Symantec has been tracking a new intelligence-gathering campaign led by a group they’ve named Hydrochasma that has been targeting medical labs and shipping companies in Asia.
The U.S. Department of Defense was reported to have launched a probe on the public exposure of several U.S. military emails and data on a Microsoft Azure government cloud server, which was identified by security researcher Anurag Sen over the weekend, DefenseScoop reports.
BleepingComputer reports that Google has been collaborating with Android ecosystem partners to strengthen firmware security as it works to better defend other components of a system on a chip against potential exploitation.
Indian government agencies have been targeted by a spear-phishing campaign by the Pakistani threat group SideCopy distributing an updated ReverseRAT backdoor, The Hacker News reports.
Paul and Scott talk about supply chain threats, vulnerable drivers, leaked source code and keys, and cover what we know about the OpenSSL 3.x vulnerability. This segment is sponsored by Eclypsium. Visit https://securityweekly.com/eclypsium to learn more about them!
SecurityWeek reports that numerous Arris routers including the G2482A, SBG10, and TG2492 models running firmware version 9.1.103 which have reached end-of-life are being impacted by a remote code execution flaw, tracked as CVE-2022-45701.
Increased government pressure and the emergence of software bill of materials have prompted a reduction in published vulnerabilities in extended Internet of Things devices since 2021 even as the flaws have been increasingly self-reported by device manufacturers rather than independent researchers, SecurityWeek reports.
Threat actors could chain two critical security vulnerabilities in Schneider Electric's Unity line of Modicon programmable logic controllers, tracked as CVE-2022-45788 and CVE-2022-45789, to compromise safety protections for limiting physical damage, according to The Record, a news site by cybersecurity firm Recorded Future.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.