"SpyLoan Android Malware on Google Play Downloaded 12 Million Times"

"SpyLoan Android Malware on Google Play Downloaded 12 Million Times"

Over a dozen malicious loan apps, collectively known as SpyLoan, have been downloaded more than 12 million times from Google Play this year, but the total is much higher because they are also available on third-party stores and suspicious websites. SpyLoan Android apps steal personal data from a victim's device regarding accounts, device information, call logs, installed apps, calendar events, local Wi-Fi network details, and image metadata. According to researchers, the threat extends to contact lists, location data, and text messages.

Submitted by Gregory Rigby on

"Unpatched Loytec Building Automation Flaws Disclosed 2 Years After Discovery"

"Unpatched Loytec Building Automation Flaws Disclosed 2 Years After Discovery"

Security researchers at industrial cybersecurity firm TXOne Networks have disclosed the details of 10 unpatched vulnerabilities discovered in building automation products made by Austrian company Loytec more than two years ago.  The vulnerabilities have been assigned to the identifiers CVE-2023-46380 through CVE-2023-46389, and their details were disclosed in three separate advisories published on the Full Disclosure mailing list in November.

Submitted by Adam Ekwall on

"94 Vulnerabilities Patched in Android With December 2023 Security Updates"

"94 Vulnerabilities Patched in Android With December 2023 Security Updates"

Google recently announced that the December 2023 Android security updates deliver patches for 94 vulnerabilities.  The first part of the updates resolves 33 vulnerabilities in Android's Framework and System components.  Google noted that three of these are rated "critical severity." Google stated that the most severe of these issues is a critical security vulnerability in the system component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed.

Submitted by Adam Ekwall on

"HYAS Infosec Groundbreaking Research on AI-Generated Malware Contributes to the AI Act, Other AI Policies and Regulations"

"HYAS Infosec Groundbreaking Research on AI-Generated Malware Contributes to the AI Act, Other AI Policies and Regulations"

Research from HYAS Infosec's HYAS Labs is contributing to the European Union's Artificial Intelligence (AI) Act. The AI Act is an initiative helping to shape the trajectory of AI governance, with US policies and considerations to follow soon. According to AI Act researchers and framers, the Act mirrors a specific conception of AI systems, considering them as non-autonomous statistical software with possible harms mainly from datasets.

Submitted by Gregory Rigby on

"Malvertising Attacks Rely on DanaBot Trojan to Spread CACTUS Ransomware"

"Malvertising Attacks Rely on DanaBot Trojan to Spread CACTUS Ransomware"

Microsoft discovered ongoing malvertising attacks involving the use of the DanaBot Trojan to spread CACTUS ransomware. Microsoft linked the campaign to Storm-0216, also known as Twisted Spider and UNC2198. Storm-0216 previously used Qakbot malware for initial access, but after the Qakbot infrastructure was taken down, it switched to other malware. The current DanaBot campaign was discovered in November, when Microsoft researchers found that the threat actors were using a private version of the popular info-stealing malware rather than the Malware-as-a-Service (MaaS) offering.

Submitted by Gregory Rigby on

"Blue Shield of California Discloses Data Breach, Number of Members Impacted Unclear"

"Blue Shield of California Discloses Data Breach, Number of Members Impacted Unclear"

It has recently been revealed that data on Blue Shield of California members may have been exposed due to a vulnerability in the MOVEit file transfer platform.  The insurer was notified on Sept. 1 by a vendor that indicated it was a victim of the data breach.  The vendor found on Aug. 23 that an unauthorized user had tapped into information in the MOVEit server and then took the server offline.  After an investigation, Blue Shield of California discovered that this third party extracted data from the server on May 28 and May 31.

Submitted by Adam Ekwall on

"AI Models Wide Open to Cyberattacks, Analyst Warns"

"AI Models Wide Open to Cyberattacks, Analyst Warns"

According to Lasso Security researchers, while HuggingFace and GitHub developer platforms are important for developing Artificial Intelligence (AI) technologies, they also expose top-level organization accounts from Google, Meta, Microsoft, and VMware to threat actors. Lasso Security began its investigation in November, inspecting hundreds of Application Programming Interfaces (APIs) on the expertise-sharing platforms. Meta, the parent company of Facebook, was discovered to be especially vulnerable, with its Large Language Model Meta AI (LLaMA) exposed in many cases.

Submitted by Gregory Rigby on

"60 Credit Unions Facing Outages Due to Ransomware Attack on Popular Tech Provider"

"60 Credit Unions Facing Outages Due to Ransomware Attack on Popular Tech Provider"

Around 60 credit unions are experiencing outages as a result of a ransomware attack on a popular technology provider. According to National Credit Union Administration (NCUA) spokesperson Joseph Adamoli, the ransomware attack targeted Ongoing Operations, a cloud services provider owned by the credit union technology company Trellance. The attack is having a larger impact on other credit union technology providers, such as FedComp, which provides data processing solutions to credit unions.

Submitted by Gregory Rigby on

"23andMe Says Hackers Accessed 'Significant Number' of Files About Users' Ancestry"

"23andMe Says Hackers Accessed 'Significant Number' of Files About Users' Ancestry"

In a recent data breach, hackers accessed about 14,000 customer accounts with the genetic testing company 23andMe. According to a new filing with the US Securities and Exchange Commission (SEC), the company determined that hackers had accessed 0.1 percent of its customer base. 23andMe's latest annual earnings report revealed that the company has over 14 million customers, so 0.1 percent of the customer base is around 14,000.

Submitted by Gregory Rigby on

"ESA Upgrades Its Security as Space Becomes Susceptible to Cybercrime"

"ESA Upgrades Its Security as Space Becomes Susceptible to Cybercrime"

The European Space Agency (ESA) is facing cyber threats, as the technology it operates has become more vulnerable to hackers. The current commercialization of European space introduces new challenges, including cybersecurity. Dr. Daniel Fischer, ESA's Head of Ground Segment System and Cybersecurity Engineering, recently announced at a conference in Tallinn that the ESA will expand its security measures. A strong defense-in-depth security strategy called the Ground Operation System Common Core - Multi-Mission Generation (EGOS-MG) will be implemented.

Submitted by Gregory Rigby on
Subscribe to