Latest Cybersecurity News and Articles


Microsoft warns of phishing attack targeting accountants as Tax Day approaches

14 April 2023
With the USA reaching the end of its annual tax season, accountants are scrambling to gather clients' tax documents to complete and file their tax returns, making it an ideal time for threat actors to target tax preparers.

A flaw in the Kyocera Android printing app can be abused to drop malware

14 April 2023
An improper intent handling issue affecting the Kyocera Android printing app can allow malicious applications to drop malware, as reported by the Japanese Vulnerability Notes (JVN).

Severe Android and Novi Survey Vulnerabilities Under Active Exploitation

14 April 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The two flaws are listed below - CVE-2023-20963 (CVSS score: 7.8) - Android Framework Privilege Escalation Vulnerability CVE-2023-29492 (CVSS score: TBD) - Novi Survey Insecure Deserialization Vulnerability

Webinar: Tips from MSSPs to MSSPs – Building a Profitable vCISO Practice

14 April 2023
In today's fast-paced and ever-changing digital landscape, businesses of all sizes face a myriad of cybersecurity threats. Putting in place the right people, technological tools and services, MSSPs are in a great position to ensure their customers' cyber resilience.  The growing need of SMEs and SMBs for structured cybersecurity services can be leveraged by MSPs and MSSPs to provide strategic

Google Launches New Cybersecurity Initiatives to Strengthen Vulnerability Management

13 April 2023
Google on Thursday outlined a set of initiatives aimed at improving the vulnerability management ecosystem and establishing greater transparency measures around exploitation. "While the notoriety of zero-day vulnerabilities typically makes headlines, risks remain even after they're known and fixed, which is the real story," the company said in an announcement. "Those risks span everything from

Strengthening security: A comprehensive, consolidated & collaborative approach

13 April 2023
EXECUTIVE SUMMARY: In 2023, the global cost of cyber attacks is expected to exceed $8 trillion dollars. In 2022, cyber attacks increased by nearly 40%, worldwide, as compared to 2021. From large multi-national corporations to government agencies, many entities need help solving for serious security vulnerabilities to avoid significant security incidents. “The main challenge that […] The post Strengthening security: A comprehensive, consolidated & collaborative approach appeared first on CyberTalk.

Qbot Takes New Distribution Method to Infect Korean Users

13 April 2023
AhnLab has discovered a fresh attack strategy that spreads Qbot malware through malevolent PDF attachments added to replies or forwarded messages in already-existing emails. Qbot or Qakbot follows a destructive attack pattern, shifting from one tactic to another for maximum profits. 

Secure-by-design and -default principles released by CISA

13 April 2023
New joint guidance by CISA and other governmental agencies prompts software manufacturers to ship products that are secure-by-design and -default.

Personal email from Dutch Police warns ex-Raidforums users

13 April 2023
The Dutch Police, in collaboration with international police organizations, has launched an investigation into Raidforums.com, leading to the platform’s shutdown and the seizure of a dataset containing user information.

New Python-Based "Legion" Hacking Tool Emerges on Telegram

13 April 2023
Besides using Telegram as a data exfiltration point, Legion is designed to exploit web servers running content management systems (CMS), PHP, or PHP-based frameworks like Laravel.

Stolen Card Numbers Plummet 94% Globally

13 April 2023
The volume of compromised credit cards offered for sale on cybercrime markets has dropped sharply over the past few years, although UK figures rose, according to Cybersixgill.

RTM Locker: Emerging Cybercrime Group Targeting Businesses with Ransomware

13 April 2023
Cybersecurity researchers have detailed the tactics of a "rising" cybercriminal gang called "Read The Manual" (RTM) Locker that functions as a private ransomware-as-a-service (RaaS) provider and carries out opportunistic attacks to generate illicit profit. "The 'Read The Manual' Locker gang uses affiliates to ransom victims, all of whom are forced to abide by the gang's strict rules,"

Malicious ChatGPT & Google Bard Installers Distribute RedLine Stealer

13 April 2023
When a victim installs a malicious file from one of these sponsored ads, their device is hijacked by the RedLine infostealer, which can then steal confidential data, disrupt critical infrastructure, and compromise financial accounts.

WhatsApp Introduces New Device Verification Feature to Prevent Account Takeover Attacks

13 April 2023
Popular instant messaging app WhatsApp on Thursday announced a new account verification feature that ensures that malware running on a user's mobile device doesn't impact their account.

Critical Vulnerability in Hikvision Storage Solutions Exposes Video Security Data

13 April 2023
The vulnerability, tracked as CVE-2023-28808, has been described by the vendor as an access control issue that can be exploited to obtain administrator permissions by sending specially crafted messages to the targeted device.

Luxury Yacht Maker Lürssen Hit by Ransomware Attack Over Easter Weekend

13 April 2023
“In coordination with internal and external experts, we immediately initiated all necessary protective measures and informed the responsible authorities,” a spokesperson reportedly said in a brief statement.

Zelle Phishing Campaign Sends Spoofed Emails

13 April 2023
Zelle, the widely used and highly acclaimed money-transfer service, is now a prime target for cybercriminals. The simplicity of sending funds to friends or businesses through Zelle has made it appealing for hackers looking to cash in.

Pakistan-Aligned Transparent Tribe APT Expands Interest in Indian Education Sector

13 April 2023
SentinelLabs has been tracking a recently disclosed cluster of malicious Office documents that distribute Crimson RAT, used by the APT36 group (aka Transparent Tribe) targeting the education sector.

Sixty-three percent of CISOs predict hybrid or remote work to remain

13 April 2023
With the rise of hybrid and remote work environments, security leaders have wondered how best to protect their employees and their networks. 

Former TSB chief information officer fined £81,000 over IT meltdown in 2018

13 April 2023
Former TSB chief information officer fined £81,000 over IT meltdown in 2018 Regulator says Carlos Abarca ‘failed to take reasonable steps’ to ensure outsourcing firm was ready to migrate accounts en masseUK regulators have imposed an £81,000 fine on a former TSB information officer over the bank’s IT meltdown in 2018 that left millions of customers locked out of their accounts.The Prudential Regulation Authority (PRA) said Carlos Abarca, who was TSB’s chief information officer at the time of the meltdown, “failed to take reasonable steps” to ensure that an outsourcing firm owned by TSB’s parent company was ready to carry out the IT migration of customers en masse. Continue reading...