Aggregator
CVE-2023-21487 | Samsung Smart Phone Telephony Framework access control (EUVD-2023-25655)
CVE-2023-21488 | Samsung Smart Phone Tips access control (EUVD-2023-25656)
CVE-2023-21485 | Samsung Smart Phone Call Setting VideoPreviewActivity improper export of android application components (EUVD-2023-25653)
CVE-2023-21486 | Samsung Smart Phone Call Setting ImagePreviewActivity improper export of android application components (EUVD-2023-25654)
Self-Replicating 'Shai-hulud' Worm Targets NPM Packages
CVE-2023-21484 | Samsung Smart Phone AppLock access control (EUVD-2023-25652)
CVE-2023-41578 | jeecg-boot up to 3.5.3 /testConnection path traversal (EUVD-2023-2563)
CVE-2023-21465 | Samsung BixbyTouch 2.2.00.6 access control (EUVD-2023-25633)
Webinar | Universal ZTNA: Secure Access, SASE, and the Quest for End-to-End Federal Digital Trust
Seon Receives $80M to Grow Autonomous AML and KYC Platform
Texas-based fraud detection startup Seon closed an $80 million Series C funding round to support its shift toward an all-in-one AML and KYC compliance platform powered by AI, as it pursues aggressive international expansion and deeper product integration.
'SlopAds' Fraud Campaign Uses Novel Obfuscation Techniques
A cybercrime crew using Android mobile apps to conduct advertising fraud took unusual pains to hide its activity, concealing malicious code in downloadable digital images and holding off from infecting the subset of users who organically found their apps through the Google Play store.
Scattered Spider Tied to Fresh Attacks on Financial Services
Elements of the notorious ransomware collective lately calling itself Scattered Lapsus$ Hunters appear to be targeting fresh victims, including a U.S. banking organization if not the sector at large, despite a member of the group claiming it would be "going dark" and retiring.
Jaguar Land Rover Extends Production Halt
British auto manufacturer Jaguar Land Rover will extend a production pause until late September as it enters its third week of contending with a cyber incident that forced it to shut down assembly lines across the globe.
Survey Surfaces Rising Number of AI Security Incidents
A global survey of 1,025 IT and security professionals finds that while organizations experienced an average of 2.17 cloud breaches over the past 18 months, only 8% were categorized as severe. At the same time, however, with the rise of artificial intelligence (AI) there may be more significant challenges ahead. More than half of respondents..
The post Survey Surfaces Rising Number of AI Security Incidents appeared first on Security Boulevard.
HPE security advisory (AV25-595)
Senators, FBI Director Patel clash over cyber division personnel, arrests
The contentious hearing focused on other subjects, but lawmakers still had cyber questions and accusations for the head of the bureau.
The post Senators, FBI Director Patel clash over cyber division personnel, arrests appeared first on CyberScoop.
'Vane Viper' Threat Group Tied to PropellerAds, Commercial Entities
万户OA代码审计与0day挖掘
Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attack
A potentially monumental supply chain attack is underway, thanks to a self-replicating worm-like payload that has been compromising packages published on the npm Registry. The worm has been dubbed “Shai-hulud” as it steals credentials from victims who run a compromised package and publishes them in a public GitHub repository which contains the name. The worm also uses npm authentication tokens stolen from the victims to perpetuate the cycle of infection and compromise, and compromised GitHub … More →
The post Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attack appeared first on Help Net Security.