Latest Cybersecurity News and Articles


US Senators Aim to Block Foreign Tech That Poses Threat

08 March 2023
Analysis in 2021 by The Citizen Lab concluded that TikTok collects types of data similar to what other social media platforms collect - and also said that "the general privacy standards for social platforms is not a high bar."

Senators introduce foreign technology legislation

08 March 2023
The RESTRICT Act was introduced to Congress to address the potential threat of technology from foreign adversaries to improve national cybersecurity.

Lazarus Group Exploits Zero-Day Vulnerability to Hack South Korean Financial Entity

08 March 2023
The North Korea-linked Lazarus Group has been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice within a span of a year.

Jenkins Security Alert: New Security Flaws Could Allow Code Execution Attacks

08 March 2023
A pair of severe security vulnerabilities have been disclosed in the Jenkins open source automation server that could lead to code execution on targeted systems. The flaws, tracked as CVE-2023-27898 and CVE-2023-27905, impact the Jenkins server and Update Center, and have been collectively christened CorePlague by cloud security firm Aqua. All versions of Jenkins versions prior to 2.319.2 are

Northern Essex Community College Remains Shuttered After Cyberattack

08 March 2023
A spokesperson for the school told The Record that they did not know if the attack was ransomware, and claimed they “do not have evidence of any personal data being compromised.” On Tuesday, the school confirmed it would not open for the day.

Chrome 111 Patches 40 Vulnerabilities

08 March 2023
A total of 24 of the addressed security defects were reported by external researchers. These include eight high-severity flaws, 11 medium-severity bugs, and five low-severity issues.

Vulnerability in Toyota Management Platform Provided Access to Customer Data

08 March 2023
A severe vulnerability in the Toyota Customer 360 customer relationship management (CRM) platform allowed a security researcher to access the personal information of the car maker’s customers in Mexico.

Exploitation of Bitrix CMS Vulnerability Drives ICS Attack Surge in Russia

08 March 2023
The exploited vulnerability, tracked as CVE-2022-27228, affects the ‘Polls, Votes’ module of the Bitrix Site Manager application. The security hole allows a remote, unauthenticated attacker to execute arbitrary code.

Security leaders discuss how to make space for women in the workplace

08 March 2023
For the 113th International Women’s Day, Security Magazine is sharing stories and suggestions from women in security leadership positions. 

Insurance holding company Group 1001 says operations restored after ransomware attack

08 March 2023
The February 9 attack disrupted operations at several member companies, including Delaware Life Insurance; Delaware Life Insurance Company of New York; Clear Spring Life and Annuity; Clear Spring Property and Casualty; and Clear Spring Health.

NIST Renews Cyber Center Partnership, Launches Small Business Focus

08 March 2023
The NIST strengthened its cybersecurity efforts on Tuesday by renewing its partnerships with the state of Maryland and Montgomery County that underpin the National Cybersecurity Center of Excellence (NCCoE).

3 ways to support women in the cybersecurity field

08 March 2023
Shikha Kothari, Principal Security Advisor at Eden Data, shares strategies for cybersecurity leaders to create supportive work environments for women.

New Malware Variant Used by Chinese Hackers has “Radio Silence” Mode to Evade Detection

08 March 2023
The new Sharp Panda campaign uses spear-phishing emails with malicious DOCX file attachments that deploy the RoyalRoad RTF kit to attempt to exploit older vulnerabilities to drop malware on the host.

Hackers are quickly learning how to breach cloud systems

08 March 2023
Attacks exploiting cloud systems nearly doubled in 2022, and the number of hacking groups that can target the cloud tripled last year, according to a CrowdStrike report released last week.

Malicious PyPI Package Delivers Colour-Blind RAT

08 March 2023
Security researchers at Kroll laid bare a malicious PyPI package called Colour-Blind. The malware package is a fully-featured info-stealer RAT with a plethora of features and capabilities, including the theft of crypto wallet data. According to researchers, the malware "points to the democratization of cybercrime" to help adversaries develop their own variations based on the shared source code.

Syxsense Platform: Unified Security and Endpoint Management

08 March 2023
As threats grow and attack surfaces get more complex, companies continue to struggle with the multitude of tools they utilize to handle endpoint security and management. This can leave gaps in an enterprise's ability to identify devices that are accessing the network and in ensuring that those devices are compliant with security policies. These gaps are often seen in outdated spreadsheets that

Russia-Aligned TA499 Beleaguers Targets with Video Call Requests

08 March 2023
The threat actor’s campaigns attempt to convince high-profile North American and European government officials as well as CEOs of prominent companies and celebrities into participating in recorded phone calls or video chats.

ATM Malware FiXS Targets Mexican Banks to Dispense Quick Money

08 March 2023
Security analysts at Metabase Q uncovered the new FiXS ATM malware that targets Mexican bank customers. Though the initial attack vector is unclear as of now, analysts have discovered hackers using an external keyboard, like in Ploutus attacks. The FiXS malware releases money 30 minutes after the latest ATM reset, leveraging the Windows GetTickCount API.

Chinese State-Sponsored Hackers Break Into Mail Servers Used by ASEAN Members

08 March 2023
The Chinese threat actors reportedly leveraged “valid credentials” to compromise ASEAN’s Microsoft Exchange servers, which used mail.asean.org and auto.discover.asean.org domains.

Celebrating International Women’s Day: Creating awareness & driving change

08 March 2023
Ulrica is a VP of Product & Strategy at Indeni with over 30 years experience developing software in networking & security technologies. She loves explaining complex technology and building high-profile and high-performing teams.  In this exclusive CyberTalk interview, Ulrica shares a bit about how her passion for technology and solving challenging customer problems has driven […] The post Celebrating International Women’s Day: Creating awareness & driving change appeared first on CyberTalk.