Nozomi Networks researchers discovered that the firmware of Lanner Electronics' IAC-AST2500 baseboard management controllers is being impacted by 13 security vulnerabilities, which could be exploited to enable remote attacks against operational technology and internet of things networks, reports The Hacker News.
The Hacker News reports that threat actors have been spreading the SharkBot banking trojan through fraudulent file manager apps on the Google Play Store in an effort to evade security restrictions of the app marketplace.
No major Android device manufacturers including Samsung, Oppo, and Xiaomi have issued any updates addressing five medium-severity security vulnerabilities in Arm's Mali GPU driver, even though the flaws have been fixed by Arm from July to August, SiliconAngle reports.
Cyberespionage operation Bahamut has leveraged fake VPN apps in a malicious campaign targeted at exfiltrating sensitive data from Android devices, according to The Hacker News.
Threats to national security have prompted the U.S. Federal Communications Commission to ban sales or imports of equipment from Chinese telecommunications firms Huawei Technologies, ZTE, and Hytera Communications, as well as Chinese surveillance manufacturers Dahua Technology and Hangzhou Hikvisionn Digital Technology, according to Reuters.
Bots and scams have been increasingly used by cybercriminals amid the holiday shopping season, reports The Record, a news site by cybersecurity firm Recorded Future.
Researchers at Proofpoint revealed more technical details about SocGholish, the malware variant they identified earlier this month, highlighting its noteworthy tactics that differ from traditional phishing campaigns.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.