Technology

Aug 11, 2024Ravie LakshmananSupply Chain / Software Security Cybersecurity researchers have discovered a new malicious package on the Python Package Index (PyPI) repository that masquerades as a library from the Solana blockchain platform but is actually designed to steal victims’ secrets. “The legitimate Solana Python API project is known as ‘solana-py’ on GitHub, but simply
0 Comments
Aug 10, 2024Ravie LakshmananVulnerability / Mobile Security As many as 10 security flaws have been uncovered in Google’s Quick Share data transfer utility for Android and Windows that could be assembled to trigger remote code execution (RCE) chain on systems that have the software installed. “The Quick Share application implements its own specific application-layer communication
0 Comments
Russia’s state communications watchdog Roskomnadzor said that Signal, an encrypted messaging app, had been blocked in the country for violating laws linked to anti-terrorist operations, Interfax news agency reported on Friday. “Access to the Signal messaging app is blocked in connection with violation of the requirements of Russian legislation which must be complied with to
0 Comments
Aug 10, 2024Ravie LakshmananVulnerability / Enterprise Security Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors. The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office – Microsoft Office
0 Comments
Aug 09, 2024Ravie LakshmananCloud Security / Data Protection Cybersecurity researchers have discovered multiple critical flaws in Amazon Web Services (AWS) offerings that, if successfully exploited, could result in serious consequences. “The impact of these vulnerabilities range between remote code execution (RCE), full-service user takeover (which might provide powerful administrative access), manipulation of AI modules, exposing
0 Comments
Aug 09, 2024Ravie LakshmananIoT Security / Wireless Security Cybersecurity researchers have uncovered weaknesses in Sonos smart speakers that could be exploited by malicious actors to clandestinely eavesdrop on users. The vulnerabilities “led to an entire break in the security of Sonos’s secure boot process across a wide range of devices and remotely being able to
0 Comments
Aug 08, 2024Ravie LakshmananCyber Attack / Cyber Espionage The North Korea-linked threat actor known as Kimsuky has been linked to a new set of attacks targeting university staff, researchers, and professors for intelligence gathering purposes. Cybersecurity firm Resilience said it identified the activity in late July 2024 after it observed an operation security (OPSEC) error
0 Comments
Microsoft blamed Delta Air Lines on Tuesday for its dayslong struggle to recover from a global cyber outage that led it to cancel more than 6,000 flights. A software update last month by global cybersecurity firm CrowdStrike triggered system problems for Microsoft customers, including many airlines. But disruptions subsided the next day at other major
0 Comments
Aug 08, 2024Ravie LakshmananVulnerability / Browser Security Cybersecurity researchers have discovered a new “0.0.0.0 Day” impacting all major web browsers that malicious websites could take advantage of to breach local networks. The critical vulnerability “exposes a fundamental flaw in how browsers handle network requests, potentially granting malicious actors access to sensitive services running on local
0 Comments
Amazon Great Freedom Festival 2024 sale, which started in India on August 6, is offering a wide range of products, including multiple electronic items at discounted rates. These include large appliances like air conditioners, smart TVs, refrigerators and washing machines as well as personal gadgets like smartphones, laptops, tablets, earphones and more. So far, we
0 Comments
Aug 07, 2024Ravie LakshmananEmail Security / Vulnerability Cybersecurity researchers have disclosed details of security flaws in the Roundcube webmail software that could be exploited to execute malicious JavaScript in a victim’s web browser and steal sensitive information from their account under specific circumstances. “When a victim views a malicious email in Roundcube sent by an
0 Comments
Aug 07, 2024Ravie LakshmananLinux / Vulnerability Cybersecurity researchers have shed light on a novel Linux kernel exploitation technique dubbed SLUBStick that could be exploited to elevate a limited heap vulnerability to an arbitrary memory read-and-write primitive. “Initially, it exploits a timing side-channel of the allocator to perform a cross-cache attack reliably,” a group of academics
0 Comments
Amazon’s Great Freedom Festival 2024 sale is now open for all shoppers after providing exclusive early access for Prime members. Beyond smartphones, tablets, laptops and other large electronic appliances, the yearly sale brings up to 80 percent discount on several mobile phone accessories including power banks, cases, mobile holders, headsets, cables, and chargers. Additionally, Amazon
0 Comments