Latest Cybersecurity News and Articles


Spain to implement biometric debit and credit cards

24 April 2023
Because of the risk of mag stripes being read and copied, Spain will begin replacing existing credit cards with fingerprint biometrics cards in 2024.

Mint Sandstorm Targets U.S. Critical Infrastructure

24 April 2023
Microsoft connected the Iranian Mint Sandstorm APT group (aka PHOSPHORUS) to a wave of attacks, between late-2021 and mid-2022, targeting the U.S. critical infrastructure. The group targets private/public organizations, including activists, journalists, the Defense Industrial Base (DIB), political dissidents, and employees from various government agencies.

Enterprise devices have an average of 67 applications installed

24 April 2023
The security of workplace devices and applications remains a growing concern within hybrid and remote environments, according to new research.

These two countries are teaming up to develop AI for cybersecurity

24 April 2023
Singapore and France have announced plans to set up a research facility to jointly develop artificial intelligence (AI) capabilities that can be applied in cyber defense.

Package names repurposed to push malware on PyPI

24 April 2023
At the beginning of March, ReversingLabs researchers encountered a malicious package on the Python Package Index (PyPI) named termcolour, a three-stage downloader published in multiple versions.

North Korean Hackers Target Mac Users With New ‘RustBucket’ Malware

24 April 2023
Dubbed RustBucket and able to fetch additional payloads from its command-and-control (C&C) server, the malware has been attributed to the APT actor BlueNoroff, which is believed to be a subgroup of the infamous Lazarus hacking group.

Threat actors can use ChatGPT to sharpen cyberthreats, but no need to panic yet

24 April 2023
Since the generative artificial intelligence chatbot was released in November, Palo Alto Networks’ Unit 42 has detected up to 118 malicious URLs related to ChatGPT daily and domain squatting related to the tool has surged 17,818%.

Hackers Exploit Generative AI to Spread RedLine Stealer MaaS

24 April 2023
As generative AI tools like OpenAI ChatGPT and Google Bard continue to dominate the headlines—and pundits debate whether the technology has taken off too quickly without necessary guardrails—cybercriminals are showing no hesitance in exploiting them.

Tomiris called, they want their Turla malware back

24 April 2023
The threat actor targets government and diplomatic entities in the CIS. The few victims discovered in other regions (Middle East or Southeast Asia) turn out to be foreign representations of CIS countries, illustrating Tomiris’s narrow focus.

Top shopping periods see an increase in bot attacks

24 April 2023
Attack trends such as brute forcing, carding, credential stuffing, inventory hoarding, scalping and web scraping were analyzed in a recent report.

SolarWinds Platform Update Patches High-Severity Vulnerabilities

24 April 2023
The most severe of the two issues is CVE-2022-36963 (CVSS score of 8.8), which is described as a command injection bug in SolarWinds’ infrastructure monitoring and management solution.

ViperSoftX Updates Encryption and Anti-Analysis Techniques to Stay Stealthy

24 April 2023
ViperSoftX, a type of information-stealing software, has been primarily reported as focusing on cryptocurrencies, making headlines in 2022 for its execution technique of hiding malicious code inside log files.

The ESG Manager role & the importance of Environmental, Social & Governance strategy

24 April 2023
In this exclusive CyberTalk.org interview, Idan Eden, the ESG Manager for Check Point, shares her expertise on the rapidly growing importance of ESG in corporate decision-making. As a highly knowledgeable ESG Manager, Idan is at the forefront of this trend. She helps Check Point build an ESG strategy that not only reduces risks and enhances […] The post The ESG Manager role & the importance of Environmental, Social & Governance strategy appeared first on CyberTalk.

Russian Hackers Tomiris Targeting Central Asia for Intelligence Gathering

24 April 2023
The Russian-speaking threat actor behind a backdoor known as Tomiris is primarily focused on gathering intelligence in Central Asia, fresh findings from Kaspersky reveal. "Tomiris's endgame consistently appears to be the regular theft of internal documents," security researchers Pierre Delcher and Ivan Kwiatkowski said in an analysis published today. "The threat actor targets government and

Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD Attack

24 April 2023
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) software by means of a Bring Your Own Vulnerable Driver (BYOVD) attack. "The AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying

Critical Flaw in Inea ICS Product Exposes Industrial Organizations to Remote Attacks

24 April 2023
The impacted product provides a data interface between remote field devices and the control center through a cellular network. According to CISA, the product is used worldwide in industries such as energy, transportation, and water and wastewater.

Over 70 billion unprotected files available on unsecured web servers

24 April 2023
Across all industries, these vulnerabilities, composed of unprotected or compromised assets, data, and credentials, have proven to be an increasing challenge for organizations to detect and secure.

Eurocontrol Says Website 'Under Attack' by Pro-Russia Hacking Group

24 April 2023
Eurocontrol confirmed its website has been "under attack" since April 19, and said "pro-Russian hackers" had claimed responsibility for it. "The attack is causing interruptions to the website and web availability," a spokesperson told The Register.

Cybersecurity best practices guide for smart cities released

24 April 2023
CISA has released a joint guide on cybersecurity best practices intended to help communities navigate through the complexities of becoming a smart city.

Study: 84% of Companies Use Breached SaaS Applications - Here's How to Fix it for Free!

24 April 2023
A recent review by Wing Security, a SaaS security company that analyzed the data of over 500 companies, revealed some worrisome information. According to this review, 84% of the companies had employees using an average of 3.5 SaaS applications that were breached in the previous 3 months. While this is concerning, it isn't much of a surprise. The exponential growth in SaaS usage has security and