Latest Cybersecurity News and Articles
10 March 2023
Media and entertainment sector organizations worldwide are under attack by the threat actor using the Linux version of the IceFire ransomware. SentinelLabs first made this observation and found that criminals abused a deserialization bug in IBM Aspera Faspex file sharing software, tracked as CVE-2022-47986. Its Windows version is known to spread via phishing messages.
10 March 2023
EXECUTIVE SUMMARY: Let’s out-innovate ransomware! Thanks to the latest technological advancements and expert insights, you might be closer to achieving this goal than you think. Stop next-generation attacks and their culprits. In the past 30 years, ransomware attacks have proliferated at a dizzying pace, victimizing millions of organizations and causing billions of dollars in losses. […]
The post Top insights from the most notorious ransomware attacks & attackers appeared first on CyberTalk.
10 March 2023
The Imperva Red Team discovered a vulnerability affecting the world’s largest NFT marketplace, OpenSea. It is a cross-site search (XS-Search) vulnerability that can be exploited by an attacker to obtain a user’s identity.
10 March 2023
The budget proposes $3.1 billion for the CISA. This includes “$98 million to implement the Cyber Incident Reporting for Critical Infrastructure Act,” as well as “$425 million to improve CISA’s internal cybersecurity and analytical capabilities.”
10 March 2023
If a malicious hacker were to discover the flaw, they could exploit it to access customer data, steal the company’s source code, and look for other vulnerabilities to exploit.
10 March 2023
This line of credit will further strengthen the company's financial position as it continues on its mission to be the first and only solution provider to verify 100% of good identities in real-time and eliminate identity fraud on the internet.
10 March 2023
Prometei, first observed in 2016, is a modular botnet that features a large repertoire of components and several proliferation methods, some of which also include the exploitation of ProxyLogon Microsoft Exchange Server flaws.
10 March 2023
They do this using custom-created gaming apps that promise huge financial rewards directly proportional to investments to potential targets they've established trust with beforehand in lengthy online conversations.
10 March 2023
Zscaler ThreatLabz has identified significant code similarities between Nevada and Nokoyawa ransomware including debug strings, command-line arguments, and encryption algorithms
10 March 2023
EXECUTIVE SUMMARY: Hackers harvest, weaponize and sell corporate and personal passwords in order to obtain financial reward, damage reputations, steal intellectual property, or for other illegal undertakings. According to cyber security researchers, 80% of hacks involve the theft or reuse of employee passwords. This is in no small part due to lack of employee education […]
The post 20 password management best practices 2023 appeared first on CyberTalk.
10 March 2023
A North Korean espionage group tracked as UNC2970 has been observed employing previously undocumented malware families as part of a spear-phishing campaign targeting U.S. and European media and technology organizations since June 2022.
10 March 2023
The 2023 Security 360: Annual Trends Report by Jamf examines the top security threats that impact devices used in the modern workplace.
10 March 2023
The 2023 Security 360: Annual Trends Report by Jamf examines the top security threats that impact devices used in the modern workplace.
10 March 2023
About 92% of organizations have fallen victim to successful phishing attacks in the last 12 months, while 91% of organizations have admitted to experiencing email data loss, according to Egress.
10 March 2023
An updated version of a botnet malware called Prometei has infected more than 10,000 systems worldwide since November 2022.
The infections are both geographically indiscriminate and opportunistic, with a majority of the victims reported in Brazil, Indonesia, and Turkey.
Prometei, first observed in 2016, is a modular botnet that features a large repertoire of components and several proliferation
10 March 2023
A suspecting China-linked hacking campaign has been observed targeting unpatched SonicWall Secure Mobile Access (SMA) 100 appliances to drop malware and establish long-term persistence.
"The malware has functionality to steal user credentials, provide shell access, and persist through firmware upgrades," cybersecurity company Mandiant said in a technical report published this week.
The
10 March 2023
The company pointed out that the attack was intense and short-lived, with most attack traffic bursting during the peak minute of the attack. The overall attack lasted only a few minutes.
10 March 2023
A coordinated international law enforcement exercise has taken down the online infrastructure associated with a cross-platform remote access trojan (RAT) known as NetWire.
Coinciding with the seizure of the sales website www.worldwiredlabs[.]com, a Croatian national who is suspected to be the website's administrator has been arrested. While the suspect's name was not released, investigative
10 March 2023
In 2022 there was a significant increase in API-related CVEs, growing +78% from H1 to H2. Although growth has stabilized over the past two quarters, the research team at Wallarm expects an increase in 2023.
10 March 2023
Named "Xenomorph 3rd generation" by the Hadoken Security Group, the threat actor behind the operation, the updated version comes with new features that allow it to perform financial fraud in a seamless manner.