advanced persistent threat (APT) actor known as SideWinder has been accused of deploying a backdoor in attacks directed against Pakistan government organizations as part of a campaign that commenced in late November 2022.
"In this campaign, the SideWinder advanced persistent threat (APT) group used a server-based polymorphism technique to deliver the next stage payload," the BlackBerry
09 May 2023
Iranian nation-state groups have now joined financially motivated actors in actively exploiting a critical flaw in PaperCut print management software, Microsoft said.
The tech giant's threat intelligence team said it observed both Mango Sandstorm (Mercury) and Mint Sandstorm (Phosphorus) weaponizing CVE-2023-27350 in their operations to achieve initial access.
"This activity shows Mint
09 May 2023
This botnet, known as AndoryuBot, first appeared in February 2023. It contains DDoS attack modules for different protocols and communicates with its command-and-control server using SOCKS5 proxies.
09 May 2023
The new rules_oci plugin can use trusted third-party toolchains, does not require running a docker daemon already on the machine, and does not include language-specific rules.
09 May 2023
This week's seizures are part of a coordinated international law enforcement effort (known as Operation PowerOFF) to disrupt online platforms allowing anyone to launch massive DDoS attacks against any target for the right amount of money.
09 May 2023
A new malware known as NodeStealer can extract sensitive information of Facebook users. This malware allows cybercriminals to take over accounts on the platform as well as Gmail and Outlook accounts by stealing browser cookies. Facebook's engineers spotted the NodeStealer malware first in late January and linked the attacks to Vietnamese threat actors.
09 May 2023
Cybersecurity researchers have shed light on a new ransomware strain called CACTUS that has been found to leverage known flaws in VPN appliances to obtain initial access to targeted networks.
"Once inside the network, CACTUS actors attempt to enumerate local and network user accounts in addition to reachable endpoints before creating new user accounts and leveraging custom scripts to automate
08 May 2023
Snake malware and its variants have been a core component in Russian operations carried out by Centre 16 of Russia’s Federal Security Service (FSB).
08 May 2023
EXECUTIVE SUMMARY: A vicious series of cyber attacks has targeted social media accounts belonging to individuals across South Asia. In this alarming set of incidents, hackers attempted to leverage fictitious Facebook and Instagram personas in order to execute espionage attempts, deliver malware and/or to steal information. But we’re still at the beginning of this story… […]
The post Massive cyber espionage operation uncovered in South Asia appeared first on CyberTalk.
08 May 2023
"The PaperCut exploitation activity by Mint Sandstorm appears opportunistic, affecting organizations across sectors and geographies," the Microsoft Threat Intelligence team said.
08 May 2023
This investment is expected to provide HUB Security with additional resources to fuel its rapid growth and development, enhance its financial stability, and enable the company to pursue its future plans.
08 May 2023
Immuta, a Boston, MA-based leader in data security, received a strategic investment from Databricks Ventures, the investment arm of Databricks, a data and AI company and pioneer of the lakehouse. The amount of the deal was not disclosed.
08 May 2023
A recent report by Torii found that 99% of IT professionals say they’re fulfilled in their jobs despite increasing SaaS spend concerns.