Malicious Android apps have been signed by threat actors through the exploitation of platform certificates used by device vendors Samsung, LG, and MediaTek, The Hacker News reports.
The Cybersecurity and Infrastructure Security Agency has warned that several vulnerabilities in the Mitsubishi Electric GX Works3 engineering workstation software for industrial control system environments could be exploited to enable access to certain CPU and OPC UA modules, as well as prompt program viewing and execution, according to The Hacker News.
BleepingComputer reports that U.S. cloud computing firm Rackspace Technology was impacted by a security incident that prompted an outage of its hosted Microsoft Exchange environments, which may have affected thousands of customers.
Facebook credentials belonging to more than 300,000 users across 71 countries have been compromised by the Android threat campaign dubbed "Schoolyard Bully Trojan," reports The Hacker News.
Password management provider 1Password has unveiled a new browser extension with automated login saving, storing, and autofilling capabilities in a bid to advance passwordless authentication amid the growing prevalence of credential theft, VentureBeat reports.
Red Hat's Quarkus Java framework has been discovered by Contrast Security researchers to contain a critical security flaw, which could be exploited to facilitate remote code execution even by attackers without any privileges, according to The Hacker News.
In a discussion with FDA official, Sen. Mark Warner shared his biggest healthcare cybersecurity concerns, what’s needed for his incentive program, and calls for a reset on security mindsets.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.