Latest Cybersecurity News and Articles


Meta Uncovers Massive Social Media Cyber Espionage Operations Across South Asia

04 May 2023
Three different threat actors leveraged hundreds of elaborate fictitious personas on Facebook and Instagram to target individuals located in South Asia as part of disparate attacks. "Each of these APTs relied heavily on social engineering to trick people into clicking on malicious links, downloading malware or sharing personal information across the internet," Guy Rosen, chief information

US Authorities Dismantle Dark Web "Card Checking" Platform

04 May 2023
Try2Check’s websites have now been taken offline and the State Department has issued a $10m reward for information leading to the capture of the man accused of running the platform.

FTC accuses Facebook of violating privacy agreement, proposes ban on profiting off children's data

04 May 2023
The FTC proposed on Wednesday that Facebook be prohibited from profiting off of data it collects from minors, a move that comes in response to alleged violations of the company’s previous agreements with the agency to protect user privacy.

Netgear Vulnerabilities Lead to Credentials Leak, Privilege Escalation

04 May 2023
Vulnerabilities in Netgear’s NMS300 ProSAFE network management system allow attackers to retrieve cleartext credentials and escalate privileges, cybersecurity firm Flashpoint reports.

UK competition watchdog launches review of AI market

04 May 2023
UK competition watchdog launches review of AI market CMA to look at underlying systems of artificial intelligence tools amid concerns over false informationBusiness live – latest updatesThe UK competition watchdog has launched a review of the artificial intelligence market, as it warned of threats from AI tools including the distribution of false or misleading information.In an announcement that comes as global regulators increase scrutiny of the technology, the Competition and Markets Authority said it would look at the underlying systems, or foundation models, behind AI tools such as ChatGPT. Continue reading...

Merck cyber coverage upheld in NotPetya decision, seen as victory for policyholders

04 May 2023
A court victory in the closely watched insurance case is expected to stabilize a turbulent market and provide some assurance for organizations amid a rise in nation-state activity.

Iranian hackers turn to influence operations to amplify cyberattacks

04 May 2023
Iran’s cyber-enabled influence operations, which combine offensive cyberattacks with social media posts and SMS campaigns, mostly target Israel, the U.S., and activists who oppose the Iranian regime, Microsoft said in a report published Tuesday.

Iranian hackers turn to influence operations to amplify cyberattacks

04 May 2023
Iran’s cyber-enabled influence operations, which combine offensive cyberattacks with social media posts and SMS campaigns, mostly target Israel, the U.S., and activists who oppose the Iranian regime, Microsoft said in a report published Tuesday.

The Untold Story of the Boldest Supply-Chain Hack Ever

04 May 2023
The Orion software suite had about 33,000 customers, some of whom had started receiving the hacked software update in March. That meant some customers might have been compromised for eight months already.

Meta Takes Down Malware Campaign That Used ChatGPT as a Lure to Steal Accounts

04 May 2023
Meta said it took steps to take down more than 1,000 malicious URLs from being shared across its services that were found to leverage OpenAI's ChatGPT as a lure to propagate about 10 malware families since March 2023. The development comes against the backdrop of fake ChatGPT web browser extensions being increasingly used to steal users' Facebook account credentials with an aim to run

Researcher hijacks popular Packagist PHP packages to get a job

04 May 2023
A researcher with the pseudonym 'neskafe3v1' reached out to BleepingComputer stating he had taken over fourteen Packagist packages, with one of them having over 500 million installs.

ChatGPT hacking, it’s only just begun…

03 May 2023
EXECUTIVE SUMMARY: Since its November debut on the world stage, the popular AI-powered chatbot, ChatGPT, has continuously attracted cyber criminal attention. Although OpenAI, has developed security measures to prevent product misuse, these measures have not curtailed hacker pursuits. According to Check Point researchers, some cyber criminals are selling tools that enable other cyber criminals to […] The post ChatGPT hacking, it’s only just begun… appeared first on CyberTalk.

KEV Catalog Adds Vulnerabilities Affecting TP-Link, Apache, and Oracle WebLogic Server

03 May 2023
Watch out for bugs in TP-Link, Apache Log4j2, and Oracle WebLogic Server that are under active exploitation by different cybercriminal groups, warns CISA. FCEB agencies are required to apply vendor-provided fixes by May 22, 2023.

Phishing Campaign Targets Romanian Telecom Users

03 May 2023
Heimdal Security's SOC team has discovered an ongoing phishing campaign that seems to be aimed at customers of Romanian telecom providers. The fraudulent page requests the victims to submit their credit card information to cover a tax related to changing a delivery address. Experts recommend avoiding opening suspicious emails or links, and using order tracking features wherever available.

AresLoader Malware Attacking Citrix Users Through Malicious GitLab Repo

03 May 2023
Cyble has recently detected AresLoader, a novel loader that is found to be disseminating numerous malware families. Malware loaders are designed to deploy and execute diverse malware strains on the targeted computer system of the victim.

Promising Jobs at the U.S. Postal Service, ‘US Job Services’ Website Leaks Customer Data

03 May 2023
A sprawling online company based in Georgia that has made tens of millions of dollars purporting to sell access to jobs at the United States Postal Service (USPS) has exposed its internal IT operations and database of nearly 900,000 customers.

Chrome 113 Released With 15 Security Patches

03 May 2023
Released roughly two weeks after Google resolved two zero-day vulnerabilities in the popular browser, the latest Chrome update only resolves medium- and low-severity flaws, despite the major version change.

Most open source maintainers still consider themselves hobbyists, despite compensation pledges

03 May 2023
Despite a major push to strengthen the security of the software supply chain, a report released Tuesday from Tidelift shows more than 60% of open source maintainers describe themselves as unpaid hobbyists.

Murfreesboro Medical Clinic Closed for Multiple Days After Cyberattack

03 May 2023
The criminal cyberattack on April 22 led Murfreesboro Medical Clinic & SurgiCenter to initiate an emergency shutdown of their network to limit the spread of stolen information within their systems.

Gary Starling appointed as CISO at IntelePeer

03 May 2023
IntelePeer recently named Gary Starling as CISO. Starling brings with him more than 20 years of domestic and multi-national IT and information security experience.