Latest Cybersecurity News and Articles


Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers

24 April 2023
Print management software provider PaperCut said that it has "evidence to suggest that unpatched servers are being exploited in the wild," citing two vulnerability reports from cybersecurity company Trend Micro. "PaperCut has conducted analysis on all customer reports, and the earliest signature of suspicious activity on a customer server potentially linked to this vulnerability is 14th April 01

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

22 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws in MinIO, PaperCut, and Google Chrome, respectively, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

22 April 2023
"The attackers also deployed DaemonSets to take over and hijack resources of the K8s clusters they attack," cloud security firm Aqua said in a report shared with The Hacker News.

Cyware to Power Accenture’s Next-Generation Threat Intelligence Services

22 April 2023
While the Cyware team is thrilled with this significant opportunity, it also represents another step forward in its mission to enable Collective Defense across a wide range of communities.

CFPB says employee sent confidential data of 256,000 consumers to personal email

22 April 2023
An employee at the Consumer Financial Protection Bureau sent confidential data about hundreds of thousands of consumer accounts to their personal email, the agency told CNN on Thursday.

Lazarus X_TRADER Hack Impacts Critical Infrastructure Beyond 3CX Breach

22 April 2023
Lazarus, the prolific North Korean hacking group behind the cascading supply chain attack targeting 3CX, also breached two critical infrastructure organizations in the power and energy sector and two other businesses involved in financial trading using the trojanized X_TRADER application. The new findings, which come courtesy of Symantec's Threat Hunter Team, confirm earlier suspicions that the

Google: Ukraine targeted by 60% of Russian phishing attacks in 2023

22 April 2023
In most cases, the campaign goals include intelligence collection, operational disruptions, and leaking sensitive data through Telegram channels dedicated to causing information damage to Ukraine.

Infoblox Uncovers DNS Malware Toolkit & Urges Companies to Block Malicious Domains

22 April 2023
Infoblox discovered activity from the remote access trojan (RAT) Pupy active in multiple enterprise networks in early April 2023. This C2 communication went undiscovered since April 2022.

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

22 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The three vulnerabilities are as follows - CVE-2023-28432 (CVSS score - 7.5) - MinIO Information Disclosure Vulnerability  CVE-2023-27350 (CVSS score - 9.8) - PaperCut MF/NG Improper Access Control

N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

22 April 2023
The attack against 3CX first came to light on March 29, 2023, when it emerged that Windows and macOS versions of its communication software were trojanized to deliver a C/C++-based data miner named ICONIC Stealer by means of a downloader, SUDDENICON.

Greening your security: Earth Day tips for cyber security experts

21 April 2023
EXECUTIVE SUMMARY: Celebrate Earth Day 2023! Cyber security professionals are recognizing the role that they can play in supporting environmental initiatives and realizing how sustainability intersects with cyber security. In considering the environmental impact of security-related projects, cyber security professionals can not only contribute to a more sustainable future, but also enhance the overall security […] The post Greening your security: Earth Day tips for cyber security experts appeared first on CyberTalk.

Greening your security: Earth Day tips for cyber security experts

21 April 2023
EXECUTIVE SUMMARY: Celebrate Earth Day 2023! Cyber security professionals are recognizing the role that they can play in supporting environmental sustainability initiatives and realizing how sustainability intersects with cyber security. In considering the environmental impact of security-related initiatives, cyber security professionals can not only contribute to a more sustainable future, but also enhance the overall […] The post Greening your security: Earth Day tips for cyber security experts appeared first on CyberTalk.

University websites using MediaWiki, TWiki hacked to serve Fortnite spam

21 April 2023
Researchers observed Wiki and documentation pages being hosted by universities including Stanford, MIT, Berkeley, UMass Amherst, Northeastern, Caltech, among others, were compromised.

GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

21 April 2023
Cybersecurity researchers have disclosed details of a now-patched zero-day flaw in Google Cloud Platform (GCP) that could have enabled threat actors to conceal an unremovable, malicious application inside a victim's Google account.

American Bar Association data breach hits 1.4 million members

21 April 2023
Thursday night, the ABA began notifying members that a hacker was detected on its network on March 17th, 2023, and may have gained access to members' login credentials for a legacy member system decommissioned in 2018.

Data Security Best-Practice in a World of Evolving Risks and Regulations

21 April 2023
In November last year, there were 95 disclosed data security incidents that resulted in 32 million breached records in Europe alone. Globally, there is a far worse picture. High-profile organizations like Twitter, Uber, and Twilio were hit last year.

Multinational ICICI Bank leaks passports and credit card numbers

21 April 2023
Among the leaked data were bank account details, bank statements, credit card numbers, full names, dates of birth, home addresses, phone numbers, emails, personal identification documents, and employees’ and candidates’ CVs.

DHS outlines national security challenges

21 April 2023
The DHS released the Quadrennial Homeland Security Review (QHSR). The QHSR assesses changes to threats facing the nation since the last review.

ChatGPT-Themed Scam Attacks Are on the Rise

21 April 2023
The dark side of this popularity is that ChatGPT is also attracting the attention of scammers seeking to benefit from using wording and domain names that appear related to the site.

VMware Patches Pre-Auth Code Execution Flaw in Logging Product

21 April 2023
The company shipped urgent patches on Thursday to cover critical security defects in the VMware Aria Operations for Logs (formerly vRealize Log Insight) product line and warned of the risk of pre-authentication remote root exploits.