Group-IB uncovered Dark Pink APT, involved in attacks on government agencies and military facilities in the Asia-Pacific region using special malware to steal information.
At least 29 security vulnerabilities have been fixed by Adobe developers in their corporate product line, releasing the first batch of security fixes for 2023.
ESET announces a new StrongPity campaign, in which APT distributes a fake Shagle application, which is a Trojan version of Telegram for Android with the addition of a backdoor.
The first January ICS fixes came up with a dozen security recommendations from Siemens and Schneider Electric, eliminating a total of 27 vulnerabilities.
Microsoft's January PatchTuesday was released with fixes for a record 98 documented software vulnerabilities. Eleven of them are classified as critical, including 0-day, of which 39 are privilege escalation, 4 are security bypassing, 33 are RCE, 10 are information disclosure, 10 are DoS and 2 are spoofing.
Potentially serious UEFI firmware vulnerabilities in Qualcomm Snapdragon chips affect many devices manufactured by Microsoft, Lenovo, Samsung and many other companies.
If Villariba and Villabaggio had suffered from the MegaCortex ransomware, then they would really have had a holiday, since the specialists of the Romanian antivirus company Bitdefender released a free decryptor.
Symantec researchers report details about the activities of a cybercrime group they track as Bluebottle, revealing significant similarities to the TTP gang OPERA1ER.
Auth0 fixed an RCE vulnerability in the popular open source library JsonWebToken, which was used in more than 22,000 projects and downloaded more than 36 million times a month on NPM.
Air France and KLM have informed Flying Blue customers about a cyber incident that resulted in their accounts being compromised and personal information being disclosed.
K7 Security Labs resellers have discovered a campaign by an unknown actor, presumably based in China, who uses Windows Problem Reporting (WerFault.exe ) to launch remote administration tools.
Automakers in pursuit of active and passive safety at the time would like to think about information. While BMW, Mercedes, Toyota and other popular manufacturers were engaged in crash tests of their cars, cybersecurity researcher Sam Curry and his colleagues discovered many vulnerabilities in cars and services implemented by automotive solution providers.