Amazon has confirmed and fixed a vulnerability in its Photos app for Android, which has been downloaded over 50 million times on the Google Play Store. Amazon Photos is an image and video storage application that enables users to seamlessly share their snaps with up to five family members, offering powerful management and organization features. Read more >>>
July 5, 2022
While people were celebrating the Fourth of July holiday in the United States, Google quietly rolled out a stable channel update for Chrome to patch an actively exploited zero-day vulnerability, the fourth such flaw the vendor has had to patch in its browser product so far this year. Read more >>>
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has removed a Windows security flaw from its catalog of known exploited vulnerabilities due to Active Directory (AD) authentication issues caused by the May 2022 updates that patch it. This security bug is an actively exploited Windows LSA spoofing zero-day tracked as CVE-2022-26925, confirmed as a new PetitPotam Windows NTLM Relay attack vector. Read more >>>
On Thursday, Apple's security response team released emergency patches to cover a pair of "actively exploited" vulnerabilities affecting macOS, iOS, and iPadOS devices. Apple confirmed the two security defects -- CVE-2022-22675 and CVE-2022-22674 -- in all its major operating systems and warned that remote code execution attacks may already be underway. Read more >>>
On Monday, the U.S. government once again cautioned of potential cyber-attacks from Russia in retaliation for economic sanctions imposed by the west on the country following its military assault on Ukraine last month. The development comes as the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) warned of "possible threats" to U.S. and international satellite communication (SATCOM) networks. Read more >>>
March 11, 2022
A new malware campaign is taking advantage of people's willingness to support Ukraine's cyber warfare against Russia to infect them with password-stealing Trojans. Last month, the Ukrainian government announced a new IT Army composed of volunteers worldwide who conduct cyberattacks and DDoS attacks against Russian entities. Read more >>>