Latest Cybersecurity News and Articles
04 May 2023
Google wants to take us further into a passwordless future by allowing personal account holders to login using passkeys rather than using passphrases and multifactor authentication (MFA).
04 May 2023
In an April 28 Attorney General filing, T-Mobile reported it was the victim of a second data breach of 2023, affecting 836 customers.
04 May 2023
The vulnerability, which has now been fixed, was caused by a window message event handler that does not properly validate the message origin, providing attackers access to sensitive user information.
04 May 2023
Meta said it took steps to take down more than 1,000 malicious URLs from being shared across its services that were found to leverage OpenAI's ChatGPT as a lure to propagate about 10 malware families since March 2023.
04 May 2023
The operation, dubbed SpecTor, also included the seizure of 117 firearms, 850 kilograms of drugs — including 64 kilograms of fentanyl or fentanyl-laced narcotics — and $53.4 million in cash and virtual currencies, the DoJ said in a statement.
04 May 2023
Russia-linked APT group Sandworm is behind destructive cyberattacks against Ukrainian state networks, the Ukrainian Government Computer Emergency Response Team (CERT-UA) warns.
04 May 2023
Cybercriminals have been using AT&T-provided email addresses to steal large amounts of cryptocurrency by accessing accounts via mail keys. One victim claimed to have lost $134,000 from its Coinbase account. The firms are suggested to update their security controls to prevent such activities and proactively require a password reset on some email accounts.
04 May 2023
Orqa, a maker of First Person View (FPV) drone racing goggles, claims that a contractor introduced code into its devices' firmware that acted as a time bomb designed to brick them.
04 May 2023
By Antoinette Hodes, a Check Point Global Solutions Architect for the EMEA region and an Evangelist with the Check Point Office of the CTO. The growth of IoT devices is transforming the way we live and work, offering unparalleled efficiency, productivity and interconnectedness. From smart homes to industrial automation, each IoT deployment scenario addresses a […]
The post The future of cellular IoT appeared first on CyberTalk.
04 May 2023
The UK government has announced a new fraud strategy which will focus heavily on mitigating the impact of telephone and online scams, although critics have said it doesn’t go far enough.
04 May 2023
Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive information or backend services.
This includes two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal, according to Israeli cloud security firm Ermetic.
"
04 May 2023
Cybersecurity researchers have found a way to exploit a recently disclosed critical flaw in PaperCut servers in a manner that bypasses all current detections.
Tracked as CVE-2023-27350 (CVSS score: 9.8), the issue affects PaperCut MF and NG installations that could be exploited by an unauthenticated attacker to execute arbitrary code with SYSTEM privileges.
While the flaw was patched by the
04 May 2023
Trend Micro noticed a ransomware variant called Rapture that adopts a minimalistic approach and leaves behind only a small digital footprint. The attackers utilized the commercial packer Themida to pack the ransomware, hence making the analysis challenging. An RSA key configuration file used by the attackers was found to be similar to that used by the Paradise ransomware.
04 May 2023
Hackers have published a trove of sensitive data stolen from payment software company AvidXchange after the company fell victim to ransomware for the second time this year.
04 May 2023
The Kids Online Safety Act, known as KOSA, would place a duty of care on platforms to prevent promoting to users under 17 content that includes harmful behaviors such as eating disorders and suicide.
04 May 2023
Pediatric mental health provider Brightline is warning patients that it suffered a data breach impacting 783,606 people after a ransomware gang stole data using a zero-day vulnerability in its Fortra GoAnywhere MFT secure file-sharing platform.
04 May 2023
The list encompasses a number of communications equipment and service providers that have been determined by the US government to pose a potential national security risk according to the Secure and Trusted Communications Networks Act of 2019.
04 May 2023
Dallas was hit with a computer ransomware attack Wednesday that brought down its Police Department and City Hall websites and caused some jury trials to be canceled, officials said.
04 May 2023
A group of more than 40 media and digital rights organizations are calling on Five Eyes nations and democratic governments around the world to reject efforts to weaken encryption and support a global vision of a free and open internet.
04 May 2023
IT and cybersecurity teams are so inundated with security notifications and alerts within their own systems, it’s difficult to monitor external malicious environments – which only makes them that much more threatening.
In March, a high-profile data breach hit national headlines when personally identifiable information connected to hundreds of lawmakers and staff was leaked on the dark web. The