Threatpost reports that Google has released fixes for an actively exploited zero-day flaw in the Chrome browser and 10 other Chrome vulnerabilities as part of a stable channel update.
Cybercrime operation Hadoken Security has been developing the new BugDrop dropper trojan with the capability to evade the security enhancements Google has introduced in the upcoming version of the Android operating system, according to The Hacker News.
Government, humanitarian, and think tank organizations around the world have been targeted in a years-long mass credential theft campaign by Chinese state-sponsored threat group RedAlpha, The Hacker News reports.
Two zero-day bugs that could allow remote code execution in Apple products that are apparently being exploited have prompted the company to release emergency security updates Wednesday.
Threat actors could exploit several vulnerabilities in ultra-wideband real-time locating systems widely used in industrial, healthcare, mass transit, and smart city settings to facilitate man-in-the-middle attacks and geo-location data modifications, reports BleepingComputer.
Cloud infrastructure provider DigitalOcean had "a very small number" of its customers' email addresses compromised following a phishing and social engineering campaign against Mailchimp aimed at exfiltrating cryptocurrency-related firms' data and information, reports TechCrunch.