Latest Cybersecurity News and Articles


Ransomware Group Says it Stole Student Data From Minneapolis Public Schools

09 March 2023
On March 7, the Medusa ransomware group added the school district to its list of victims, giving them 10 days to pay a ransom before data stolen from the school was leaked.

Illegal 'DeepStreamer' movie streaming platforms hide lucrative ad fraud operation

09 March 2023
DeepStreamer used different techniques to evade detection and forge traffic by surreptitiously loading “money sites” filled with Google ads completely hidden from view, while internet users were watching movies.

Update: Dole doesn’t expect to recover full costs of ransomware attack

09 March 2023
During a conference call on Tuesday, company executives were asked whether they could recover any of the disruption amounts later in the year through supplier recovery or insurance coverage.

MedusaLocker Distributes GlobeImposter Ransomware via RDP

09 March 2023
ASEC researchers have reported the active distribution of the GlobeImposter ransomware by the threat actors behind MedusaLocker that used remote desktop protocols as an attack vector. Besides other malware, hackers also deployed an XMRig CoinMiner to compromised systems. Security experts suggest users should ensure that RDP is deactivated when not in use.

New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access

09 March 2023
Fortinet has released fixes to address 15 security flaws, including one critical vulnerability impacting FortiOS and FortiProxy that could enable a threat actor to take control of affected systems.

SeigedSec hacking group defaces Faroe Islands tourist website, but kept out of government systems

09 March 2023
A hacking group defaced the tourist website for the Faroe Islands – a self-governing territory of the Kingdom of Denmark — and claimed it stole employee data and other sensitive information.

Mistakes by Threat Actors Lead to Disruption, Not Just Better Blocking

09 March 2023
Threat actors really only stop when their infrastructure is disrupted and their flow of funds disappears, and this normally can only be achieved through the activities of U.S. law enforcement agencies and major commercial data hosting providers.

TSA Requires Aviation Sector to Enhance Cybersecurity Resilience

09 March 2023
Airport and aircraft operators are required to develop a plan for improving their resilience and preventing infrastructure disruption and degradation. In addition, they need to assess the effectiveness of their measures.

New ScrubCrypt Crypter Used in Cryptojacking Attacks Targeting Oracle WebLogic

09 March 2023
The infamous cryptocurrency miner group called 8220 Gang has been observed using a new crypter called ScrubCrypt to carry out cryptojacking operations. According to Fortinet FortiGuard Labs, the attack chain commences with successful exploitation of susceptible Oracle WebLogic servers to download a PowerShell script that contains ScrubCrypt. Crypters are a type of software that can encrypt,

New Security Flaws in Jenkins Could Allow Code Execution Attacks

09 March 2023
The flaws, tracked as CVE-2023-27898 and CVE-2023-27905, impact the Jenkins server and Update Center, and have been collectively christened CorePlague by cloud security firm Aqua. All versions of Jenkins versions prior to 2.319.2 are vulnerable.

New Critical Flaw in FortiOS and FortiProxy Could Give Hackers Remote Access

09 March 2023
Fortinet has released fixes to address 15 security flaws, including one critical vulnerability impacting FortiOS and FortiProxy that could enable a threat actor to take control of affected systems. The issue, tracked as CVE-2023-25610, is rated 9.3 out of 10 for severity and was internally discovered and reported by its security teams. "A buffer underwrite ('buffer underflow') vulnerability in

Purpose, direction and innovation: The mindset of a successful leader

08 March 2023
In her role as president and co-founder of Six Degrees Consulting, Molly actively oversees strategy, vision, marketing, professional services, human resources, and day-to-day operations. The company’s mission is to solve clients’ IT operational challenges and anticipate future needs, yet Molly has found that its true value to clients is the honesty and passion found in […] The post Purpose, direction and innovation: The mindset of a successful leader appeared first on CyberTalk.

Report: Collaboration is key to security optimization

08 March 2023
Report reveals good relationships, strong communication, & transparency are key factors in security collaborative optimization success.

TSA issues new cybersecurity measures to better defend airlines

08 March 2023
TSA has issued a new cybersecurity amendment. as part of the Department of Homeland Security’s efforts to increase cybersecurity resilience.

Qakbot Strikes Again With New Delivery Method; Puts Millions of Devices at Risk

08 March 2023
Researchers at Trellix Advanced Research Center have detected various campaigns that use OneNote documents to distribute Qakbot and other malware such as AsyncRAT, Icedid, and XWorm.

Sharp Panda Targets Southeast Asian Governments Using Evolved Soul Malware Framework

08 March 2023
It uses spear-phishing emails for initial access, carrying malicious documents with government-themed lures. It further deploys the RoyalRoad RTF kit, allowing attackers to exploit older vulnerabilities for further infection.

SYS01 Campaign Uses Multiple Attack Evasion Tactics; Stayed Invisible for Five Months

08 March 2023
Morphisec researchers have been tracking this info-stealer since November 2022. This campaign uses lures and loading tactics similar to another info-stealer named S1deload, however, the final payload delivered is different.

Netherlands: Qilin Ransomware Breaches Elderly Care Facility and Leaks Confidential Data Online

08 March 2023
The attack occurred on February 17, causing technical difficulties for the facility. The care institution announced the breach via its website and attributed the problem to a group that had gained unauthorized access to its network.

TikTok unveils European data security plan amid calls for US ban

08 March 2023
TikTok unveils European data security plan amid calls for US ban Move comes as White House backs bill that could give it power to ban Chinese-owned app nationwideTikTok has announced a data security regime for protecting user information across Europe, as political pressure increases in the US to ban the social video app.The plan, known as Project Clover, involves user data being stored on servers in Ireland and Norway at an annual cost of €1.2bn (£1.1bn), while any data transfers outside Europe will be vetted by a third-party IT company. Continue reading...

Update: Israel blames state-sponsored Iranian hackers for ransomware attack on university

08 March 2023
The attack in February forced the Israel Institute of Technology (Technion) to postpone exams and shut down its IT systems. The incident followed what Israeli defense officials said were dozens of attempted Iranian cyberattacks over the past year.