Latest Cybersecurity News and Articles
19 April 2023
U.S. authorities allege Chinese operatives ran the campaign from 2016 to the present that willfully caused emotional stress on targets of a harassment campaign along with immediate family members.
19 April 2023
By mimicking normal behavior, LOTL attacks make it extremely difficult for IT teams and security solutions to detect any signs of malicious activities. Experienced analysts, however, might be able to pick up on subindicate an LOTL attack.
19 April 2023
In the wrong hands, the data gleaned from the devices – including customer data, router-to-router authentication keys, application lists, and much more – is enough to launch a cyberattack.
19 April 2023
An Iranian government-backed actor known as Mint Sandstorm has been linked to attacks aimed at critical infrastructure in the U.S. between late 2021 to mid-2022.
"This Mint Sandstorm subgroup is technically and operationally mature, capable of developing bespoke tooling and quickly weaponizing N-day vulnerabilities, and has demonstrated agility in its operational focus, which appears to align
19 April 2023
A fresh round of patches has been made available for the vm2 JavaScript library to address two critical flaws that could be exploited to break out of the sandbox protections.
Both the flaws – CVE-2023-29199 and CVE-2023-30547 – are rated 9.8 out of 10 on the CVSS scoring system and have been addressed in versions 3.9.16 and 3.9.17, respectively.
Successful exploitation of the bugs, which allow
18 April 2023
New report from the NCSC assesses the threat to UK industry and society from the use of commercial cyber tools and services.
18 April 2023
This alert highlights the emerging risk posed by state-aligned adversaries following the Russian invasion of Ukraine.
18 April 2023
Alert issued warns of the emerging threat from state-aligned groups and the different forms of activity.
18 April 2023
EXECUTIVE SUMMARY: As the fastest-growing consumer application in history, with more than 100 million monthly active users, ChatGPT has gained the attention of lawmakers and policy analysts around the world. Due to the wave of interest in the technology, the U.S. National Telecommunications and Information Administration (NTIA) is asking for public input regarding how to […]
The post What to know: New AI rules in the U.S. appeared first on CyberTalk.
18 April 2023
For the past seven years, a malware-based proxy service known as "Faceless" has sold anonymity to countless cybercriminals. For less than a dollar per day, Faceless customers can route their malicious traffic through tens of thousands of compromised systems advertised on the service. In this post we'll examine clues left behind over the past decade by the proprietor of Faceless, including some that may help put a face to the name.
18 April 2023
EXECUTIVE SUMMARY: As the AI revolution continues to sweep the world, OpenAI’s ChatGPT tool has emerged as a groundbreaking force in the realm of natural language processing. With applications spanning across industries and organizations, the possibilities sometimes seem limitless. But with the widespread adoption of AI language models, ChatGPT, and adjacent technologies, concerns around data […]
The post CISO insights on ChatGPT: Game-changer or security threat? appeared first on CyberTalk.
18 April 2023
The now-defunct Conti ransomware gang members were observed deploying a new malware strain, dubbed Domino, that appears to have been developed by the FIN7 cybercrime organization. Domino has been active in the wild since at least October 2022. Organizations and security teams need a robust Threat Intelligence Platform (TIP) to identify and understand the scope and extent of such attacks.
18 April 2023
The malware is currently still in development and is receiving continuous improvement updates designed to make it a more potent and effective tool for attackers and a threat to defenders.
18 April 2023
As business travel rises companies need to remind employees of security risks of plugging in any type of portable media or connected cables.
18 April 2023
Recent cybersecurity trends were analyzed in a report revealing that 68% of organizations experienced a known cyberattack within the last 12 months.
18 April 2023
The component that makes Aurora’s delivery stealthy and dangerous is a highly evasive loader we named “in2al5d p3in4er.” It is compiled with Embarcadero RAD Studio and targets endpoint workstations using an advanced anti-VM technique.
18 April 2023
A security researcher has released, yet another sandbox escape proof of concept (PoC) exploit that makes it possible to execute unsafe code on a host running the VM2 sandbox.
18 April 2023
Across all BEC attacks seen over the past year, 57% of them relied on language as the main attack vector to get them in front of unsuspecting employees, according to Armorblox.
18 April 2023
While the nation-state group has previously employed ScreenConnect, RemoteUtilities, and Syncro, a new analysis from Group-IB has revealed the adversary's use of the SimpleHelp remote support software in June 2022.
18 April 2023
The covid-19 pandemic has greatly affected the healthcare industry, including staffing shortages within IT departments that put organizations at risk.