Infosec News

InfoSec News 20230606

  • Publicado: Ter, 06/06/2023 - 15:38

Top News


  • Zero-Day Alert: Google Issues Patch for New Chrome Vulnerability - Update Now!

"Google on Monday released security updates to patch a high-severity flaw in its Chrome web browser that it said is being actively exploited in the wild.

Tracked as CVE-2023-3079, the vulnerability has been described as a type confusion bug in the V8 JavaScript engine. Clement Lecigne of Google's Threat Analysis Group (TAG) has been credited with reporting the issue on June 1, 2023."

InfoSec News 20230602

  • Publicado: Sex, 02/06/2023 - 12:48

Top News


  • New Horabot campaign targets the Americas

Cisco Talos has observed a threat actor deploying a previously unidentified botnet program Talos is calling “Horabot,” which delivers a known banking trojan and spam tool onto victim machines in a campaign that has been ongoing since at least November 2020.
The threat actor appears to be targeting Spanish-speaking users in the Americas and, based on our analysis, may be located in Brazil.

InfoSec News 20230601

  • Publicado: Qui, 01/06/2023 - 13:30

Top News


  • Amazon's Ring and Alexa fined $30m for spying and child privacy abuse

"Amazon will fork over $30m in fines for multiple privacy violations, including allowing Ring employees to spy on customers, creating a security atmosphere ripe for hackers, and illegally keeping Alexa recordings of children’s voices.
In the first set of charges, the US Federal Trade Commission (FTC) says Amazon’s home security camera company, Ring, violated customer privacy by allowing any Ring employee or contractor to access consumers’ private videos.

InfoSec News 20230531

  • Publicado: Qua, 31/05/2023 - 13:48

Top News


  • Android apps with spyware installed 421 million times from Google Play

"A new Android malware distributed as an advertisement SDK has been discovered in multiple apps, many previously on Google Play and collectively downloaded over 400 million times.
Security researchers at Dr. Web discovered the spyware module and tracked it as 'SpinOk,' warning that it can steal private data stored on users' devices and send it to a remote server.

InfoSec News 20230530

  • Publicado: Ter, 30/05/2023 - 14:48

Top News


  • Google Cloud Users Can Now Automate TLS Certificate Lifecycle

"Google on Thursday announced the availability of its Automatic Certificate Management Environment (ACME) API for all Google Cloud users, allowing them to automatically acquire and renew TLS certificates for free.

InfoSec News 20230529

  • Publicado: Seg, 29/05/2023 - 13:51

Top News


  • Clever ‘File Archiver In The Browser’ phishing trick uses ZIP domains

"A new 'File Archivers in the Browser' phishing kit abuses ZIP domains by displaying fake WinRAR or Windows File Explorer windows in the browser to convince users to launch malicious files.
Earlier this month, Google began offering the ability to register ZIP TLD domains, such as bleepingcomputer.zip, for hosting websites or email addresses.

InfoSec News 20230526

  • Publicado: Sex, 26/05/2023 - 12:11

Top News


  • Microsoft 365 phishing attacks use encrypted RPMSG messages

"Attackers are now using encrypted RPMSG attachments sent via compromised Microsoft 365 accounts to steal Microsoft credentials in targeted phishing attacks designed to evade detection by email security gateways.

InfoSec News 20230525

  • Publicado: Qui, 25/05/2023 - 13:12

Top News


  • ‘Operation Magalenha’ targets credentials of 30 Portuguese banks

"A Brazilian hacking group has been targeting thirty Portuguese government and private financial institutions since 2021 in a malicious campaign called 'Operation Magalenha.'
Examples of the targeted entities include ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco.

InfoSec News 20230524

  • Publicado: Qua, 24/05/2023 - 12:06

Top News


  • AhRat Android RAT was concealed in iRecorder app in Google Play

"ESET researchers have discovered an Android app on Google Play that was hiding a new remote access trojan (RAT) dubbed AhRat.
The app, named iRecorder – Screen Recorder, has more than 50,000 installs. The app was initially uploaded to the Google Play store without malicious features on September 19th, 2021. Threat actors introduced the support for malicious functionalities in version 1.3.8 which was uploaded on August 2022.

Páginas