Latest Cybersecurity News and Articles


Russia’s Rostec allegedly can de-anonymize Telegram users

28 March 2023
This is according to a report by Russian media the Bell and Medusa, who investigated the matter after a series of arrests of anonymous Telegram channel owners and bloggers in 2022.

Stealthy DBatLoader Malware Loader Spreading Remcos RAT and Formbook in Europe

28 March 2023
A new phishing campaign has set its sights on European entities to distribute Remcos RAT and Formbook via a malware loader dubbed DBatLoader. "The malware payload is distributed through WordPress websites that have authorized SSL certificates, which is a common tactic used by threat actors to evade detection engines," Zscaler researchers Meghraj Nandanwar and Satyam Singh said in a report

UK’s National Crime Agency Harvests Info on DDoS-For-Hire With Fake Booter Sites

28 March 2023
The NCA didn’t say how many of the sites it had set up as part of the operation, but claimed that “several thousand” people had already accessed them in search of the “booter” services needed to launch DDoS attacks against targets.

Understanding adversaries through dark web intelligence

28 March 2023
93 percent of CISOs are concerned about dark web threats, and almost 72 percent of CISOs believe that intelligence on cybercriminals is “critical” to defend their organization and increase cybersecurity, according to Searchlight Cyber.

President Biden Signs Executive Order Restricting Use of Commercial Spyware

28 March 2023
U.S. President Joe Biden on Monday signed an executive order that restricts the use of commercial spyware by federal government agencies. The order said the spyware ecosystem "poses significant counterintelligence or security risks to the United States Government or significant risks of improper use by a foreign government or foreign person." It also seeks to ensure that the government's use of

Microsoft shares guidance for investigating attacks exploiting CVE-2023-23397

28 March 2023
Microsoft published guidance for investigating attacks exploiting recently patched Outlook vulnerability tracked as CVE-2023-23397. The flaw is a Microsoft Outlook spoofing vulnerability that can lead to an authentication bypass.

Stress testing is at the heart of preventing cybersecurity risks

28 March 2023
Stress testing involves simulating different types of attacks that hackers might use to breach a system, including distributed denial of service (DDoS) attacks, brute force attacks, SQL injections, and other types of exploits.

Update: Latitude Financial cyberattack worse than first thought with 14 million customer records stolen

28 March 2023
The details stolen include 7.9 million Australian and New Zealand driver’s license numbers and 53,000 passport numbers, Latitude said. Further 6.1 million customer records were also stolen, of which 5.7 million were provided before 2013.

Apple Issues Urgent Security Update for Older iOS and iPadOS Models

27 March 2023
Apple on Monday backported fixes for an actively exploited security flaw to older iPhone and iPad models. The issue, tracked as CVE-2023-23529, concerns a type confusion bug in the WebKit browser engine that could lead to arbitrary code execution. It was originally addressed by the tech giant with improved checks as part of updates released on February 13, 2023. An anonymous researcher has been

Operation Tainted Love: New Cyberespionage Campaign by Chinese

27 March 2023
A Chinese cyber-espionage campaign, named Operation Tainted Love—associated with Operation Soft Cell—has been found hitting telecommunications providers in the Middle East since Q1 2023. Operation Soft Cell relies heavily on a custom credential theft malware, mim221.

REF2924 Brings a New Weapon NAPLISTENER to the Table

27 March 2023
The REF2924 threat cluster was observed dropping a previously-unseen malware, dubbed NAPLISTENER, on entities in Southeast and South Asia. The malware evades network-based forms of detection. Actors target Microsoft Exchange Servers exposed to the internet to deploy several backdoors, including SIESTAGRAPH, DOORME, and ShadowPad.

J.P. Morgan to utulize biometric-based payments

27 March 2023
A new biometric payment system will be rolled out by J.P. Morgan including palm and face identification for payment authentication in-store. 

AI and the future of work: Strategies for boldly leading through uncertainty

27 March 2023
EXECUTIVE SUMMARY Replacement by robots? The idea of robots dominating the world is a common sci-fi trope that elicits an almost involuntary eye-roll from most of us. However, as technology continues to advance at lightning speed, the prospect of being replaced by robots is no longer so distant. For some employees, it’s becoming an increasingly […] The post AI and the future of work: Strategies for boldly leading through uncertainty appeared first on CyberTalk.

Pwn2Own Vancouver 2023 awarded $1,035,000 and a Tesla for 27 0-days

27 March 2023
On the third day, contestants were awarded $185,000 after demonstrating 5 zero-day exploits targeting the Ubuntu Desktop, Windows 11, and the VMware Workstation software.

Twitter says source code was leaked on GitHub, now it’s trying to find the culprit

27 March 2023
Parts of Twitter’s source code were recently leaked online via GitHub, the New York Times reports, but were taken down after the social media platform filed a DMCA request.

51% of users admit to resetting forgotten passwords once a month

27 March 2023
Research highlights current shifts in identity management including passwordless authentication and personally identifiable information ownership.

New BEC Attack Tactics Enable Fake Asset Purchases

27 March 2023
Instead of sending fake invoices or money transfer requests, attackers attempt to ‘purchase’ high-value goods such as construction materials, agricultural supplies, IT hardware, and solar energy products.

Report shows top transport cyber threats in EU

27 March 2023
A new report by the European Union Agency for Cybersecurity reveals ransomware attacks are the most prominent threat facing the transport sector.

20-Year-Old BreachForums Founder Faces Up to 5 Years in Prison

27 March 2023
Conor Brian Fitzpatrick, the 20-year-old founder and the administrator of the now-defunct BreachForums has been formally charged in the U.S. with conspiracy to commit access device fraud. If proven guilty, Fitzpatrick, who went by the online moniker "pompompurin," faces a maximum penalty of up to five years in prison. He was arrested on March 15, 2023. "Cybercrime victimizes and steals financial

Bitter APT Targets Chinese Nuclear Energy Organizations With Spoofed Emails

27 March 2023
In the new campaign found by Intezer, Bitter sends emails pretending to be from the Embassy of Kyrgyzstan in Beijing to various Chinese nuclear energy companies and academics related to that field.