01 Dec Compromised OEM Android platform certificates used to sign malware Multiple platform certificates used by Android OEM device vendors to digitally sign core system applications were utilized by threat actors to sign apps containing malware. […]
01 Dec Samsung, LG, Mediatek certificates compromised to sign Android malware Multiple platform certificates used by Android OEM device vendors to digitally sign core system applications have also been used to sign Android apps containing malware. […]
01 Dec Android malware infected 300,000 devices to steal Facebook accounts An Android malware campaign masquerading as reading and education apps has been underway since 2018, attempting to steal Facebook account credentials from infected devices. […]
01 Dec FBI: Cuba ransomware raked in $60 million from over 100 victims The FBI and CISA revealed in a new joint security advisory that the Cuba ransomware gang raked in over $60 million in ransoms as of August 2022 after breaching more than 100 victims worldwide. […]
01 Dec New Redigo malware drops stealthy backdoor on Redis servers A new Go-based malware threat that researchers call Redigo has been targeting Redis servers vulnerable to CVE-2022-0543 to plant a stealthy backdoor and allow command execution. […]
30 Nov GoTo says hackers breached its dev environment, cloud storage Remote access and collaboration company GoTo disclosed today that they suffered a security breach where threat actors gained access to their development environment and third-party cloud storage service. […]
30 Nov Keralty ransomware attack impacts Colombia’s health care system The Keralty multinational healthcare organization suffered a RansomHouse ransomware attack on Sunday, disrupting the websites and operations of the company and its subsidiaries. […]
30 Nov Critical RCE bugs in Android remote keyboard apps with 2M installs Three Android applications that allow users to use devices as remote keyboards for their computers have critical vulnerabilities that could expose key presses and enable remote code execution. […]
30 Nov Lastpass says hackers accessed customer data in new breach LastPass says unknown attackers breached its cloud storage using information stolen during a previous security incident from August 2022. […]
30 Nov New Windows malware scans victims’ mobile phones for data to steal Security researchers found a previously unknown backdoor they call Dophin that’s been used by North Korean hackers in highly targeted operations for more than a year to steal files and send them to Google Drive storage. […]