Latest Cybersecurity News and Articles
14 March 2023
A Chrome Extension offering quick access to fake ChatGPT functionality was found to be hijacking Facebook accounts and installing hidden account backdoors. Notably, the Facebook app “backdoor” gives the threat actors super-admin permissions.
14 March 2023
By Deryck Mitchelson, Field CISO EMEA, Check Point Software Technologies. Cyber complexity can impede efforts to secure systems. In particular, cyber security complexity increases risks, drives high costs, and can result in sub-par decision-making. By pursuing a simplification agenda, leaders can build true cyber security resilience. Reducing complexity means focusing on operational overlap, on duplication and […]
The post Increasing infrastructure security by reducing complexity appeared first on CyberTalk.
14 March 2023
Reports published in the past couple of months by various industrial cybersecurity companies provide different numbers when it comes to the vulnerabilities discovered in industrial control system (ICS) products in 2022.
14 March 2023
GSC Game World says it has been enduring cyberattacks for ‘more than a year’ and that hackers demand Russia-friendly changes to the game or else they’ll leak tons of the game’s development materials.
14 March 2023
A new Golang-based malware dubbed GoBruteforcer has been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a botnet.
"GoBruteforcer chose a Classless Inter-Domain Routing (CIDR) block for scanning the network during the attack, and it targeted all IP addresses within that CIDR range," Palo Alto Networks Unit 42 researchers said.
"The threat actor
14 March 2023
GitHub has added SMS support and fresh account lockout prevention features to its phased rollout plans as it prepares to implement a 2FA requirement for accounts beginning Monday.
14 March 2023
Today, the LockBit ransomware is the most active and successful cybercrime organization in the world. Attributed to a Russian Threat Actor, LockBit has stepped out from the shadows of the Conti ransomware group, who were disbanded in early 2022.
LockBit ransomware was first discovered in September 2019 and was previously known as ABCD ransomware because of the ".abcd virus" extension first
14 March 2023
According to PeckShield, hackers exploited Euler “in a flurry of transactions” which led to the theft of around $197 million in crypto. Crypto security firm BlockSec also reported the attack.
14 March 2023
Cyberattacks and fraud are now too closely linked to be considered separately. But many firms still have investigative fraud teams and cybersecurity teams operating independently, along with the systems and processes that support them.
14 March 2023
The Clop ransomware gang has begun extorting companies whose data was stolen using a zero-day flaw in the Fortra GoAnywhere MFT secure file-sharing solution. The extortion group said they used the flaw over ten days to steal data from 130 companies.
14 March 2023
Makop ransomware operations are based on the human operator ransomware practice where most of the intrusion is handled by hands-on keyboard criminals, even in the encryption stage.
14 March 2023
An open source adversary-in-the-middle (AiTM) phishing kit has found a number of takers in the cybercrime world for its ability to orchestrate attacks at scale.
Microsoft Threat Intelligence is tracking the threat actor behind the development of the kit under its emerging moniker DEV-1101.
An AiTM phishing attack typically involves a threat actor attempting to steal and intercept a target's
14 March 2023
The zero-day flaw in question is CVE-2022-41328 (CVSS score: 6.5), a medium security path traversal bug in Fortinet's FortiOS that could lead to arbitrary code execution.
14 March 2023
The attacks were aimed at stealing personal or business information used by customers to carry out online transactions, and the information was then used to conduct scams such as canceling installment payment setups, according to the CIB.
14 March 2023
Hawaii’s Department of Health says it is sending out breach notification letters after a cyberattack in January gave hackers limited access to the state’s death registry.
14 March 2023
According to its data breach notice, HACLA discovered on December 31, 2022, that files on its computer systems were encrypted. This prompted the agency to shut down its servers and launch an investigation.
14 March 2023
Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result in data loss and OS and file corruption.
"The complexity of the exploit suggests an advanced actor and that it is highly targeted at governmental or government-related targets," Fortinet researchers Guillaume Lovet and Alex Kong said in an
13 March 2023
Top security officials from the U.S., Canada, New Zealand and Singapore amongst speakers for CYBERUK 2023 announced today.
13 March 2023
EXECUTIVE SUMMARY: Around the globe, cyber risks are intensifying. Responding to these growing challenges requires developing new partnerships, encouraging inter-departmental collaboration, pursuing innovative cyber security solutions, and promoting employee security awareness and engagement, among other things. In honing in on employee engagement, new survey findings suggest that there is a significant disconnect between CISO expectations […]
The post A shocking truth: One in five government employees, indifferent to workplace hacks appeared first on CyberTalk.
13 March 2023
GoBruteforcer, a new Golang-based botnet, has been seen scanning and infecting well-known web servers including FTP and MySQL, and deploys an IRC bot to communicate. At the time of the attack, GoBruteforcer uses a Classless Inter-Domain Routing (CIDR) block for scanning the network. The best way to avoid threats originating from brute forcers is to change default passwords and implement a strong password policy including 2FA.