The Cybersecurity and Infrastructure Security Agency has temporarily omitted the Windows Local Security Authority Spoofing flaw, tracked as CVE-2022-26925, from its Known Exploited Vulnerability Catalog following a problematic fix issued by Microsoft, reports ZDNet.
BleepingComputer reports that nearly 3% of 2.8 million pages included in the 100,000 top ranking websites worldwide have been found to leak information entered in site forms including usernames, email addresses, passwords, and personal identifiers to third-party trackers prior to submission.
Malware could be loaded into the Bluetooth chips of iPhones and could be executed even if the devices are turned off through a new attack surface discovered by researchers at the Technical University of Darmstadt's Secure Mobile Networking Lab, according to The Hacker News.
Novel link-layer Bluetooth Low Energy relay attacks that could evade mitigations and protections including encrypted link layer, detectable latency levels, and localization approaches could be performed by a new tool developed by NCC Group researchers, SecurityWeek reports.
The Register reports that the U.S. has sentenced Glib Oleksandr Ivanov-Tolpintsev to four years imprisonment for his involvement in the sale of stolen credentials across over 6,700 compromised servers.
Three security vulnerabilities impacting SonicWall's Secure Mobile Access 1,000 appliances, one of which is a high-severity authentication bypass flaw, have been detailed as part of a warning from SonicWall, reports The Hacker News.
SecurityWeek reports that malicious actors could exploit a medium-severity vulnerability in Siemens Desigo PXC4.E16 programmable building automation controllers that could make the device unavailable for days.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.