Latest Cybersecurity News and Articles


Update: UK pension funds warned to check on clients’ data after Capita breach

01 May 2023
Capita, the country’s largest outsourcing company, holds contracts to administer the payment systems for pension funds used by more than 4 million individuals in Britain.

Nashua School District hit by 'sophisticated' cyberattack

01 May 2023
"We are working diligently to investigate the incident, confirm its impact on our systems, and securely restore functionality to our environment as soon as possible," the district said in a statement.

DeFi Protocol 0VIX Loses Nearly $2M in Flash-Loan Exploit

01 May 2023
A total of 1.45 million USDC, along with other tokens, was stolen before being bridged to the Ethereum mainnet on Stargate Finance, where it was eventually swapped for ether (ETH).

Microsoft’s next-level nomenclature, naming hacking groups

01 May 2023
EXECUTIVE SUMMARY: Last week, Microsoft’s cyber security division announced that it is changing its taxonomy for naming hacking groups. Previously, Microsoft assigned cyber criminal organizations the names of chemical elements, as listed in the periodic table. In the new system, Microsoft will assign hacker groups two-word names, including a weather-based descriptor. The new names The […] The post Microsoft’s next-level nomenclature, naming hacking groups appeared first on CyberTalk.

Google Blocks 1.43 Million Malicious Apps, Bans 173,000 Bad Accounts in 2022

01 May 2023
In addition, the company said it banned 173,000 bad accounts and fended off over $2 billion in fraudulent and abusive transactions through developer-facing features like Voided Purchases API, Obfuscated Account ID, and Play Integrity API.

Court Records Expose Private Information for Thousands of Missouri Residents

01 May 2023
Documents containing Social Security numbers and other private information for thousands of Missourians are accessible to anyone using the Casenet website, the state’s judicial records system, the Post-Dispatch recently discovered.

Sensitive Data Leaked From Servers Running Salesforce Community Software

01 May 2023
Servers running software sold by Salesforce are leaking sensitive data managed by government agencies, banks, and other organizations, according to a post published Friday by KrebsOnSecurity.

Using multiple solutions adds complexity to your zero trust strategy

01 May 2023
Companies are also now increasingly reliant on their supply chain, which means partners, suppliers, and shippers are now typically directly connected to a company’s systems.

Update: Hackers leak images to taunt Western Digital's cyberattack response

01 May 2023
The ALPHV ransomware crew, aka BlackCat, has published screenshots of internal emails and video conferences stolen from Western Digital, indicating they likely had continued access to the company's systems even as the company responded to the breach.

Cybercriminals use proxies to legitimize fraudulent requests

01 May 2023
Bot attacks were previously seen as a relatively inconsequential type of online fraud, and that mentality has persisted even as threat actors have gained the ability to cause significant damage to revenue and brand reputation, according to HUMAN.

Report shows nearly 600% annual growth in vulnerable cloud attack surface

01 May 2023
A new report reveals security organizations experienced 133% year-over-year growth in cyber assets, resulting in increased security complexity for cloud enterprises.

‘BouldSpy’ Android Malware Used in Iranian Government Surveillance Operations

01 May 2023
On the infected devices, BouldSpy harvests account usernames and associated application/service, a list of installed apps, browser data, call logs, clipboard content, contact lists, device information, a list of files and folders, and SMS messages.

New Decoy Dog Malware Toolkit Uncovered: Targeting Enterprise Networks

01 May 2023
An analysis of over 70 billion DNS records has led to the discovery of a new sophisticated malware toolkit dubbed Decoy Dog targeting enterprise networks. Decoy Dog, as the name implies, is evasive and employs techniques like strategic domain aging and DNS query dribbling, wherein a series of queries are transmitted to the command-and-control (C2) domains so as to not arouse any suspicion. "

Companies Increasingly Hit With Data Breach Lawsuits: Law Firm

01 May 2023
Lawsuits filed against companies that have suffered a data breach are increasingly common, with action being taken more frequently even in cases where the number of impacted individuals is smaller, according to US law firm BakerHostetler.

Russia-linked APT28 Uses Fake Windows Update Instructions to Target Ukrainian Government Bodies

01 May 2023
CERT-UA observed the campaign in April 2023, the malicious e-mails with the subject “Windows Update” were crafted to appear as sent by system administrators of departments of multiple government bodies.

United HealthCare Reports Data Breach That May Have Revealed Customer's Personal Information

01 May 2023
United HealthCare made customers aware of a data breach on Friday, which temporarily allowed access to personal information for those enrolled in the company's healthcare plans.

South Korea, US agree to cooperate on cybersecurity and combating North Korean digital heists

01 May 2023
North Korea has long relied on its government-backed hacking groups to fund its weapons programs, launching audacious attacks on cryptocurrency exchanges and medical facilities.

Wanted Dead or Alive: Real-Time Protection Against Lateral Movement

01 May 2023
Just a few short years ago, lateral movement was a tactic confined to top APT cybercrime organizations and nation-state operators. Today, however, it has become a commoditized tool, well within the skillset of any ransomware threat actor. This makes real-time detection and prevention of lateral movement a necessity to organizations of all sizes and across all industries. But the disturbing truth

Are Qualcomm chips snooping on you? No, not quite

01 May 2023
Recently, security firm Nitrokey published an advisory claiming that "smartphones with Qualcomm chips secretly send personal data to Qualcomm" and do so "without user consent, unencrypted, and even when using a Google-free Android distribution."

Some 'Sensitive Information' Potentially Compromised: Diocese of Las Vegas Reports Cybersecurity Breach

01 May 2023
In response to the breach, the Diocese states it has "reviewed and enhanced its data security policies...in order to help reduce the likelihood of a similar event in the future."