Category: Uncategorized
-
CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)
What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129…
-

Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability [email protected] (The Hacker News)
Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance for Open Media (AOMedia). Exploitation of such buffer overflow flaws canRead More
-
Chinese Gov Hackers Caught Hiding in Cisco Router Firmware Ryan Naraine
The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently hop around the corporate networks of U.S. and Japanese companies. The post Chinese Gov Hackers Caught Hiding in Cisco Router Firmware appeared first on SecurityWeek. Read More
-
CISA Unveils New HBOM Framework to Track Hardware Components Ryan Naraine
CISA unveils a new Hardware Bill of Materials (HBOM) framework for buyers and sellers to communicate about components in physical products. The post CISA Unveils New HBOM Framework to Track Hardware Components appeared first on SecurityWeek. Read More
-

Red Cross-Themed Phishing Attacks Distributing DangerAds and AtlasAgent Backdoors [email protected] (The Hacker News)
A new threat actor known as AtlasCross has been observed leveraging Red Cross-themed phishing lures to deliver two previously undocumented backdoors named DangerAds and AtlasAgent. NSFOCUS Security Labs described the adversary as having a “high technical level and cautious attack attitude,” adding that “the phishing attack activity captured this time is part of the attacker’s targeted strike onRead More
-
Gem Security Lands $23 Million Series A Funding Ryan Naraine
Israeli security startup Gem Security has raised a total of $34 million to tackle cloud threat detection and incident response. The post Gem Security Lands $23 Million Series A Funding appeared first on SecurityWeek. Read More
-
Misconfigured TeslaMate Instances Put Tesla Car Owners at Risk Ionut Arghire
Attackers can find tons of information on Tesla cars and their drivers by searching for misconfigured TeslaMate instances online. The post Misconfigured TeslaMate Instances Put Tesla Car Owners at Risk appeared first on SecurityWeek. Read More
-
Firefox 118 Patches High-Severity Vulnerabilities Ionut Arghire
Firefox 118 patches six high-severity vulnerabilities, including a memory leak potentially leading to sandbox escape. The post Firefox 118 Patches High-Severity Vulnerabilities appeared first on SecurityWeek. Read More
-

Researchers Uncover New GPU Side-Channel Vulnerability Leaking Sensitive Data [email protected] (The Hacker News)
A novel side-channel attack called GPU.zip renders virtually all modern graphics processing units (GPU) vulnerable to information leakage. “This channel exploits an optimization that is data dependent, software transparent, and present in nearly all modern GPUs: graphical data compression,” a group of academics from the University of Texas at Austin, Carnegie Mellon University, University ofRead More
-
Stolen GitHub Credentials Used to Push Fake Dependabot Commits Ionut Arghire
Threat actors have been using stolen GitHub personal access tokens to push malicious code posing as Dependabot contributions. The post Stolen GitHub Credentials Used to Push Fake Dependabot Commits appeared first on SecurityWeek. Read More
