Latest Cybersecurity News and Articles
01 April 2023
A 10-year-old Windows vulnerability is still being exploited in attacks to make executables appear legitimately signed, with the fix from Microsoft still "opt-in" after all these years. Even worse, the fix is removed after upgrading to Windows 11.
01 April 2023
Researchers at Palo Alto Networks Unit 42 discovered the new Cylance ransomware, which has already claimed several victims. Researchers noticed it early Friday morning, and further probing revealed that it is targeting Linux and Windows devices.
01 April 2023
This new funding round will enable SCADAfence to continue scaling its global reach into new markets, increasing sales and support teams in key regions, and building stronger collaborative relationships with its strategic partners.
01 April 2023
Dark Power is a relatively new ransomware written in the Nim programming language and launched in early February 2023. PayMe100USD is a new ransomware written in Python that was discovered in March 2023.
01 April 2023
The company said the Series A financing was led by Rockefeller Asset Management through its Technology Ventures Group with equity investments from Uncorrelated Ventures, the Partnership Fund for New York City.
01 April 2023
The flaw, described as a case of broken access control, impacts versions 3.11.6 and earlier. It was addressed by the plugin maintainers in version 3.11.7 released on March 22.
01 April 2023
Critical security flaws in Cacti, Realtek, and IBM Aspera Faspex are being exploited by various threat actors in hacks targeting unpatched systems.
This entails the abuse of CVE-2022-46169 (CVSS score: 9.8) and CVE-2021-35394 (CVSS score: 9.8) to deliver MooBot and ShellBot (aka PerlBot), Fortinet FortiGuard Labs said in a report published this week.
CVE-2022-46169 relates to a critical
01 April 2023
Unknown threat actors are actively exploiting a recently patched security vulnerability in the Elementor Pro website builder plugin for WordPress.
The flaw, described as a case of broken access control, impacts versions 3.11.6 and earlier. It was addressed by the plugin maintainers in version 3.11.7 released on March 22.
"Improved code security enforcement in WooCommerce components," the
31 March 2023
Pål (Paul) has more than 30 years of experience from the IT industry and has worked with both domestic and international clients on a local and global scale. Pål has a very broad competence base that covers everything from general security, to datacenter security, to cloud security services and development. For the past 10 years, […]
The post Artificial intelligence: A double-edged sword for technology & ethics appeared first on CyberTalk.
31 March 2023
U.S. healthcare giant Blue Shield of California confirmed more than 63,000 customers may have been affected by a recent ransomware attack.
31 March 2023
It has been a year since CIRCIA was signed into law by President Biden and security leaders are sharing their thoughts on the legislation.
31 March 2023
Authorities in Germany this week seized Internet servers that powered FlyHosting, a dark web service that catered to cybercriminals operating DDoS-for-hire services. Fly Hosting first advertised on cybercrime forums in November 2022, saying it was a Germany-based hosting firm that was open for business to anyone looking for a reliable place to host malware, botnet controllers, or DDoS-for-hire infrastructure.
31 March 2023
In a data breach notification letter sent yesterday to impacted individuals, the Canadian finance giant informs that hackers breached its systems in early December 2022 but did not detect the breach until February 13th, 2023.
31 March 2023
An Azure Active Directory (AAD) misconfiguration by Microsoft in one of its own cloud-hosted applications could have allowed miscreants to subvert the IT giant's Bing search engine – even changing search results.
31 March 2023
Acoalition of 11 countries committed on Thursday to counter the misuse of commercial spyware, a step toward building an international agreement to curb technology deployed by authoritarian countries to spy on dissidents and journalists.
31 March 2023
The leaked documents, referred to as The Vulkan Files, were obtained by a whistleblower and analyzed by Mandiant in collaboration with several major media outlets in Europe and the United States.
31 March 2023
Soon after Latitude Financial revealed it suffered a cyberattack, DXC Technology quietly published a note on its website stating its global network and customer support networks were not compromised.
31 March 2023
While hack-for-hire groups may advertise, they aren’t usually helping clients get a cryptocurrency payout. And you can’t sign up for a subscription service. It’s more than likely that hack-for-hire clients have a specific target and goal in mind.
31 March 2023
EXECUTIVE SUMMARY: On Wednesday, cyber security threat intelligence analysts uncovered a supply chain attack targeting the communications software provider 3CX and the company’s customers. 3CX is a VoIP IPBX software development firm whose 3CX phone system is used by more than 600,000 enterprises around the world, with 12 million daily users. The company’s client list […]
The post Malicious supply chain attack hits 3CX Desktop App appeared first on CyberTalk.
31 March 2023
Officials noted that the Washington County Sheriff's Office had its app, finance system, and jail networks disrupted by a ransomware attack between February 21 and early March, with the attack claimed by LockBit on February 27.