Latest Cybersecurity News and Articles


Azure API Management Vulnerabilities Allowed Unauthorized Access

05 May 2023
Three security vulnerabilities in the Azure API Management service could be exploited to perform various types of malicious actions, cloud security company Ermetic reveals.

New Android Malware 'FluHorse' Targeting East Asian Markets with Deceptive Tactics

05 May 2023
Various sectors in East Asian markets have been subjected to a new email phishing campaign that distributes a previously undocumented strain of Android malware called FluHorse that abuses the Flutter software development framework.

Will the EU’s new cyber security law change the game?

05 May 2023
Peter Sandkuijl, a resident of The Netherlands, is a senior security specialist who has operated in the security market for over 25 years. He started his career at a local Check Point distributor, where he served as a technical product manager. In 2000, Check Point started a Benelux office, where Sandkuijl started as the Technical […] The post Will the EU’s new cyber security law change the game? appeared first on CyberTalk.

City of Dallas recovers after recent ransomware attack

05 May 2023
City of Dallas residents are still dealing with some delays and disruptions following a Wednesday ransomware attack which affected some city websites and services.

Fortinet Patches High-Severity Vulnerabilities in FortiADC, FortiOS

05 May 2023
Fortinet this week announced its monthly set of security updates that address nine vulnerabilities in multiple products, including two high-severity bugs in FortiADC, FortiOS, and FortiProxy.

Hackers Targeting Italian Corporate Banking Clients with New Web-Inject Toolkit DrIBAN

05 May 2023
Italian corporate banking clients are the target of an ongoing financial fraud campaign that has been leveraging a new web-inject toolkit called drIBAN since at least 2019.

Vulnerability Could Have Been Exploited for ‘Unlimited’ Free Credit on OpenAI Accounts

05 May 2023
A vulnerability in OpenAI’s account validation process allowed anyone to obtain virtually unlimited free credit for the company’s services by registering new accounts using the same phone number, application security firm Checkmarx says.

Ex-Uber CSO Joe Sullivan gets probation for breach cover-up

05 May 2023
Joe Sullivan won't serve any serious time behind bars for his role in covering up Uber's 2016 computer security breach and trying to pass off a ransom payment as a bug bounty.

New Android Malware 'FluHorse' Targeting East Asian Markets with Deceptive Tactics

05 May 2023
Various sectors in East Asian markets have been subjected to a new email phishing campaign that distributes a previously undocumented strain of Android malware called FluHorse that abuses the Flutter software development framework. "The malware features several malicious Android applications that mimic legitimate applications, most of which have more than 1,000,000 installs," Check Point said in

Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor

05 May 2023
The latest Android updates patch more than 40 security vulnerabilities in the Framework, System, Kernel, Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components.

Critical Siemens RTU Vulnerability Could Allow Hackers to Destabilize Power Grid

05 May 2023
The vulnerability, tracked as CVE-2023-28489, impacts the CPCI85 firmware of Sicam A8000 CP-8031 and CP-8050 products, and it can be exploited by an unauthenticated attacker for remote code execution.

Organizations urged to incorporate FCC covered list into risk management plans

05 May 2023
CISA has issued an alert to remind critical infrastructure owners to take steps in securing the nation’s critical supply chains.

ScarCruft Deploys RokRAT via LNK File

05 May 2023
ScarCruft, a North Korean threat group, has been attempting to deliver the RokRAT malware since July 2022 using oversized LNK files. The malware is capable of targeting macOS (CloudMensis) and Android (RambleOn). The malware variants are equipped to carry out a range of activities such as credential theft, data exfiltration, command and shellcode execution, file and directory management, and more.

Earth Longzhi Returns, Targets New Regions Using New Tactics

05 May 2023
After more than six months of no activity, Chinese state-sponsored threat group Earth Longzhi is back with new tricks up its sleeves in a new series of attacks. The attackers aim at IIS and Microsoft Exchange servers exposed to the internet to get access to the networks to install the Behinder web shell. Protection against such threats demands a proactive defense strategy.

Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign

05 May 2023
SentinelLabs has observed ongoing attacks from Kimsuky, a North Korean state-sponsored APT that has a long history of targeting organizations across Asia, North America, and Europe.

Critical RCE vulnerability in Cisco phone adapters, no update available

05 May 2023
“This vulnerability is due to a missing authentication process within the firmware upgrade function. An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware,” Cisco’s security advisory explains.

Hackers Targeting Italian Corporate Banking Clients with New Web-Inject Toolkit DrIBAN

05 May 2023
Italian corporate banking clients are the target of an ongoing financial fraud campaign that has been leveraging a new web-inject toolkit called drIBAN since at least 2019. "The main goal of drIBAN fraud operations is to infect Windows workstations inside corporate environments trying to alter legitimate banking transfers performed by the victims by changing the beneficiary and transferring

New Fleckpe Android Malware Installed 600,000 Times on Google Play Store

05 May 2023
Kaspersky reveals that Fleckpe is the newest addition to the realm of malware that generates unauthorized charges by subscribing users to premium services, joining the ranks of other malicious Android malware, such as Jocker and Harly.

Sourcepass Raises Additional $65M in Funding

05 May 2023
The company intends to use the funds to support its strategic objectives, including acquiring Proxios, which expands its physical presence in the mid-Atlantic states, while broadening its client base in the healthcare, legal, and non-profit sectors.

Discord leaks ‘demoralizing’ for US intelligence agencies, DNI Haines says

05 May 2023
The leaks of classified documents online by a Massachusetts Air National Guard member have had an emotional impact on the government agencies that produce those products, the director of national intelligence told Congress on Thursday.