Latest Cybersecurity News and Articles
31 March 2023
According to a guidance document published earlier today, applicants seeking approval for new medical devices must submit a plan designed to “monitor, identify and address” possible cybersecurity issues associated with them.
31 March 2023
Researchers from Orca Security discovered the cross-site scripting (XSS) flaw — which they dubbed Super FabriXss — in December and reported it to Microsoft, which issued a fix for it in March's round of Patch Tuesday updates.
31 March 2023
Votiro is revolutionizing file security and safety by expanding its disarming with enhanced data detection and analytics capabilities and making them easily accessible as a browser- and cloud-based services.
31 March 2023
The vulnerabilities include remote code execution, cross-site request forgery (CSRF), authentication bypass, cross-site scripting (XSS), command injection, backdoor access, file disclosure, and session hijacking issues.
30 March 2023
In this interview, CyberTalk speaks with Deloitte’s U.S. Cyber & Strategic Risk Leader, Deborah (Deb) Golden. We’re honored and thrilled to be able to highlight her during Women’s History Month 2023! Let’s dive in! With more than 27 years in the industry, Deb currently leads one of Deloitte’s largest growth and business transformation offering portfolios […]
The post Leading with a growth mindset through grit, resilience and insatiable curiosity appeared first on CyberTalk.
30 March 2023
EXECUTIVE SUMMARY: When it comes to digital transformations, artificial intelligence and machine learning capabilities present tremendous opportunities. At the same time, they also expand the threat surface that CISOs and cyber risk professionals have to govern. To successfully navigate this new landscape, organizations need to adopt a holistic approach to risk management. The reality is […]
The post Why red team exercises for AI should be on CISO radars appeared first on CyberTalk.
30 March 2023
Are you a crypto user addicted to Tor? Tor browser users across the world are under attack with trojanized versions of Tor browser installers, especially those in Russia and nearby regions. These infected browsers were being promoted as "security-strengthened" versions of the browser. Kaspersky warned against the most common mistake - downloading and running Tor from a third-party store.
30 March 2023
A new phishing campaign has surfaced to drop Remcos RAT and Formbook malware through DBatLoader malware loader, revealed Zscaler researchers. The campaign is aimed at compromising systems in Europe. Actors also leverage a multi-layered obfuscated HTML file and OneNote attachments to propagate the DBatLoader payload.
30 March 2023
AI allows you to craft very believable ‘spear-phishing’ emails and other written communication with very little effort, especially compared to what you have to do before.
30 March 2023
Benjamin Fabre founded DataDome in 2015 with Fabien Grenier, a longtime business partner, after the pair made the observation that most companies weren’t able to detect and block bots.
30 March 2023
Details have emerged about a now-patched vulnerability in Azure Service Fabric Explorer (SFX) that could lead to unauthenticated remote code execution.
Tracked as CVE-2023-23383 (CVSS score: 8.2), the issue has been dubbed "Super FabriXss" by Orca Security, a nod to the FabriXss flaw (CVE-2022-35829, CVSS score: 6.2) that was fixed by Microsoft in October 2022.
"The Super FabriXss vulnerability
30 March 2023
A CISA guide may improve relationships between stakeholders and partners who may not traditionally be involved in a port resilience assessment.
30 March 2023
A Chinese state-sponsored threat activity group tracked as RedGolf has been attributed to the use of a custom Windows and Linux backdoor called KEYPLUG.
"RedGolf is a particularly prolific Chinese state-sponsored threat actor group that has likely been active for many years against a wide range of industries globally," Recorded Future told The Hacker News.
"The group has shown the ability to
30 March 2023
Professional bio: Micki Boland is a global cyber security warrior and evangelist with Check Point’s Office of the CTO. Micki has over 20 years in ICT, cyber security, emerging technology and innovation. Micki’s focus is helping customers, system integrators, and service providers reduce risk through the adoption of emerging cyber security technologies. Micki is an […]
The post Why AI is becoming more powerful: Implications for business & society appeared first on CyberTalk.
30 March 2023
The Azure Pipelines flaw affected both the SaaS version of Azure DevOps Server and the self-hosted, on-premises version. Customers running the on-premises version need to patch their instances to remediate the RCE vulnerability.
30 March 2023

Documents leaked from Vulkan cybersecurity firm also raise questions about role of IT engineers behind information-control projectA consortium of media outlets have published a bombshell investigation about Russia’s cyber-capabilities, based on a rare leak of documents. The files come from NTC Vulkan, a cybersecurity firm in Moscow that doubles as a contractor to Russian military and intelligence agencies.They reveal how, for years, a group of top Russian IT engineers have been hired to work with Russian military intelligence and a research facility of the FSB, Vladimir Putin’s domestic spy agency. This might seem an unusual mix, and would have been unimaginable before the end of the cold war. Continue reading...
30 March 2023

• Documents leaked by whistleblower angry over Ukraine war• Private Moscow consultancy bolstering Russian cyberwarfare• Tools support hacking operations and attacks on infrastructure• Documents linked to notorious Russian hacking group Sandworm• Russian program aims to control internet and spread disinformationThe inconspicuous office is in Moscow’s north-eastern suburbs. A sign reads: “Business centre”. Nearby are modern residential blocks and a rambling old cemetery, home to ivy-covered war memorials. The area is where Peter the Great once trained his mighty army.Inside the six-storey building, a new generation is helping Russian military operations. Its weapons are more advanced than those of Peter the Great’s era: not pikes and halberds, but hacking and disinformation tools. Continue reading...
30 March 2023
The U.S. and Costa Rica will collaborate on cybersecurity with the U.S. planning to provide $25M to strengthen Costa Rica’s digital infrastructure.
30 March 2023
A group of academics from Northeastern University and KU Leuven has disclosed a fundamental design flaw in the IEEE 802.11 Wi-Fi protocol standard, impacting a wide range of devices running Linux, FreeBSD, Android, and iOS.
Successful exploitation of the shortcoming could be abused to hijack TCP connections or intercept client and web traffic, researchers Domien Schepers, Aanjhan Ranganathan,
30 March 2023
Researchers spotted a new malware operation, named NullMixer, that hit over 8,000 targets within a week, with a special focus on North America, Italy, and France. The attackers use SEO poisoning, along with social engineering tactics to lure their potential victims, consisting mostly of IT personnel and technocrats. Now stay ahead of such threats with our state-of-the-art threat Intel exchange platform, CTIX.