Joint Alert About Attacks Supported by North Korea Issued by CISA, FBI, and the Treasury Department The public and healthcare sectors are on high…
API
Several hundred cryptographic libraries are susceptible to private key theft
Difficult Ed25519 implementations have made hundreds of cryptography packages vulnerable to attacks. Ed25519 is a common digital signature method. Cryptographer Konstantinos Chalkias of MystenLabs,…
Spanish Bank service users targeted by Trojan “Revive”
An unknown Android banking trojan has been tracked; the trojan has targeted users of the Spanish financial services company BBVA. The malware, assumed to…
Android virus called “Revive” poses as the 2FA app for BBVA bank.
The 2FA application necessary to access BBVA bank accounts in Spain is impersonated by a new Android banking malware called Revive. Instead of aiming…
2022 SaaS Security Survey Report: 7 Key Findings
Learn about the emerging threats to SaaS security and how different firms are addressing them. In partnership with CSA, the 2022 SaaS Security Survey…
A Microsoft Office 365 feature can help Ransomware hackers to hack Cloud files
A “dangerous piece of functionality” has been uncovered in Microsoft 365 suite that can be exploited by attackers to ransom files stored on SharePoint…
Yunmai’s weight-monitoring software faces mass account takeover danger due to an unpatched bug chain
At least 500,000 Android accounts have had their data compromised. According to security researchers, a chained zero-day attack could potentially expose all user data…
CISA Warns About Critical Vulnerabilities in Illumina’s DNA Sequencing Devices
The Food and Drug Administration (FDA) and the US Cybersecurity and Infrastructure Security Agency (CISA) have issued an advisory concerning serious security vulnerabilities in…
Multiple Vulnerabilities are discovered In Open Automation Software (OAS) Platform
Open Automation Software, a major ICS platform, has a number of security flaws, according to researchers (OAS). Exploiting these flaws could lead to the…
Google’s OAuth client library for Java had a major flaw
Last month Google patched a severe flaw in its OAuth client library for Java; the actors can exploit the flaw by using a compromised…