Latest Cybersecurity News and Articles


Cancer patient sues hospital over stolen naked photos

16 March 2023
A cancer patient whose nude medical photos and records were posted online after they were stolen by a ransomware gang, has sued her healthcare provider for allowing the "preventable" and "seriously damaging" leak.

Authorities Shut Down ChipMixer Platform Tied to Crypto Laundering Scheme

16 March 2023
A coalition of law enforcement agencies across Europe and the U.S. announced the takedown of ChipMixer, an unlicensed cryptocurrency mixer that began its operations in August 2017. "The ChipMixer software blocked the blockchain trail of the funds, making it attractive for cybercriminals looking to launder illegal proceeds from criminal activities such as drug trafficking, weapons trafficking,

Russia-linked APT29 abuses EU information exchange systems in recent attacks

16 March 2023
The Russian APT29 threat group abused multiple legitimate systems, including LegisWrite and eTrustEx, which are used by EU nations for exchanging info and data in a secure way.

FBI Warns Users About Surge in Pig Butchering Crypto Scams

16 March 2023
'Pig Butchering' cryptocurrency investment schemes increasingly target Americans; over $2 billion in cryptocurrencies were stolen by hackers in the U.S. last year. The fraudsters approach victims via dating platforms, messaging apps, or social media platforms to introduce themselves. The FBI has recommended some tips for users to defend themselves against cryptocurrency investment scams.

Exfiltration malware takes center stage in cybersecurity concerns

16 March 2023
While massive public data breaches rightfully raise alarms, the spike in malware designed to exfiltrate data directly from devices and browsers is a key contributor to continued user exposure, according to SpyCloud.

NSA Shares Guidance on Maturing ICAM Capabilities for Zero Trust

16 March 2023
According to the NSA, a mature zero trust framework requires the adoption of capabilities from seven different pillars, namely application/workload, automation and orchestration, device, data, network/environment, user, and visibility and analytics.

ChipMixer platform seized for laundering ransomware payments, drug sales

16 March 2023
The operation was conducted by Europol in coordination with law enforcement in Germany (BKA) and the United States (FBI), allowing the police to seize four servers, 7 TB of data, and $46.5 million worth of cryptocurrency (Bitcoin).

Update: Microsoft Pins Outlook Zero-Day Attacks on Russian Actor, Offers Detection Script

16 March 2023
A day after sounding an alarm for live exploitation of the Outlook security flaw, Microsoft said it traced the exploit to a Russian APT targeting a limited number of organizations in government, transportation, energy, and military sectors in Europe.

What's Wrong with Manufacturing?

16 March 2023
In last year's edition of the Security Navigator we noted that the Manufacturing Industry appeared to be totally over-represented in our dataset of Cyber Extortion victims. Neither the number of businesses nor their average revenue particularly stood out to explain this. Manufacturing was also the most represented Industry in our CyberSOC dataset – contributing more Incidents than any other

Multiple Hacker Groups Exploit 3-Year-Old Vulnerability to Breach U.S. Federal Agency

16 March 2023
Multiple threat actors, including a nation-state group, exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal entity in the U.S. The disclosure comes from a joint advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC).

CISA Issues Urgent Warning: Adobe ColdFusion Vulnerability Exploited in the Wild

16 March 2023
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 15 added a security vulnerability impacting Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The critical flaw in question is CVE-2023-26360 (CVSS score: 8.6), which could be exploited by a threat actor to achieve arbitrary code execution. "Adobe ColdFusion

Cyber security for the public sector: What you need to know

15 March 2023
By Mazhar Hamayun, cyber security engineer and member of the Office of the CTO at Check Point. In the digital age, public sector organizations face a myriad of cyber security challenges that can potentially compromise sensitive information and critical infrastructure. From phishing schemes to ransomware attacks, public sector organizations must stay ahead of threats while […] The post Cyber security for the public sector: What you need to know appeared first on CyberTalk.

NSA releases information for advancing zero trust

15 March 2023
To help improve threat prevention, the NSA released the Advancing Zero Trust Maturity throughout the User Pillar Cybersecurity Information Sheet.

Tick APT Targeted High-Value Customers of East Asian Data-Loss Prevention Company

15 March 2023
Tick (aka Bronze Butler, REDBALDKNIGHT, Stalker Panda, and Stalker Taurus) is a suspected China-aligned collective that has primarily gone after government, manufacturing, and biotechnology firms in Japan. It's said to be active since at least 2006.

Key Aerospace Player Safran Group Leaks Sensitive Data

15 March 2023
The Cybernews research team recently discovered that the French-based multinational aviation company, the eighth largest aerospace supplier worldwide, was leaking sensitive data due to a misconfiguration of its systems.

Criminals already targeting nervous CVB customers

15 March 2023
According to various researchers and security firms, threat actors are already out hunting for SVB-exposed prey through both passive and active phishing scams, including similar fake domains and business email compromise (BEC) attacks.

Microsoft Patch Tuesday, March 2023 Edition

15 March 2023
Microsoft on Tuesday released updates to quash at least 74 security bugs in its Windows operating systems and software. Two of those flaws are already being actively attacked, including an especially severe weakness in Microsoft Outlook that can be exploited without any user interaction.

ISO27001 Updates: Change is afoot

15 March 2023
The standard hasn't had a significant update since 2013. There were some minor amendments in 2017, but largely these were structural or grammatical updates. In 2022, things have changed dramatically, but also in very subtle ways.

Ring Denies Falling Victim to Ransomware Attack

15 March 2023
On Monday, the cybergang behind the Alphv ransomware added an entry to their leaks site claiming they breached Ring and threatening to release data supposedly stolen from the company.

Rishi Sunak hints at TikTok ban from UK government devices

15 March 2023
Rishi Sunak has indicated that the UK could follow the US and Canada in banning TikTok from government devices, saying he will take “whatever steps are necessary” to protect Britain’s security.