Latest Cybersecurity News and Articles
09 March 2023
Russia-linked TA499 threat actor has been aggressively conducting email campaigns to target high-profile European and North American government authorities and CEOs of reputable organizations. The attack begins with an email or phone call, masquerading as prominent political figures. The phone call recordings are then released to the public via YouTube and RuTube.
09 March 2023
In the attacks observed by ASEC, successful exploitation of the flaws is followed by the execution of a PowerShell command that retrieves an executable and a DLL file from a remote server.
09 March 2023
The threat intelligence vendor Flashpoint warned that threat actors are increasingly combining known vulnerabilities, stolen credentials, and exposed data to wreak maximum damage.
09 March 2023
Suspected Chinese cybercriminals have zeroed in on unpatched SonicWall gateways and are infecting the devices with credential-stealing malware that persists through firmware upgrades, according to Mandiant.
09 March 2023
Theft deterrent software has been developed by Hyundai and Kia following online videos detailing how to start and steal the vehicles without a key.
09 March 2023
The London-based company said Series B financing was led by Eurazeo, a French investment and asset management firm. Ten Eleven Ventures, a prior backer, also expanded its equity stake.
09 March 2023
Bitwarden's credentials autofill feature contains a risky behavior that could allow malicious iframes embedded in trusted websites to steal people's credentials and send them to an attacker.
09 March 2023
Meet the founder and CEO of ReynCon, Connie Matthews Reynolds. With more than two decades of experience in the cyber security industry, she has received much recognition for her work. As a founding member of EmpoWE-R Women of InfoSec, she encourages women and minorities to consider careers in cyber security and lives by the motto […]
The post Empowering women in cyber security: A CEO’s perspectives appeared first on CyberTalk.
09 March 2023
Security vulnerabilities in remote desktop programs such as Sunlogin and AweSun are being exploited by threat actors to deploy the PlugX malware.
AhnLab Security Emergency Response Center (ASEC), in a new analysis, said it marks the continued abuse of the flaws to deliver a variety of payloads on compromised systems.
This includes the Sliver post-exploitation framework, XMRig cryptocurrency
09 March 2023
An interior ministry spokesperson on Tuesday confirmed that the German government was carrying out a general review of telecoms tech suppliers, but said that this was not directed at specific manufacturers.
09 March 2023
An unauthenticated attacker can exploit the vulnerability to obtain the credentials stored in the VeeamVBR configuration database and use them to access backup infrastructure hosts.
09 March 2023
The Series B round was led by Energy Impact Partners and Paladin Capital Group, along with participation from KPN Ventures, Lapa Capital Partners, Lanx Capital, and Cisco Investments.
09 March 2023
A previously known Windows-based ransomware strain known as IceFire has expanded its focus to target Linux enterprise networks belonging to several media and entertainment sector organizations across the world.
The intrusions entail the exploitation of a recently disclosed deserialization vulnerability in IBM Aspera Faspex file-sharing software (CVE-2022-47986, CVSS score: 9.8), according to
09 March 2023
ScrubCrypt obfuscates and encrypts applications and makes them able to dodge security programs. It has an updated version, and the seller’s webpage guarantees that it can bypass Windows Defender and provide anti-debug and some bypass functions.
09 March 2023
Michael Pezullo, currently serving as the secretary of the Department of Home Affairs, said the Russian Federation hosted “the greatest density of cybercriminals, particularly those with ransomware,” in the world.
09 March 2023
LSA protection is crucial for safeguarding against the theft of sensitive information or login credentials by blocking untrusted code injection into the LSA process and blocking process memory dumping.
09 March 2023
Phishing, the theft of users' credentials or sensitive data using social engineering, has been a significant threat since the early days of the internet – and continues to plague organizations today, accounting for more than 30% of all known breaches. And with the mass migration to remote working during the pandemic, hackers have ramped up their efforts to steal login credentials as they take
09 March 2023
Iranian state-sponsored actors are continuing to engage in social engineering campaigns targeting researchers by impersonating a U.S. think tank.
"Notably the targets in this instance were all women who are actively involved in political affairs and human rights in the Middle East region," Secureworks Counter Threat Unit (CTU) said in a report shared with The Hacker News.
The cybersecurity
09 March 2023
The FBI is investigating a data breach affecting U.S. House of Representatives members and staff after their account and sensitive personal information was stolen from DC Health Link's servers.
09 March 2023
To help tackle the skills deficit in cloud security, the SANS Institute and Google have launched a new academy focused on providing scholarship-based training for underrepresented groups.