Month: November 2022

Update Chrome Browser Now to Patch New Actively Exploited Zero-Day Flaw

25 November 2022

Google on Thursday released software updates to address yet another zero-day flaw in its Chrome web browser. Tracked as CVE-2022-4135, the high-severity vulnerability has been described as a heap buffer overflow in the GPU component. Clement Lecigne of Google’s Threat Analysis Group (TAG) has been credited with reporting the flaw on November 22, 2022. Heap-based […]

Read More

Dell, HP, and Lenovo Devices Found Using Outdated OpenSSL Versions

25 November 2022

An analysis of firmware images across devices from Dell, HP, and Lenovo has revealed the presence of outdated versions of the OpenSSL cryptographic library, underscoring a supply chain risk. EFI Development Kit, aka EDK, is an open source implementation of the Unified Extensible Firmware Interface (UEFI), which functions as an interface between the operating system […]

Read More

U.K. Police Arrest 142 in Global Crackdown on ‘iSpoof’ Phone Spoofing Service

25 November 2022

A coordinated law enforcement effort has dismantled an online phone number spoofing service called iSpoof and arrested 142 individuals linked to the operation. The websites, ispoof[.]me and ispoof[.]cc, allowed the crooks to “impersonate trusted corporations or contacts to access sensitive information from victims,” Europol said in a press statement. Worldwide losses exceeded €115 million ($ […]

Read More

Interpol Seized $130 Million from Cybercriminals in Global “HAECHI-III” Crackdown Operation

25 November 2022

Interpol on Thursday announced the seizure of $130 million worth of virtual assets in connection with a global crackdown on cyber-enabled financial crimes and money laundering. The international police operation, dubbed HAECHI-III, transpired between June 28 and November 23, 2022, resulting in the arrests of 975 individuals and the closure of more than 1,600 cases. […]

Read More

New RansomExx Ransomware Variant Rewritten in the Rust Programming Language

24 November 2022

The operators of the RansomExx ransomware have become the latest to develop a new variant fully rewritten in the Rust programming language, following other strains like BlackCat, Hive, and Luna. The latest version, dubbed RansomExx2 by the threat actor known as Hive0091 (aka DefrayX), is primarily designed to run on the Linux operating system, although […]

Read More

Millions of Android Devices Still Don’t Have Patches for Mali GPU Flaws

24 November 2022

A set of five medium-severity security flaws in Arm’s Mali GPU driver has continued to remain unpatched on Android devices for months, despite fixes released by the chipmaker. Google Project Zero, which discovered and reported the bugs, said Arm addressed the shortcomings in July and August 2022. “These fixes have not yet made it downstream […]

Read More

Boost Your Security with Europe’s Leading Bug Bounty Platform

24 November 2022

As 2022 comes to an end, now’s the time to level up your bug bounty program with Intigriti. Are you experiencing slow bug bounty lead times, gaps in security skills, or low-quality reports from researchers? Intigriti’s expert triage team and global community of ethical hackers are enabling businesses to protect themselves against every emerging cybersecurity […]

Read More

Bahamut Cyber Espionage Hackers Targeting Android Users with Fake VPN Apps

24 November 2022

The cyber espionage group known as Bahamut has been attributed as behind a highly targeted campaign that infects users of Android devices with malicious apps designed to extract sensitive information. The activity, which has been active since January 2022, entails distributing rogue VPN apps through a fake SecureVPN website set up for this purpose, Slovak […]

Read More

This Android File Manager App Infected Thousands of Devices with Sharkbot Malware

24 November 2022

The Android banking fraud malware known as SharkBot has reared its head once again on the official Google Play Store, posing as file managers to bypass the app marketplace’s restrictions. A majority of the users who downloaded the rogue apps are located in the U.K. and Italy, Romanian cybersecurity company Bitdefender said in an analysis […]

Read More

Black Basta Ransomware Gang Actively Infiltrating U.S. Companies with Qakbot Malware

24 November 2022

Companies based in the U.S. have been at the receiving end of an “aggressive” Qakbot malware campaign that leads to Black Basta ransomware infections on compromised networks. “In this latest campaign, the Black Basta ransomware gang is using QakBot malware to create an initial point of entry and move laterally within an organization’s network,” Cybereason […]

Read More