Latest Cybersecurity News and Articles
22 March 2023
EXECUTIVE SUMMARY: Welcome to the digital age, where everything from our personal information to the critical infrastructure of entire nations is stored and managed online. The value of the aforementioned data is immense and cyber criminals are eager to capitalize on ill-gotten gains. A combination of extortion and dark web data sales allow cyber criminals […]
The post 10 top cyber security vulnerabilities that you can’t ignore (2023) appeared first on CyberTalk.
22 March 2023
This is the second ransomware gang claiming to have stolen data from the City of Oakland after Play ransomware took responsibility in early March for a mid-February cyberattack.
22 March 2023
The UK’s leading cybersecurity agency has launched two new services designed to help the nation’s small businesses to more effectively enhance their cyber-risk management.
22 March 2023
Researchers from Ruhr University Bochum, Germany, and the Max Planck Institute for Security and Privacy (MPI-SP) are pioneering innovative detection techniques to combat these hardware Trojans.
22 March 2023
SentinelOne spotted the Winter Vivern APT group targeting Polish government agencies, Indian government entities, the Ukraine Ministry of Foreign Affairs, and the Italy Ministry of Foreign Affairs in cyberespionage campaigns since 2021.
22 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released eight Industrial Control Systems (ICS) advisories on Tuesday, warning of critical flaws affecting equipment from Delta Electronics and Rockwell Automation.
This includes 13 security vulnerabilities in Delta Electronics' InfraSuite Device Master, a real-time device monitoring software. All versions prior to 1.0.5 are
22 March 2023
“Should they click on the ‘apply’ button contained on these scam web pages, victims are redirected to phishing websites that the scammers create to harvest the credentials of victims’ social network accounts,” reads the advisory by Group-IB.
22 March 2023
How should security leaders implement zero trust?
Find out more in this Security podcast episode featuring Mark Ruchie, CISO at Entrust.
22 March 2023
According to researchers at SentinelOne, the gang has lately shifted to DLL hijacking via Microsoft Distributed Transaction Coordinator (MSDTC) to extract and launch ransomware payloads.
22 March 2023
The North Korean advanced persistent threat (APT) actor dubbed ScarCruft is using weaponized Microsoft Compiled HTML Help (CHM) files to download additional malware.
According to multiple reports from AhnLab Security Emergency response Center (ASEC), SEKOIA.IO, and Zscaler, the findings are illustrative of the group's continuous efforts to refine and retool its tactics to sidestep detection.
"
22 March 2023
When opening a file in the Windows 11 Snipping Tool and overwriting an existing file, instead of truncating any unused data, it leaves the unused data behind, allowing it to be partially recovered.
22 March 2023
Italian car manufacturer Ferrari confirmed this week it was the target of a cyberattack with a ransom demand related to certain client contact details.
22 March 2023
REF2924 is the moniker assigned to an activity cluster linked to attacks against an entity in Afghanistan as well as the Foreign Affairs Office of an ASEAN member in 2022.
22 March 2023
Active Directory (AD) is a powerful authentication and directory service used by organizations worldwide. With this ubiquity and power comes the potential for abuse. Insider threats offer some of the most potentials for destruction. Many internal users have over-provisioned access and visibility into the internal network.
Insiders' level of access and trust in a network leads to unique
22 March 2023
The campaigns have affected individuals in Chile, Mexico, Peru, and Portugal. The attackers send a fake overdue invoice as an HTML page or a password-protected PDF file to lure victims. Mispadu gathers the list of antivirus solutions installed on the compromised host, steals Google Chrome and Microsoft Outlook credentials, and submits the collected data to its C2 servers.
22 March 2023
The Twitter account of one of the leading news channels in India – News24 – became a victim of a recent cryptocurrency scheme. Hackers breached the account to post phishing links of a fake XRP drop, urging people to click and potentially get conned.
22 March 2023
In Tuesday's "final update" the site's admins wrote they "confirmed that the glowies [slang for government agents – ed.] likely have access to Pom's machine" and shutting down the site is the only option.
22 March 2023
Avast researchers observed that attackers are abusing this service to distribute Redline. They register for the service via a fake email and upload a document containing a link to their website.
22 March 2023
Also known as LockBit Black, LockBit 3.0 features a highly modular architecture compared to its previous versions and offers a range of customizable arguments that can alter its behavior post-deployment.
22 March 2023
An early morning cyberattack on one of the island’s few telecommunications providers, Docomo Pacific, left customers in Guam and the CNMI without services on last Friday.