PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Watch Out! That Android System Update May Contain A Powerful Spyware

samedi 27 mars 2021 à 10:14
Researchers have discovered a new information-stealing trojan, which targets Android devices with an onslaught of data-exfiltration capabilities — from collecting browser searches to recording audio and phone calls. While malware on Android has previously taken the guise of copycat apps, which go under names similar to legitimate pieces of software, this sophisticated new malicious app

Apple Issues Urgent Patch Update for Another Zero‑Day Under Attack

samedi 27 mars 2021 à 07:07
Merely weeks after releasing out-of-band patches for iOS, iPadOS, macOS and watchOS, Apple has issued yet another security update for iPhone, iPad, and Apple Watch to fix a critical zero-day weakness that it says is being actively exploited in the wild. Tracked as CVE-2021-1879, the vulnerability relates to a WebKit flaw that could enable adversaries to process maliciously crafted web content

OpenSSL Releases Patches for 2 High-Severity Security Vulnerabilities

vendredi 26 mars 2021 à 15:56
The maintainers of OpenSSL have released a fix for two high-severity security flaws in its software that could be exploited to carry out denial-of-service (DoS) attacks and bypass certificate verification. Tracked as CVE-2021-3449 and CVE-2021-3450, both the vulnerabilities have been resolved in an update (version OpenSSL 1.1.1k) released on Thursday. While CVE-2021-3449 affects all OpenSSL

New 5G Flaw Exposes Priority Networks to Location Tracking and Other Attacks

vendredi 26 mars 2021 à 09:57
New research into 5G architecture has uncovered a security flaw in its network slicing and virtualized network functions that could be exploited to allow data access and denial of service attacks between different network slices on a mobile operator's 5G network. AdaptiveMobile shared its findings with the GSM Association (GSMA) on February 4, 2021, following which the weaknesses were

Another Critical RCE Flaw Discovered in SolarWinds Orion Platform

vendredi 26 mars 2021 à 06:07
IT infrastructure management provider SolarWinds on Thursday released a new update to its Orion networking monitoring tool with fixes for four security vulnerabilities, counting two weaknesses that could be exploited by an authenticated attacker to achieve remote code execution (RCE). Chief among them is a JSON deserialization flaw that allows an authenticated user to execute arbitrary code via