Latest Cybersecurity News and Articles


Decoy Dog: An Enterprise-targeting Malware Toolkit

25 April 2023
Decoy Dog, a new enterprise-targeting malware toolkit, is using DNS query dribbling and strategic domain aging techniques to bypass security checks and target enterprises. Researchers have shared IOCs on its public GitHub repository which can be helpful for security teams.

Fakecalls Gets Sneakier, Abuses Stolen App Keys

25 April 2023
Fakecalls banking trojan has been targeting South Korean organizations via fake apps; this time it is abusing legitimate app signing keys to bypass signature-based detection techniques. To avoid detection, the malware uses a packer to encrypt its source code. Stay safe by downloading apps from the official stores and reliable sources only.

10 new and dangerous malware threats to watch out for (2023 edition)

25 April 2023
EXECUTIVE SUMMARY: Discover 10 of the most dangerous malware threats and learn how to identify, prevent and defend against attacks. Malware-based attacks pose a significant risk to 80% of small-to-medium sized businesses, while larger organizations are becoming increasingly vulnerable to dangerous and damaging incidents. Stay informed in order to safeguard your organization. Types of malware […] The post 10 new and dangerous malware threats to watch out for (2023 edition) appeared first on CyberTalk.

Insecure Default Configuration in Apache Superset Leads to Remote Code Execution

25 April 2023
Researchers found that a majority of internet-exposed instances of Apache Superset – at least 2000 (two-thirds of all servers) – are running with a dangerous default configuration. This means many of these servers are effectively open to the public.

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

25 April 2023
The top 10 countries with the most organizations having vulnerable SLP instances are the U.S., the U.K., Japan, Germany, Canada, France, Italy, Brazil, the Netherlands, and Spain.

Security leaders weigh in on CommScope breach

25 April 2023
Last week hackers published data stolen from CommScope through a ransomware attack. Among the stolen data was employee’s Social Security numbers and bank account details.

Iranian Hackers Launch Sophisticated Attacks Targeting Israel with PowerLess Backdoor

25 April 2023
The attack chain documented by Check Point begins with an ISO disk image file that makes use of Iraq-themed lures to drop a custom in-memory downloader that ultimately launches the PowerLess implant.

Organizations are stepping up their game against cyber threats

25 April 2023
Global median dwell time drops to just over two weeks, reflecting the essential role partnerships and the exchange of information play in building a more resilient cybersecurity ecosystem, according to Mandiant.

TP-Link Archer WiFi router flaw exploited by Mirai malware

25 April 2023
The Mirai malware botnet is actively exploiting a TP-Link Archer A21 (AX1800) WiFi router vulnerability tracked as CVE-2023-1389 to incorporate devices into DDoS (distributed denial of service) swarms.

The U.S., U.K. and Germany rank top in ransomware attacks

25 April 2023
Cyberattacks have increased over the past few years. Ransomware attacks from April 2022 to March 2023 were analyzed in a recent report by Black Kite.

Adult content malvertising scheme leads to clickjacking

25 April 2023
Visitors are lured to several fake blogs about topics they might find interesting. The original blog, however, is hidden by an overlay showing blurred explicit content and a button asking the visitor to confirm they are 18+ to enter the website.

VirusTotal now has an AI-powered malware analysis feature

25 April 2023
VirusTotal Code Insight analyzes potentially harmful files to explain their (malicious) behavior, and it will improve the ability to identify which of them pose actual threats.

Peugeot Leaks Access to User Information, Application Secrets in South America

25 April 2023
Peugeot has leaked access to its user data in Peru. On February 3rd, the Cybernews research team discovered an exposed environment file (.env) hosted on the official Peugeot store for Peru.

AI tools help attackers develop sophisticated phishing campaigns

25 April 2023
Phishing scams are a growing threat, and cybercriminals’ methods are becoming increasingly sophisticated, making them harder to detect and block, according to a Zscaler report.

50 percent of organizations fell victim to ransomware in 2022

25 April 2023
New research revealed a large disconnect between an organizations’ level of preparedness and their ability to stop a ransomware attack.

New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks

25 April 2023
Details have emerged about a high-severity security vulnerability impacting Service Location Protocol (SLP) that could be weaponized to launch volumetric denial-of-service attacks against targets. "Attackers exploiting this vulnerability could leverage vulnerable instances to launch massive Denial-of-Service (DoS) amplification attacks with a factor as high as 2200 times, potentially making it

Iranian Hackers Launch Sophisticated Attacks Targeting Israel with Powerless Backdoor

25 April 2023
An Iranian nation-state threat actor has been linked to a new wave of phishing attacks targeting Israel that's designed to deploy an updated version of a backdoor called PowerLess. Cybersecurity firm Check Point is tracking the activity cluster under its mythical creature handle Educated Manticore, which exhibits "strong overlaps" with a hacking crew known as APT35, Charming Kitten, Cobalt

Scammers Impersonate Meta in Credential Harvesting Campaign With 3200 Fake Profiles

25 April 2023
According to experts, the ultimate goal of this campaign is to gain access to the Facebook accounts of public figures, celebrities, businesses, and sports teams, among others, to steal sensitive information and use it to access additional accounts.

To combat cybercrime, US law enforcement increasingly prioritizes disruption

25 April 2023
Rather than carrying out traditional investigations aimed at building cases, arresting suspects, convicting them, and sending them to jail, U.S. law enforcement is increasingly focused on disrupting online crime.

55% say cyber/IT assessment is as hard as renewing driver’s license

25 April 2023
Of the biggest challenges faced when implementing an effective cyber/IT risk management program, 49% of respondents say an increase in the quantity of cyber threats.