Security News > 2024 > September

Victims lose $70k to one single wallet-draining app on Google's Play Store
2024-09-26 14:08

Attackers got 10k people to download 'trusted' web3 brand cheat before Mountain View intervened The latest in a long line of cryptocurrency wallet-draining attacks has stolen $70,000 from people...

Automattic blocks WP Engine’s access to WordPress resources
2024-09-26 13:51

WordPress.org has banned WP Engine from accessing its resources and stopped delivering plugin updates to websites hosted on the platform, urging impacted users to choose other hosting providers. [...]

Fake WalletConnect app on Google Play steals Android users’ crypto
2024-09-26 13:11

A crypto draining app mimicking the legitimate 'WalletConnect' project has been distributed over Google Play for five months getting more than 10,000 downloads. [...]

N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks
2024-09-26 12:28

Threat actors with ties to North Korea have been observed leveraging two new malware strains dubbed KLogEXE and FPSpy. The activity has been attributed to an adversary tracked as Kimsuky, which is...

Overloaded with SIEM Alerts? Discover Effective Strategies in This Expert-Led Webinar
2024-09-26 12:28

Imagine trying to find a needle in a haystack, but the haystack is on fire, and there are a million other needles you also need to find. That's what dealing with security alerts can feel like....

The number of Android memory safety vulnerabilities has tumbled, and here’s why
2024-09-26 12:21

Google’s decision to write new code into Android’s codebase in Rust, a memory-safe programming language, has resulted in a significant drop in memory safety vulnerabilities, despite old code...

HPE Aruba Networking fixes critical flaws impacting Access Points
2024-09-26 12:11

HPE Aruba Networking has fixed three critical vulnerabilities in the Command Line Interface (CLI) service of its Aruba Access Points, which could let unauthenticated attackers gain remote code...

An Analysis of the EU’s Cyber Resilience Act
2024-09-26 11:03

A good—long, complex—analysis of the EU’s new Cyber Resilience Act.

#EU
EPSS vs. CVSS: What’s the Best Approach to Vulnerability Prioritization?
2024-09-26 11:00

Many businesses rely on the Common Vulnerability Scoring System (CVSS) to assess the severity of vulnerabilities for prioritization. While these scores provide some insight into the potential...

Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware
2024-09-26 10:43

As many as 25 websites linked to the Kurdish minority have been compromised as part of a watering hole attack designed to harvest sensitive information for over a year and a half. French...