Threatpost reports that Google has released fixes for an actively exploited zero-day flaw in the Chrome browser and 10 other Chrome vulnerabilities as part of a stable channel update.
Cybercrime operation Hadoken Security has been developing the new BugDrop dropper trojan with the capability to evade the security enhancements Google has introduced in the upcoming version of the Android operating system, according to The Hacker News.
Two zero-day bugs that could allow remote code execution in Apple products that are apparently being exploited have prompted the company to release emergency security updates Wednesday.
Threat actors could exploit several vulnerabilities in ultra-wideband real-time locating systems widely used in industrial, healthcare, mass transit, and smart city settings to facilitate man-in-the-middle attacks and geo-location data modifications, reports BleepingComputer.
Developers of the SOVA Android banking trojan have been continuously updating the malware to expand its capabilities, most recently implementing a ransomware module on the 5.0 version, according to BleepingComputer.
Cybersecurity groups SEKOIA and Trend Micro have released reports detailing the activities of China-based advanced persistent threat actor Lucky Mouse and its use of a trojanized version of the MiMi chat application to attack systems, according to The Hacker News.
At least 9,000 exposed virtual network computing endpoints have been found by security weakness hunters at Cyble, and since they don't require authorization or passwords to use, it is simple for threat actors to access internal networks, BleepingComputer reports.
SecurityWeek reports that CVE-2022-27255, a high severity security vulnerability that affects Realtek eCos SDK, could allow remote attackers to get arbitrary code execution or cause networking devices that use the SDK to crash.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.