Latest Cybersecurity News and Articles


Dark Pink Deploys KamiKakaBot to Target Government Entities in South Asian Countries

15 March 2023
Cybercriminals, purportedly of Asia-Pacific origin, have launched attacks aimed at government and military organizations in Southeast Asian countries. According to EclecticIQ, Dark Pink APT is behind the campaign and attempts to cripple systems via a custom malware dubbed KamiKakaBot. There are used to execute arbitrary commands and pilfer sensitive data from users.

Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

15 March 2023
In all, Adobe released patches for a whopping 106 vulnerabilities in a wide range of products, some serious enough to expose both Windows and macOS users to remote code execution attacks.

Emotet, QSnatch Malware Dominate Malicious DNS Traffic

15 March 2023
An analysis of trillions of DNS requests by Akamai showed a shocking amount of malicious traffic inside enterprise networks, with threats using DNS as a sort of malicious Autobahn.

SAP releases security updates fixing five critical vulnerabilities

15 March 2023
Software vendor SAP has released security updates for 19 vulnerabilities, five rated as critical, meaning that administrators should apply them as soon as possible to mitigate the associated risks.

Microsoft Rolls Out Patches for 80 New Security Flaws — Two Under Active Attack

15 March 2023
Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of 80 security flaws, two of which have come under active exploitation in the wild. Eight of the 80 bugs are rated Critical, 71 are rated Important, and one is rated Moderate in severity. The updates are in addition to 29 flaws the tech giant fixed in its Chromium-based Edge browser in recent weeks. The

Two U.S. Men Charged in 2022 Hacking of DEA Portal

14 March 2023
Two U.S. men have been charged with hacking into a U.S. Drug Enforcement Agency (DEA) online portal that taps into 16 different federal law enforcement databases. Both are alleged to be part of a larger criminal organization that specializes in using fake emergency data requests from compromised police and government email accounts to publicly threaten and extort their victims.

10 of the best places to find AI talent for your business

14 March 2023
EXECUTIVE SUMMARY: Investing in AI? Don’t forget to invest in AI talent. In the modern business world, Artificial Intelligence (AI) tools are like powerful and versatile Swiss Army knives. As a Swiss Army knife offers a wide range of capabilities that can be adapted to a variety of situations, AI tools provide enterprises with a […] The post 10 of the best places to find AI talent for your business appeared first on CyberTalk.

UK's schoolgirl cyber security champions joined by undeclared war star at prestigious awards night

14 March 2023
Winning teams from the National Cyber Security Centre’s 2023 CyberFirst Girls Competition attend prize-giving ceremony in Belfast.

DEV-1101 Offers Phishing Kit for High-Volume AiTM Campaigns

14 March 2023
Microsoft Threat Intelligence stumbled across an open source adversary-in-the-middle (AiTM) phishing kit that furthers the ability of hackers to launch organized attacks and also scale it. The threat actor behind the kit is being tracked under the moniker DEV-1101. The kit’s features include setting up landing pages impersonating Microsoft Office and Outlook platforms. It can let attackers manage campaigns from mobile devices and even bypass CAPTCHA barriers.

2022 saw a 61% increase in the rate of phishing attacks

14 March 2023
A 2022 SaaS report by SaaS Alerts analyzed new threat vectors, key areas of concern and potential security gaps in SaaS applications. 

Users question corporate data responsibility & privacy

14 March 2023
Users question corporate data responsibility & privacy The Corporate Data Responsibility Survey 2022 from KPMG found disparate views on data privacy between U.S. users and corporations.

Antwan D. Banks hired as NMFTA Director of Enterprise Security

14 March 2023
Antwan D. Banks has been hired as Director of Enterprise Security for the National Motor Freight Traffic Association to defend trucking cybersecurity.

Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

14 March 2023
An open-source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale. Microsoft is tracking the threat actor behind the kit under the moniker DEV-1101.

Siemens Addresses Over 90 Vulnerabilities for ICS Patch Tuesday

14 March 2023
Siemens has released only seven new advisories, but they describe a total of 92 vulnerabilities. However, a vast majority are introduced by the use of third-party components rather than being specific to Siemens products.

Hospital in Brussels latest victim in spate of European healthcare cyberattacks

14 March 2023
Ambulances were diverted from the Centre Hospitalier Universitaire (CHU) Saint-Pierre this weekend following the attack in the early hours of Friday morning. Details about the attack and the perpetrators have not yet been disclosed.

Financial services DDoS resilience starts with understanding attack surface

14 March 2023
The recent attack on Danish Bank shows what can happen when organizations need more awareness of vulnerabilities and evolving DDoS attack surface. 

CISA now warns critical infrastructure of ransomware-vulnerable devices

14 March 2023
"As part of RVWP, CISA leverages existing authorities and technology to proactively identify information systems that contain security vulnerabilities commonly associated with ransomware attacks," the cybersecurity agency said.

Grip Security Receives Investment from The Syndicate Group

14 March 2023
The Boston, MA, and Tel Aviv, Israel-based SaaS security company unifying discovery, access control, and data governance, received an investment from The Syndicate Group. The amount of the deal was not disclosed.

LockBit Claims it Stole SpaceX Schematics From Parts Supplier, Threatens to Leak Them

14 March 2023
Ransomware gang Lockbit has boasted it broke into Maximum Industries, which makes parts for SpaceX, and stole 3,000 proprietary schematics developed by Elon Musk's rocketeers.

88% of breached passwords are 12 characters or less

14 March 2023
A recent study of 800 million breached passwords found that 88% of passwords used in successful cyberattacks were 12 characters or less.