BleepingComputer reports that Windows Subsystem for Linux has been increasingly leveraged by threat actors as an attack surface for new malware development.
Android devices could be compromised with a persistent backdoor should four high-severity security flaws in pre-installed Android System apps' mobile framework be exploited, according to SecurityWeek.
Mobile trojan detections have significantly increased in the first quarter of 2022 even though mobile malware volumes have dwindled since 2020, suggesting the increasing push toward more advanced threat campaigns, BleepingComputer reports.
New security vulnerabilities have been added by Keksec threat group, also known as Kek Security, FreakOut, and Necro, to its Enemybot Linux-based botnet to attack web servers, content management systems, and Android devices, reports The Hacker News.
This week’s breach roundup includes several hacks and a massive theft of paper records and is led by a followup into the March cyberattack and network outage incurred by Partnership HealthPlan of California in March.
This week in the AppSec News: Pwn2own results, reading the DBIR for appsec insights, XMPP flaws in Zoom, $10M bounty for a blockchain bridge vuln, researcher puts malicious payloads in ancient packages, Argo patches JWT handling, & more!
Threat actors have hijacked the PyPi package dubbed "ctx" and the "phpass" PHP package to facilitate AWS credential exfiltration, reports The Hacker News.
Sixty-five major cyberattacks against blockchain and decentralized platforms last year have resulted in $1.8 billion in losses, even though 90% of the intrusions were deemed to be "unsophisticated," ZDNet reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.