Mobile ad fraud operation Scylla, which involved 89 mobile applications with 13 million total downloads, has been identified and disrupted by cybersecurity provider Human, reports SecurityWeek.
WhatsApp has issued fixes for two security vulnerabilities impacting its app, one of which has been given a "critical" rating, according to TechCrunch.
Vietnamese security firm GTSC warned of an attack campaign using a new zero-day affecting Microsoft Exchange servers that can lead to remote code execution.
Kasada report found that 40% of companies lost 10% of revenue or more from bot-driven account fraud, up from 5% in 2021 reporting that level of revenue loss.
Security analysts say integration with email and XDR will offer security teams more visibility into attacks as phishing is often involved in attack chains.
The FDA user-fee legislation passed without medical device cybersecurity requirements. While disappointing, stakeholders note these efforts take time — even if awareness of the risk to healthcare is at an all-time high.
Microsoft recently detailed on its security blog an attack where malicious OAuth applications were used to compromise cloud tenants to gain control of Exchange Online settings to eventually spread spam.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.