Latest Cybersecurity News and Articles


RTM Locker Enforces Strict Rules on Affiliates to Avoid Public Attention

15 April 2023
Trellix detected a new private RaaS group, named Read The Manual (RTM) Locker, that has been leveraging affiliates for ransom. Also, it flies under the radar by avoiding high-profile targets. Moreover, the self-destructive nature of RTM Locker and the wipeout of logs make it a tough game to crack for security professionals.

Transparent Tribe Eyes Indian Education Sector

15 April 2023
SentinelLabs identified a campaign by the Transparent Tribe that targets the Indian education sector via education-themed malicious Office documents propagating Crimson RAT. The group has long been targeting different sectors in India. Hence, vigilance and robust cyber defense strategies are necessary.

Forensic Analysis Confirms Involvement of North Korean Attackers in 3CX Supply Chain Attack

15 April 2023
3CX confirmed that the software supply chain attack was the work of a North Korean hacker group, UNC4736. The group used the Taxhaul and Simplesea malware for infecting Windows and macOS, respectively. Attackers used Taxhaul (or TxRLoader) to target Windows machines, which was further used to deploy a second-stage payload called Coldcat.

APT28 Leader’s Email Breached by Ukrainian Hackers

15 April 2023
Ukrainian hacker group Cyber Resistance claimed to have hacked the personal accounts, emails, and social media of a Russian GRU officer, who is also the leader of APT28. The email hack allowed the hackers to extract sensitive documents along with personal information and photos, and then leak them into the public domain.

Legion: A Python-Based Hacking Tool Targets Websites and Web Services

15 April 2023
The cybercriminal group, which goes by the moniker “Forza Tools,” was seen offering Legion - a Python-based credential harvester and SMTP hijacking tool. The malware targets online email services for phishing and spam attacks. Experts suggest it is likely based on the AndroxGhOst malware and has several feature modules. 

iPhones Hacked to Drop QuaDream’s KingsPawn Spyware

15 April 2023
QuaDream, an Israeli company best known for its malware Reign, has launched the new commercial spyware KingsPawn (a Pegasus-like threat). To begin the attack, iCloud calendar invitations with backdated timestamps are sent to targeted iOS devices. Experts recommend following best practices, such as enabling automatic software updates and using reliable anti-malware software to stay protected.

Darktrace: Investigation found no evidence of LockBit breach

15 April 2023
It is now apparent that LockBit messed up, confusing Darktrace with threat intelligence company DarkTracer which tweeted about the gang's leak site being flooded with fake victims.

Massive malvertising campaign targets seniors via fake Weebly sites

15 April 2023
The malvertising campaign is run via Google ads aimed at seniors. The threat actor is creating hundreds of fake websites via Weebly to host decoy content to fool search engines and crawlers while redirecting victims to a fake computer alert.

Vice Society ransomware uses new PowerShell data theft tool in attacks

15 April 2023
The new, rather sophisticated PowerShell script automates data theft from compromised networks. The script uses PowerShell to automate data exfiltration and consists of multiple functions, including Work(), Show(), CreateJobLocal(), and fill().

Google Releases Urgent Chrome Update to Fix Actively Exploited Zero-Day Vulnerability

15 April 2023
Tracked as CVE-2023-2033, the high-severity vulnerability has been described as a type confusion issue in the V8 JavaScript engine. Clement Lecigne of Google's Threat Analysis Group (TAG) has been credited with reporting the issue on April 11, 2023.

Google Releases Urgent Chrome Update to Fix Actively Exploited Zero-Day Vulnerability

14 April 2023
Google on Friday released out-of-band updates to resolve an actively exploited zero-day flaw in its Chrome web browser, making it the first such bug to be addressed since the start of the year. Tracked as CVE-2023-2033, the high-severity vulnerability has been described as a type confusion issue in the V8 JavaScript engine. Clement Lecigne of Google's Threat Analysis Group (TAG) has been

Why is ‘Juice Jacking’ Suddenly Back in the News?

14 April 2023
KrebsOnSecurity received a nice bump in traffic this week thanks to tweets from the Federal Bureau of Investigation (FBI) and the Federal Communications Commission (FCC) about "juice jacking," a term first coined here in 2011 to describe a potential threat of data theft when one plugs their mobile device into a public charging kiosk. It remains unclear what may have prompted the alerts, but the good news is that there are some fairly basic things you can do to avoid having to worry about juice jacking.

Researchers Disclosure Cisco ISE Broken Access Control Issue

14 April 2023
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files.

Juniper Networks Patches Critical Third-Party Component Vulnerabilities

14 April 2023
Networking, cloud, and cybersecurity solutions provider Juniper Networks this week published advisories detailing tens of vulnerabilities found across its product portfolio, including critical bugs in third-party components of Junos OS and STRM.

New landscapes in cloud security (2023)

14 April 2023
Richard Flanders has 35 years’ experience in advising clients on all aspects of enterprise IT. He has held senior roles at VMware, Fujitsu and Computacenter and others and is currently leading Check Points’ cloud security business in Eastern EMEA and Africa. He has been in this role at Check Point for seven years. In this […] The post New landscapes in cloud security (2023) appeared first on CyberTalk.

Privacy-invasive and Clicker Android Adware found in popular apps in South Korea

14 April 2023
Some apps were removed from Google Play while others were updated by the official developers. Users are encouraged to update the apps to the latest version to remove the identified threat from their devices.

Severe Android and Novi Survey Vulnerabilities Under Active Exploitation

14 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

12,000 Indian Government Websites on Alert for Indonesian Hacking Threat

14 April 2023
CERT-In issued an ‘Urgent- High Alert’ warning to all Central and state agencies and departments to be alert of potential attacks by Indonesian hackers and report any such incidents to them immediately.

Cyber assets increased by 133% year-over-year

14 April 2023
Cloud access for security leaders was analyzed in a recent report by JupiterOne and found that cyber assets increased by 133% year-over-year.

Nation-state actors are taking advantage of weak passwords to go after cloud customers, Google says

14 April 2023
Weak passwords and other comprises of user identity continue to drive security incidents for Google Cloud customers, with weak passwords accounting for nearly half of the incidents affecting its clients, according to a report released by the company.