Threat actors have been exploiting a DLL hijacking vulnerability in the Windows 10 Control Panel executable in new phishing attacks deploying the QBot malware, also known as QakBot, reports BleepingComputer.
Deep Instinct researchers say just because security pros don’t see a prevalence of infections from a specific group, it doesn’t mean the threat actors aren’t maintaining a presence or monitoring devices.
Navigating the UEFI waters is treacherous. While UEFI has become the standard on most PCs, servers, and laptops, replacing legacy BIOS, it is a complex set of standards and protocols. Jesse joins us to help explain how some of this works and describe how vulnerabilities, specifically with SMM, can manifest and be exploited. Segment Resources: CHIPS...
A number of state attorneys general announced Monday the largest consumer privacy settlement in U.S. history as tech giant Google agreed to pay nearly $400 million over its location tracking practices.
An update to the much-lauded medical device cybersecurity playbook centers around preparedness and response plans, particularly for cyber incidents that impact medical devices.
Threat actors could leverage three security vulnerabilities in the LiteSpeed Web Server to facilitate arbitrary code execution with elevated privileges and achieve complete server takeovers, SecurityWeek reports.
The Hacker News reports that two Android apps Todo: Day manager and "経費キーパ" have been found to serve as Xenomorph banking malware droppers, with both apps already removed from the Google Play Store.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.