Latest Cybersecurity News and Articles


Ransomware Roundup – Sirattacker and ALC Ransomware

07 March 2023
Sirattacker is one of the latest Chaos ransomware variants. It was first released in the middle of February 2023. ALC is a recently reported ransomware. It is known for a message aimed at “Russia and its counterpart” in its ransom note.

Almost Half of Industrial Sector Computers Affected By Malware in 2022

07 March 2023
Two out of every five (40.6%) operational technology (OT) computers used in industrial settings have been affected by malware in 2022. The data comes from a report published earlier today by security researchers at Kaspersky.

Old Windows ‘Mock Folders’ UAC bypass used to drop malware

07 March 2023
A new phishing campaign targets organizations in Eastern European countries with the Remcos RAT malware with aid from an old Windows User Account Control bypass discovered over two years ago.

The Role of Marketing and PR in Incident Response

07 March 2023
Clear communication is essential. Communication strategies differ before and after a cyber incident. The way a company approaches both is as important as incident mitigation itself.

Vulnerability in DJI drones may reveal pilot’s location

07 March 2023
The researchers informed DJI of the 16 detected vulnerabilities prior to releasing the information to the public. In the course of the responsible disclosure process, the manufacturer has fixed these issues.

Suprbay.org, The Pirate Bay Web Forum Down amid Cyberattack

07 March 2023
The official forum of The Pirate Bay is the latest victim of an apparent cyberattack that forced its site to remain offline for several days. The forum allows users to request torrent reseeding and report malware found in torrent files.

Scammers Pose as ChatGPT in New Phishing Scam

07 March 2023
Bitdefender researchers have discovered a new phishing scam in which cybercriminals are redirecting unsuspecting users to a fake ChatGPT version. The primary targets were found in Ireland, Australia, Germany, Denmark, and the Netherlands.

Microsoft and MITRE developed a tool to prepare security teams for attacks on ML systems

07 March 2023
A new plug-in, created by Microsoft and MITRE, integrates various open-source software tools to aid cybersecurity professionals in bolstering their defenses against attacks on machine learning (ML) systems.

Update: Ransomware gang leaks data stolen from City of Oakland

07 March 2023
The Play ransomware gang has begun to leak data from the City of Oakland, California. The initial data leak consists of a 10GB multi-part RAR archive allegedly containing confidential documents, employee information, passports, and IDs.

Shein's Android App Caught Transmitting Clipboard Data to Remote Servers

07 March 2023
An older version of Shein's Android application suffered from a bug that periodically captured and transmitted clipboard contents to a remote server. The Microsoft 365 Defender Research Team said it discovered the problem in version 7.9.2 of the app that was released on December 16, 2021. The issue has since been addressed as of May 2022. Shein, originally named ZZKKO, is a Chinese online fast

LastPass Hack: Engineer's Failure to Update Plex Software Led to Massive Data Breach

07 March 2023
The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what's a sobering reminder of the dangers of failing to keep software up-to-date. The embattled password management service last week revealed how unidentified actors leveraged information stolen from an earlier incident that took place prior to August 12, 2022, along with

The evolving sophistication of social engineering attacks

06 March 2023
By Anas Baig, product manager and cyber security expert with Securiti. A social engineering attack is a type of cyber attack in which a threat actor attempts to manipulate people into performing certain actions or divulging confidential information, such as passwords and credit card details. These attacks often target unsuspecting users who do not realize […] The post The evolving sophistication of social engineering attacks appeared first on CyberTalk.

After Clasiopa, APT41 Targets Asian Materials Sector

06 March 2023
Symantec warned against the Chinese state-sponsored Winnti, aka APT41 and Blackfly, hacker group targeting two subsidiaries of an Asian conglomerate in the materials sector. The operation ran from late 2022 to early 2023, with a focus on intellectual property theft. Symantec has provided IOCs to detect and mitigate any threat due to the malicious activity of the Blackfly group.

Digital Smoke: Massive Investment Fraud Scam

06 March 2023
Resecurity identified Digital Smoke, one of the largest investment scam networks, that has been defrauding netizens mostly from Europe, Asia, and Australia. The attackers impersonate Fortune 100 firms from the U.S. and the U.K. Most of the fraudulent schemes pertained to financial services, EV and EV batteries, oil & gas, renewable energy, healthcare, semiconductors, as well as internationally renowned investment corporations and funds with global footprint.

Multi-Year Spearphihing Campaign Against Maritime Industry

06 March 2023
EclecticIQ has revealed that a single connected threat cluster is most likely behind an attack campaign targeting the maritime industry with spearphishing emails to distribute different malware threats. In July 2022, the campaign shifted from Agent Tesla to Formbook using CAB file attachments. However, there’s not much clarity on why the cluster changed its tooling.

CISA red-teamed a ‘large critical infrastructure’ organization, no one noticed

06 March 2023
EXECUTIVE SUMMARY: In recent years, protecting critical infrastructure entities has been synonymous with ensuring the continued operations of governments and economies. In the United States, a CISA Red Team was recently granted permission to conduct a stealthy three-month attack on a critical infrastructure organization to assess the group’s cyber security posture. The Red Team gained […] The post CISA red-teamed a ‘large critical infrastructure’ organization, no one noticed appeared first on CyberTalk.

LockBit Introduces New Method to Bypass MOTW Protection

06 March 2023
Researchers uncovered a new LockBit ransomware campaign last December and January using a novel technique involving the use of a .img container to bypass the Mark of The Web (MOTW) protection mechanism. LockBit remained one of the most active ransomware families in successful RaaS and extortion attacks for the second and third quarters of 2022.

New Feature-Rich Post-Exploitation Tool 'Exfiltrator-22' Linked With LockBit

06 March 2023
Hackers in the underground marketplace have introduced a new Exfiltrator-22, or EX-22, post-exploitation framework. According to the CYFIRMA team, LockBit 3.0 affiliates or its members are most probably behind its development. The developers have used the same C2 infrastructure previously exposed in a LockBit 3.0 sample. In the latest instance, criminals displayed lateral movement and ransomware-spreading capabilities.

Vulnerabilities of years past haunt organizations, aid attackers

06 March 2023
According to a Tenable report, the number one group of most frequently exploited vulnerabilities represents a large pool of known vulnerabilities, some of which were originally disclosed as far back as 2017.

RIG EK Achieves Lifetime High Success Rate with Old IE Bugs

06 March 2023
RIG EK continues to make its mark as a successful exploit kit as it attempted to make roughly 2,000 intrusions daily, with the highest attack success rate of its lifetime of 30%. By exploiting relatively old Internet Explorer vulnerabilities, the exploit kit has been seen distributing various types of malware such as Dridex, SmokeLoader, and Raccoon Stealer.