SecurityWeek reports that federal agencies have been ordered by the Cybersecurity and Infrastructure Security Agency to remediate within three weeks a Linux kernel bug, tracked as CVE-2021-3493, which has been added to the agency's Known Exploited Vulnerabilities Catalog following active exploitation by the new stealthy Linux malware Shikitega.
Newly emergent blockchain network Aptos, which had its mainnet only launched last week, has been impacted by an already-patched flaw in its Move Virtual Machine, which could be exploited to facilitate a denial-of-service condition, reports The Hacker News.
Iranian state-sponsored threat group Domestic Kitten, also known as APT-C-50, has deployed the updated FurBall Android spyware in mobile surveillance campaigns targeted at Iranian citizens, BleepingComputer reports.
Millennial and Gen Z employees are more relaxed when it comes to cybersecurity on their work devices than their personal devices, according to a new survey from Ernst & Young Consulting.
Immediate patching of a recently reported and actively exploited critical vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiProxy, has been further urged following the release of a proof-of-concept exploit code, according to The Hacker News.
A new Forescout’s Vedere Labs report details the state of medical device security, noting that while the data shows healthcare’s risk-level is lower than other sectors, it’s a reflection of visibility, not risk profiles.
WhatsApp users' account access keys are being stolen by an updated version of the malicious modded WhatsApp Android application dubbed 'YoWhatsApp', which has the same permissions but features interface customization and chat access blocking not available in the original app, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.