Security Affairs newsletter Round 334
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.
If you want to also receive for free the international press subscribe here.
Threat actors exploit a flaw in Coinbase 2FA to steal user funds |
Flubot Android banking Trojan spreads via fake security updatesTh |
Tim’s RED Team Research reports 3 new CVEs, two of which in 4G/5G |
Baby died at Alabama Springhill Medical Center due to cyber attack |
Hydra Android trojan campaign targets customers of European banks |
Neiman Marcus discloses data breach, payment card data exposed |
Google fixes 2 new actively exploited zero-day flaws in Chrome |
Weaponizing Apple AirTag to lure users to malicious sites |
Experts show how to make fraudulent payments using Apple Pay with VISA on locked iPhones |
Popular Android apps with 142.5 million collective installs leak user data |
Threat actors use recently discovered CVE-2021-26084 Atlassian Confluence |
CISA releases Insider Risk Mitigation Self-Assessment Tool |
Facebook released Mariana Trench tool to find flaws in Android and Java apps |
Expert discloses new iPhone lock screen vulnerability in iOS 15 |
GriftHorse malware infected more than 10 million Android phones from 70 countries |
NSA, CISA release guidance on hardening remote access via VPN solutions |
Group-IB CEO was put under arrest on treason charges |
Experts observed for the first time FinFisher infections involving usage of a UEFI bootkit |
Trend Micro fixes a critical flaw in ServerProtec Solution, patch it now! |
A complete PoC exploit for CVE-2021-22005 in VMware vCenter is available online |
Russia-linked Nobelium APT group uses custom backdoor to target Windows domains |
ERMAC, a new banking Trojan that borrows the code from Cerberus malware |
New BloodyStealer malware is targeting the gaming sector |
Expert found RCE flaw in Visual Studio Code Remote Development Extension |
Jupyter infostealer continues to evolve and is distributed via MSI installers |
Telegram is becoming the paradise of cyber criminals |
German Federal Office for Information Security (BSI) investigates Chinese mobile phones |
Port of Houston was hit by an alleged state-sponsored attack |
JSC GREC Makeyev and other Russian entities under attack |
Google TAG spotted actors using new code signing tricks to evade detection |
Follow me on Twitter: @securityaffairs and Facebook
|
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)
The post Security Affairs newsletter Round 334 appeared first on Security Affairs.
If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.