ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
— Veille & Actualités
Vulnérabilités, actualités et mises à jour cybersécurité — chaque élément est attribué à sa source d'origine. Rien n'est republié en intégral.
346 résultats
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
DSA-6461-1 thunderbird - security update
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code or information disclosure https://security-tracker.debian.org/tracker/DSA-6461-1
DSA-6460-1 openjdk-25 - security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. https://security-tracker.debian.org/tracker/DSA-6460-1
If you're not using AI to attack your own systems, your adversaries will
Agents are also the new attack surface - cue defenders' existential angst
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [..
Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command au
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Sp
DSA-6459-1 libnet-dns-perl - security update
Two vulnerabilities were discovered in libnet-dns-perl, a Perl module to perform DNS queries, which could result in denial of service or remote code execution. https://security-tracker.debian.org/trac
AWS Security makes an inscrutable choice
Quarantining leaked credentials is not good enough
USN-8658-2: Linux kernel (IBM) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SC
USN-8661-2: Linux kernel (Low Latency) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE