Apple issued a slew of security updates this week, the most serious of which was for a zero-day vulnerability that has been actively exploited on iPhones and iPads.
Twenty-two percent of all brand phishing attempts around the world between July and September have been attributed to DHL, making the logistics firm the most impersonated brand in phishing emails in the third quarter, followed by Microsoft and LinkedIn, which was the most spoofed brand during the first two quarters of 2022, The Register reports.
Nearly a dozen types of cyberattacks could compromise computer numerical control machines used by many manufacturing facilities, according to SecurityWeek.
SecurityWeek reports that federal agencies have been ordered by the Cybersecurity and Infrastructure Security Agency to remediate within three weeks a Linux kernel bug, tracked as CVE-2021-3493, which has been added to the agency's Known Exploited Vulnerabilities Catalog following active exploitation by the new stealthy Linux malware Shikitega.
Newly emergent blockchain network Aptos, which had its mainnet only launched last week, has been impacted by an already-patched flaw in its Move Virtual Machine, which could be exploited to facilitate a denial-of-service condition, reports The Hacker News.
Iranian state-sponsored threat group Domestic Kitten, also known as APT-C-50, has deployed the updated FurBall Android spyware in mobile surveillance campaigns targeted at Iranian citizens, BleepingComputer reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.