Latest Cybersecurity News and Articles


EvilExtractor: An Educational Tool or Info-stealer?

25 April 2023
FortiGuard Labs laid bare EvilExtractor - an attack tool developed to target Windows systems and extract data and files from devices. While its creator firm claimed that it is an educational tool, research revealed that it was being actively used as an info-stealer. Typically, it masquerades as an authentic file, such as a Dropbox file or an Adobe PDF document, but upon execution, it initiates malicious actions using PowerShell.

Intel CPUs Vulnerable to New Transient Execution Side-Channel Attack

25 April 2023
The new attack was discovered by researchers at Tsinghua University, the University of Maryland, and a computer lab (BUPT) run by the Chinese Ministry of Education and is different than most other side-channel attacks.

Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

25 April 2023
Search giant Google on Monday unveiled a major update to its 12-year-old Authenticator app for Android and iOS with an account synchronization option that allows users to back up their time-based one-time passwords (TOTPs) codes to the cloud.

Modernizing Vulnerability Management: The Move Toward Exposure Management

25 April 2023
Managing vulnerabilities in the constantly evolving technological landscape is a difficult task. Although vulnerabilities emerge regularly, not all vulnerabilities present the same level of risk. Traditional metrics such as CVSS score or the number of vulnerabilities are insufficient for effective vulnerability management as they lack business context, prioritization, and understanding of

US Navy Contractor Fincantieri Marine Group Hit by Cyberattack

25 April 2023
“Fincantieri Marine Group experienced a cybersecurity incident last week that is causing a temporary disruption to certain computer systems on its network,” reads the statement.

Lazarus Subgroup Targeting Apple Devices with New RustBucket macOS Malware

25 April 2023
A financially-motivated North Korean threat actor is suspected to be behind a new Apple macOS malware strain called RustBucket. "[RustBucket] communicates with command and control (C2) servers to download and execute various payloads," Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said in a technical report published last week.  The Apple device management company attributed it

The double-edged sword of open-source software

25 April 2023
The lack of visibility into the software supply chain creates an unsustainable cycle of discovering vulnerabilities and weaknesses in software and IT systems, overwhelming organizations, according to Lineaje.

Google Cloud Introduces Security AI Workbench for Faster Threat Detection and Analysis

25 April 2023
Google's cloud division is following in the footsteps of Microsoft with the launch of Security AI Workbench that leverages generative AI models to gain better visibility into the threat landscape.  Powering the cybersecurity suite is Sec-PaLM, a specialized large language model (LLM) that's "fine-tuned for security use cases." The idea is to take advantage of the latest advances in AI to augment

Collaboration between CISA, Cyber Command thwarted dangerous cyberattacks, officials said

25 April 2023
Information sharing between U.S. Cyber Command and the CISA at the Department of Homeland Security stopped several potentially disastrous cyberattacks, including a suspected Iranian attack against American elections.

38 Countries Take Part in NATO’s 2023 Locked Shields Cyber Exercise

25 April 2023
Organized at the CCDCOE in Estonia for more than a decade, the exercise tests participants’ ability to defend systems against real-time attacks, handle incident reporting, and solve challenges related to forensics, the media, and legal issues.

US Indicts Chinese National for Laundering DPRK Crypto

25 April 2023
A Chinese and a Hong Kong national are each under U.S. federal indictment for money laundering for their roles in channeling cryptocurrency stolen by North Korean hackers into hard currency and goods.

KuCoin's Twitter account hacked to promote crypto scam

25 April 2023
As some KuCoin users pointed out on social media, the scammers set up a convincing campaign similar to the platform's regular promotional events, so it was easy for them to get fooled.

National Cybersecurity Alliance launches HBCU Scholarship Program

25 April 2023
Established in partnership with One In Tech, an ISACA Foundation, the initiative will support individuals who are currently underrepresented in the industry by ensuring equitable access and advancements within cybersecurity and tech careers.

Experts released PoC Exploit code for actively exploited PaperCut flaw

25 April 2023
The cybersecurity firm Horizon3 disclosed details of the flaw along with a PoC exploit code for CVE-2023-27350. The PoC code allows attackers to bypass authentication and execute code on vulnerable PaperCut servers.

Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

25 April 2023
Search giant Google on Monday unveiled a major update to its 12-year-old Authenticator app for Android and iOS with an account synchronization option that allows users to back up their time-based one-time passwords (TOTPs) codes to the cloud. "This change means users are better protected from lockout and that services can rely on users retaining access, increasing both convenience and security,"

Cyber security technology integration, intrapreneurship & beyond

24 April 2023
In this edited interview excerpt from The Women in Technology Podcast, Check Point Global Cyber Security Warrior and Evangelist Micki Boland speaks with Becky Schneider about cyber security, technology integration, the intrapreneureal spirit and so much more. Don’t miss this! And if you like what you read, please check out the full podcast.  Tell us […] The post Cyber security technology integration, intrapreneurship & beyond appeared first on CyberTalk.

8220 Gang of Cryptojackers Exploit Log4Shell to Mint Coins

24 April 2023
Researchers found 8220 Gang exploiting the Log4Shell vulnerability to install CoinMiner in VMware Horizon servers of Korean energy-related companies. The gang uses a PowerShell script to download ScrubCrypt and establish persistence by making edits to the registry entries. System administrators are advised to verify whether their existing VMware servers are susceptible and apply the latest patches.

Play Ransomware Group Adds Two New Tools to Harvest More Data

24 April 2023
The Play ransomware group has added two custom tools written in .NET to expand the effectiveness of its attacks. Named Grixba and Volume Shadow Copy Service (VSS), these tools enable attackers to keep track of users in compromised networks and gather information about security, backup, and remote administration software.

New Blind Eagle Attack Chain Discovered

24 April 2023
The Blind Eagle cyberespionage group was identified as the source of a new multi-stage attack chain that ultimately results in the deployment of NjRAT on compromised systems. In this attack campaign, Blind Eagle leverages social engineering, custom malware, and spear-phishing attacks. Therefore, upgrade your security posture to stay safe. Moreover, training employees on how to detect phishing emails is much recommended. 

AuKill Exploits Process Explorer Utility via BYOVD, Deploys Ransomware

24 April 2023
Sophos X-Ops uncovered a defense evasion tool called AuKill. The tool exploits an outdated version of the driver used by version 16.32 of the Microsoft utility Process Explorer to disable EDR processes to deploy either a backdoor or ransomware on the targeted system. Since the beginning of 2023, the tool has been used to drop Medusa Locker and LockBit ransomware strains.