Numerous zero-day flaws in Windows, Google Chrome, and Mozilla Firefox were noted by Google's Threat Analysis Group to have been leveraged by Spanish custom security solutions provider Variston IT as a means to distribute spyware, TechCrunch reports.
Widespread gift card BEC attack detailed Cybercrime operation Lilac Wolverine has launched a massive gift card business email compromise attack, which lures targets into giving gift cards to individuals posing as seriously ill people or having lost relatives to illnesses, ZDNET reports.
Microsoft has revealed the general availability of built-in protection in Defender for Endpoint that would offer better threat protection for enterprise endpoints, according to BleepingComputer.
Enterprise networks compromised through the exploitation of a recently patched Fortinet vulnerability, tracked as CVE-2022-30684, are having their access sold by initial access brokers over the web, according to SecurityWeek.
Acer has released a BIOS update addressing a high-severity vulnerability, tracked as CVE-2022-4020, that could be exploited to enable UEFI Secure Boot deactivation on targeted devices, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.