Latest Cybersecurity News and Articles
27 April 2023
Today, Microsoft disclosed that the Clop and LockBit ransomware gangs are behind recent attacks on PaperCut servers and using them to steal corporate data from vulnerable servers.
26 April 2023
Google patched a security hole dubbed GhostToken that affects all the users of Google Cloud Platform (GCP). This flaw enables attackers to gain access to user accounts through the installation of malicious OAuth applications obtained from either the Google Marketplace or third-party providers. Criminals can hide malicious apps by abusing this flaw.
26 April 2023
Elastic Security Labs has uncovered LOBSHOT, a previously unknown hVNC malware, that impersonates legitimate software for financial gain and is promoted through malvertising, such as Google Ads, to extend their reach and perpetrate their attacks. It targets 32 Chrome extensions, nine Edge wallet extensions, and 11 Firefox wallet extensions, enabling threat actors to steal cryptocurrency assets.
26 April 2023
Group-IB spotted a new phishing campaign targeting Facebook users, leveraging 3,200 fake profiles, in an attempt to steal account credentials from public figures, businesses, celebs, and others. The profiles were either created by the actors or were genuinely hacked accounts of users. Of these fake profiles, 1,200 were created in March alone. Users are urged to practice digital hygiene.
26 April 2023
The Mirai botnet operators were seen abusing CVE-2023-1389, a vulnerability in the TP-Link Archer A21 (AX1800) WiFi router, and trying to make those devices part of their future DDoS attacks. The initial study of the attack infrastructure revealed targeted devices in the Eastern Europe region, however, the attack campaign could be spreading worldwide. The vulnerability was patched last month by TP-Link.
26 April 2023
To hinder the spread of CryptBot, a federal court has granted Google a temporary restraining order which allows the company to disrupt the distributors and their infrastructure.
26 April 2023
EXECUTIVE SUMMARY: What is user provisioning? User provisioning enables management teams to control access to business resources, strengthening data security by limiting unnecessary access and allowing only authorized personnel to log in. User provisioning technology can assist management teams in enabling access, managing accounts and revoking access as needed. It simplifies the process of handling […]
The post Access management made easy, boosting security with user provisioning appeared first on CyberTalk.
26 April 2023
EXECUTIVE SUMMARY: What is user provisioning? User provisioning enables management teams to control access to business resources, strengthening data security by limiting unnecessary access and allowing only authorized personnel to log in. User provisioning technology can assist management teams in enabling access, managing accounts and revoking access as needed. It simplifies the process of handling […]
The post Access management made easy, boosting security with user provisioning appeared first on CyberTalk.
26 April 2023
For the past eight years, NSB has been used by bot operators to acquire limited edition and hard-to-find items from over 100 online shops. It's considered one of the best scalping bots available on the market, with an annual price of $499.
26 April 2023
Datadog released its 2023 State of Application Security Report analyzing the current vulnerabilities and threats targeting DevOps organizations.
26 April 2023
The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033.
That's according to findings from Palo Alto Networks Unit 42, which discovered recent malicious cyber activity carried out by the group targeting South Africa and Nepal.
Alloy Taurus is the constellation-themed moniker assigned to a
26 April 2023
At the end of March 2023, WithSecure caught FIN7 attacks that exploited internet-facing servers running Veeam Backup & Replication software to execute payloads on the compromised environment.
26 April 2023
A group of teenagers and individuals in their 20s from the U.S. and the U.K are among the most prevalent threat actors today, Mandiant Consulting CTO Charles Carmakal said Monday at an off-site media briefing during the RSA Conference.
26 April 2023
This malware is tailored to suit individual targets and exhibits a higher level of complexity, evidenced by a unique communication approach with its command-and-control (C2) infrastructure.
26 April 2023
Cyberattackers leveraged more than 500 unique tools and tactics in 2022, according to Sophos. The data was analyzed from more than 150 Sophos Incident Response (IR) cases.
26 April 2023
When it comes to preventing theft and fraud, security leaders need to consider how different transaction methods require different security measures.
26 April 2023
The Critical Technology Security Centers Act of 2023 introduced Tuesday by Rep. Ritchie Torres (D-N.Y.) would create two cybersecurity-focused offices to evaluate and test the security of critical technology used by the federal government.
26 April 2023
The prolific Iranian nation-state group known as Charming Kitten targeted multiple victims in the U.S., Europe, the Middle East and India with a novel malware dubbed BellaCiao, adding to its ever-expanding list of custom tools.
Discovered by Bitdefender Labs, BellaCiao is a "personalized dropper" that's capable of delivering other malware payloads onto a victim machine based on commands received
26 April 2023
ESET Research uncovered a campaign by the APT group known as Evasive Panda targeting an international NGO in China with malware delivered through updates of popular Chinese software.
26 April 2023
There has been a significant number of victims in the consumer and enterprise sectors in Australia, Japan, and the U.S. after information-stealer ViperSoftX adopted new anti-detection capabilities. The enterprise sector made up over 40% of the total number of affected victims. The latest version of the info-stealer comes with the capability to steal passwords from two password managers such as KeePass 2 and 1Password.