More than 400 custom web injects for mobile malware are being offered for sale by the InTheBox darknet marketplace, which is thought to emerge in January 2020, reports The Hacker News.
Several U.S. federal agencies have been pushed by the Government Accountability Office to perform cybersecurity risk assessments on internet of things and operational technology systems in a bid to bolster critical infrastructure sectors' cybersecurity posture, according to SecurityWeek.
Eclypsium's research team has discovered 3 vulnerabilities in BMCs. Nate Warfield comes on the show to tell the full story! This has garnered much attention in the press: Original research post: https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/, https://www.securityweek.com/security-flaws-ami-bmc-can-expose...
In an emergency cybersecurity directive issued Tuesday, the state flagged technologies from eight companies and prohibited state government employees from using them for official business.
Malicious Android apps have been signed by threat actors through the exploitation of platform certificates used by device vendors Samsung, LG, and MediaTek, The Hacker News reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.