Malware & Threats Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push Researchers can earn as much as $450,000 for a single vulnerability report as Google boosts its mobile vulnerability rewards program. Ionut ArghireMay 1, 2024
Malware & Threats Cuttlefish Malware Targets Routers, Harvests Cloud Authentication Data Cuttlefish malware platform roaming around enterprise SOHO routers capable of covertly harvesting public cloud authentication data from internet traffic. Ryan NaraineMay 1, 2024
Malware & Threats Wpeeper Android Trojan Uses Compromised WordPress Sites to Shield Command-and-Control Server The new Wpeeper Android trojan ceased operations after a week and has zero detections in VirusTotal. Ionut ArghireMay 1, 2024
Malware & Threats Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover Three vulnerabilities in the Judge0 open source service could allow attackers to escape the sandbox and obtain root privileges on the host. Ionut ArghireApril 30, 2024
Artificial Intelligence CISA Rolls Out New Guidelines to Mitigate AI Risks to US Critical Infrastructure New CISA guidelines categorize AI risks into three significant types and pushes a four-part mitigation strategy. Ryan NaraineApril 29, 2024
Malware & Threats Google Says it Blocked 2.28 Million Apps from Google Play Store In 2023, Google said it blocked 2.28 million bad applications from being published on Google Play and banned 333,000 developer accounts. Ionut ArghireApril 29, 2024
Data Breaches Kaiser Permanente Data Breach Impacts 13.4 Million Patients US healthcare giant is warning millions of current and former patients that their personal information was exposed to third-party advertisers. Ionut ArghireApril 29, 2024
Malware & Threats Powerful ‘Brokewell’ Android Trojan Allows Attackers to Takeover Devices A new Android trojan named Brokewell can steal user’s sensitive information and allows attackers to take over devices. Ionut ArghireApril 26, 2024
Malware & Threats Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published. Ionut ArghireApril 26, 2024
Malware & Threats Self-Spreading PlugX USB Drive Malware Plagues Over 90k IP Addresses More than 90,000 unique IPs are still infected with a PlugX worm variant that spreads via infected flash drives. Ionut ArghireApril 26, 2024
Malware & Threats North Korean Hackers Hijack Antivirus Updates for Malware Delivery A North Korea-linked threat actor hijacked the update mechanism of eScan antivirus to deploy backdoors and cryptocurrency miners. Ionut ArghireApril 24, 2024
Malware & Threats Threat Actor Uses Multiple Infostealers in Global Campaign A threat actor tracked as CoralRaider has been using multiple infostealers to harvest credentials from users worldwide. Ionut ArghireApril 24, 2024