Latest Cybersecurity News and Articles


"Juice jacking:" FBI warns against using public charging stations

12 April 2023
"Avoid using free charging stations in airports, hotels, or shopping centers," the FBI cautioned on Twitter recently. "Bad actors have figured out ways to use public USB ports to introduce malware and monitoring software onto devices."

Criminal businesses adopt corporate behavior as they grow

12 April 2023
“The criminal underground is rapidly professionalizing – with groups beginning to mimic legitimate businesses that grow in complexity as their membership and revenue increases,” said Jon Clay, VP of threat intelligence at Trend Micro.

SAP releases security updates for two critical-severity flaws

12 April 2023
SAP has released its April 2023 security updates for several of its products, which include fixes for two critical-severity vulnerabilities that impact the SAP Diagnostics Agent and the SAP BusinessObjects Business Intelligence Platform.

Consumers take data control into their own hands amid rising privacy concerns

12 April 2023
Data Subject Requests (DSRs), which are formal requests made by individuals to access, modify, or delete their personal data held by a company, increased by 72% from 2021 to 2022, according to DataGrail.

Adobe Plugs Gaping Security Holes in Reader, Acrobat

12 April 2023
Software maker Adobe on Tuesday shipped patches for at least 56 security vulnerabilities in a wide range of products, some serious enough to expose Windows and macOS users to code execution attacks.

Windows zero-day vulnerability exploited in ransomware attacks

12 April 2023
Microsoft has patched a zero-day vulnerability in the Windows Common Log File System (CLFS), actively exploited by cybercriminals to escalate privileges and deploy Nokoyawa ransomware payloads.

Urgent: Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit

12 April 2023
It's the second Tuesday of the month, and Microsoft has released another set of security updates to fix a total of 97 flaws impacting its software, one of which has been actively exploited in ransomware attacks in the wild. Seven of the 97 bugs are rated Critical and 90 are rated Important in severity. Interestingly, 45 of the shortcomings are remote code execution flaws, followed by 20

Lazarus Sub-Group Labyrinth Chollima Uncovered as Mastermind in 3CX Supply Chain Attack

12 April 2023
Enterprise communications service provider 3CX confirmed that the supply chain attack targeting its desktop application for Windows and macOS was the handiwork of a threat actor with North Korean nexus. The findings are the result of an interim assessment conducted by Google-owned Mandiant, whose services were enlisted after the intrusion came to light late last month. The threat intelligence

As the west tries to limit TikTok’s reach, what about China’s other apps?

12 April 2023
As the west tries to limit TikTok’s reach, what about China’s other apps? With government concerns over national security growing, Beijing’s influence over platforms such as WeChat and Shein could come under scrutinyAs TikTok, the world’s most popular app, comes under increasing scrutiny in response to data privacy and security concerns, lawmakers in the west may soon set their sights on other Chinese platforms that have gone global.TikTok was built by ByteDance as a foreign version of its popular domestic video-sharing platform, Douyin. But it is far from being ByteDance’s only overseas moneymaker. The Chinese company owns dozens of apps that are available overseas, many of them English-language versions of Chinese offerings. Continue reading...

Microsoft (& Apple) Patch Tuesday, April 2023 Edition

11 April 2023
Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.

Color1337 Cryptojacking Campaign Churns Juices From Linux Servers

11 April 2023
Cybersecurity company Tehtris analyzed a cryptojacking campaign targeting Linux systems and infecting those with a malware bot called uhQCCSpB. With the bot, attackers use two strategies to launch a Monero miner on the infected machine. The "diicot" cryptominer is activated on machines that have more than four cores, whereas the "SlowAndSteady" option is executed on machines with four or fewer cores.

Update: 3CX confirms North Korean hackers behind supply chain attack

11 April 2023
The North Korea-linked attackers infected 3CX systems with malware known as Taxhaul (or TxRLoader), which deployed a second-stage malware downloader named Coldcat by Mandiant.

Celebrate Identity Management Day with these best practices

11 April 2023
EXECUTIVE SUMMARY: Happy Identity Management Day! Established in 2021, in partnership with the National Cybersecurity Alliance, Identity Management Day is held on the second Tuesday of April. The day is intended to advance the education of business leaders and to create general awareness around the importance of identity management.  Key insights A recent survey of […] The post Celebrate Identity Management Day with these best practices appeared first on CyberTalk.

Siemens, Schneider Electric Address Dozens of ICS Vulnerabilities

11 April 2023
The total number of vulnerabilities patched this month is significantly smaller than in February and March, when the industrial giants addressed roughly 100 security issues.

Malware Disguised as Document from Ukraine's Energoatom Delivers Havoc Demon Backdoor

11 April 2023
When opened, it displays an image instructing the user to enable Word’s macro code execution to reveal information supposedly protected by M.E. Doc (My Electronic Document).

Belgium Anti-Phishing Shield (BAPS) Stops 14 Million Dangerous Clicks in 2022

11 April 2023
The Belgium Anti-Phishing Shield (BAPS) has prevented a staggering 14 million clicks to suspicious websites in 2022, thanks to the unique collaboration between the Centre for Cybersecurity Belgium (CCB) and the general public.

Battle could be brewing over new FCC data breach reporting rules

11 April 2023
An expanded data breach definition and the telcos’ desire to link notifications to “concrete harm” are among the most controversial aspects of the proposed FCC data breach reporting rules.

Miscreants could use Azure access keys as backdoors

11 April 2023
A design flaw in Microsoft Azure – that shared key authorization is enabled by default when creating storage accounts – could give attackers full access to your environment, according to Orca Security researchers.

Over 40% of cybersecurity teams told to keep breaches confidential

11 April 2023
New report reveals phishing and ransomware attacks are on the rise with half of companies experiencing some form of cyber threat in the past year.

Over 40% of cybersecurity teams told to keep breeches confidential

11 April 2023
New report reveals phishing and ransomware attacks are on the rise with half of companies experiencing some form of cyber threat in the past year.