Latest Cybersecurity News and Articles
28 April 2023
TrendMicro uncovered a new risk to Docker containers from a piece of malware called TrafficStealer. It influences web traffic and ad interaction via the use of containers to generate illegal income. TrafficStealer uses a combination of two techniques: web crawling and click simulation. Experts recommend implementing zero-trust security for all container environments and auditing for any unwanted open container APIs.
28 April 2023
The potential of generative AI in cybersecurity tooling has sparked excitement among cybersecurity professionals. However, there are concerns about the practical usage of AI in cybersecurity and the reliability of training data used in AI models.
28 April 2023
The websites of major Israeli news outlet Maariv, sister publication of The Jerusalem Post, were taken offline on Wednesday. The Anonymous Sudan group also managed to take down the website of the Israel Ports Authority and the Meretz political party.
28 April 2023
Patrik Honegger has worked in the IT sector since the 1990’s and has specialized in the IT security field since 2000. He joined Check Point in 2001. Since joining Check Point, he has been involved with the full array of company solutions and customer sectors and maintains a deep technological understanding of products and customers’ […]
The post Ransomware: Current state or already too late? appeared first on CyberTalk.
28 April 2023
The latest cyberattack techniques highlighted by a range of experts during the RSA 2023 Conference include SEO-based attacks, targeting of developers, malicious use of ChatGPT, and more.
28 April 2023
A school in Wiltshire was hit by a ransomware attack last weekend. Hardenhuish School, a mixed secondary academy in Chippenham, sent texts to parents and guardians of its 1,623 pupils notifying them of the attack.
28 April 2023
A ransomware attack has been reported in Spartanburg County. WYFF News 4 reached out to Spartanburg County officials and the South Carolina Judicial Branch after hearing about a possible computer issue.
28 April 2023
The DHS announced an artificial intelligence task force designed to use the technology to address emerging threats to national security.
28 April 2023
Taiwanese network equipment manufacturer Zyxel this week announced patches for a critical-severity vulnerability impacting its ATP, USG FLEX, VPN, and ZyWALL/USG firewalls.
28 April 2023
A senior Department of Homeland Security official confirmed Wednesday that DHS is working with Congress and the White House on a bill that would codify the Cyber Safety Review Board (CSRB) — a new effort to examine major cybersecurity incidents.
28 April 2023
The latest iteration, as observed by Malwarebytes on a Parisian travel accessory store running on the PrestaShop CMS, involved the injection of a skimmer called Kritec to intercept the checkout process and display a fake payment dialog to victims.
28 April 2023
A 36-year-old Ukrainian citizen was arrested this week for allegedly selling the personal data of over 300 million people to Russia, the Ukrainian cyber police said in a statement.
28 April 2023
Unit 42 discovered a new version of the PingPull malware, designed by Alloy Taurus (aka Gallium), to cripple Linux systems. It is essentially an ELF file that only 3 out of 62 antivirus vendors flagged as malicious. During the investigation, the threat actor's infrastructure also blurted out the evidence of another backdoor used in the attack known as Sword2033.
28 April 2023
A report released this week reveals manufacturing as the top targeted industry for ransomware attacks.
28 April 2023
Threat actors are advertising a new information stealer for the Apple macOS operating system called Atomic macOS Stealer (or AMOS) on Telegram for $1,000 per month, joining the likes of MacStealer.
"The Atomic macOS Stealer can steal various types of information from the victim's machine, including Keychain passwords, complete system information, files from the desktop and documents folder, and
28 April 2023
Russian hackers are attempting to inject ransomware into Ukraine's logistics supply chain and those of the Western countries that back Kyiv in its fight against Moscow, a senior National Security Agency official said on Wednesday.
28 April 2023
Stopping new and evasive threats is one of the greatest challenges in cybersecurity. This is among the biggest reasons why attacks increased dramatically in the past year yet again, despite the estimated $172 billion spent on global cybersecurity in 2022.
Armed with cloud-based tools and backed by sophisticated affiliate networks, threat actors can develop new and evasive malware more quickly
28 April 2023
Networking equipment maker Zyxel has released patches for a critical security flaw in its firewall devices that could be exploited to achieve remote code execution on affected systems.
The issue, tracked as CVE-2023-28771, is rated 9.8 on the CVSS scoring system. Researchers from TRAPA Security have been credited with reporting the flaw.
"Improper error message handling in some firewall versions
28 April 2023
Hackers have stolen email addresses, direct messages, and other personal data from users of two dating websites, according to Troy Hunt, the founder and maintainer of Have I Been Pwned.
28 April 2023
A significant number of victims in the consumer and enterprise sectors located across Australia, Japan, the U.S., and India have been affected by an evasive information-stealing malware called ViperSoftX.
ViperSoftX was first documented in 2020, with cybersecurity company Avast detailing a campaign in November 2022 that leveraged the malware to distribute a malicious Google Chrome extension