> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape reveals significant threats and trends. Bitdefender has identified preinstalled Android malware, "Midnight Mimosa," affecting cheap MediaTek devices in 150 countries, which engages in click fraud and botnet activities. Additionally, a malware incident at Nippon Columbia has compromised 8.7 million records of karaoke enthusiasts, showcasing the ongoing risks of data breaches. In infrastructure security, AI systems are increasingly being recognized for their potential to execute sophisticated attacks, raising alarms about preparedness. U.S. CISA has updated its Known Exploited Vulnerabilities catalog with critical flaws in several applications, emphasizing the need for timely patching. Meanwhile, new insights into facial recognition vulnerabilities reveal risks even when individuals are partially obscured.
|
// AI-powered summary generated at 16:01
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- x86 architecture;
- Compute Acceleration Framework;
- Bus device...
New research has uncovered that publishers of over 100 Visual Studio Code (VS Code) extensions leaked access tokens that could be exploited by bad actors to update the extensions, posing a critical software supply chain risk.
"A leaked VSCode Marketplace or Open VSX PAT [personal access token] allow...
As the leader in WordPress security, Wordfence provides unparalleled security coverage that fully encompasses protection, active monitoring, detection, and response all built around our threat intelligence, demonstrating a strong commitment to security. Our mission is to ensure comprehensive defense...
An advanced persistent threat (APT) group, Flax Typhoon, was able to gain persistent access to the mapping tool ArcGIS for over a year, putting several enterprises at risk.
ArcGIS is a geospatial platform developed by ESRI, often relied upon by organizations to understand a...
Scientists have revealed a gaping hole in global telecom security, intercepting personal and business data from geostationary satellites.
Artificial Intelligence (AI) is advancing at a pace that outstrips traditional security frameworks. Generative AI has already changed how financial institutions analyze data, create insights and engage with customers. The next frontier, agentic AI, is even more transformative....
TLDR
Even if you take nothing else away from this piece, if your organization is evaluating passkey deployments, it is insecure to deploy synced passkeys.
Synced passkeys inherit the risk of the cloud accounts and recovery processes that protect them, which creates material enterprise exposure.
Adv...
Apple is now offering a $2M bounty for a zero-click exploit. According to the Apple website:
Today we’re announcing the next major chapter for Apple Security Bounty, featuring the industry’s highest rewards, expanded research categories, and a flag system for researchers to objectively demonstrate v...
ICO makes example of outsourcing giant over sluggish cyber response The UK's Information Commissioner's Office (ICO) has issued a £14 million ($18.6 million) penalty to outsourcing giant Capita following a catastrophic 2023 cyberattack that exposed the personal data of 6.6 million people.…
Spanish fashion retailer MANGO has warned customers that there has been a data breach.
PhantomVAI is a new loader used to deploy multiple infostealers. We discuss its overall evolution and use of steganography and obfuscated scripts.
The post PhantomVAI Loader Delivers a Range of Infostealers appeared first on Unit 42.
Microsoft has fixed over 170 CVEs in October’s Patch Tuesday, including six zero-day vulnerabilities
An estimated 100 million people live with facial differences. As face recognition tech becomes widespread, some say they’re getting blocked from accessing essential systems and services.
Microsoft on Tuesday released fixes for a whopping 183 security flaws spanning its products, including three vulnerabilities that have come under active exploitation in the wild, as the tech giant officially ended support for its Windows 10 operating system unless the PCs are enrolled in the Extende...
Could a simple call to the helpdesk enable threat actors to bypass your security controls? Here’s how your team can close a growing security gap.
Outsourcing giant Capita has been fined £14m by the ICO after a major data breach in 2023
At Sophos, we're proud to champion the next generation of women in tech by creating early opportunities, fostering confidence, and supporting inclusive initiatives that empower girls to explore and thrive in technology.
Investigations found that the network operates scam centers in Cambodia, Myanmar and across Southeast Asia
Affected software updated with new package information.
Affected software updated with new package information.