Guardio Labs disclosed CVE-2024-21388 in Microsoft Edge, where a private marketing API (edgeMarketingPagePrivate) could be abused to silently install extensions from the Edge Add-ons Store when JavaScript runs on privileged Microsoft domains. Microsoft patched…
Tag: SPYWARE
Summary : The leaked data trove belonging to the Chinese hacking contractor iSoon reveals its links to Chinese APT groups, showcasing its involvement in cyberespionage operations on behalf of Beijing. Key Point : 🔍 The leaked data trove belonging to iSoon reveals its links to Chinese state hacking g…
__________________________________________________ Summary : The GEOBOX tool on the Dark Web allows hackers to manipulate GPS, simulate networks, mimic Wi-Fi, and evade anti-fraud filters using Raspberry Pi devices. Key Point : 🔒 Cybercriminals repurpose Raspberry Pi devices with GEOBOX for digital…
In this report, we share our latest Android malware findings: the Tambir spyware, Dwphon downloader and Gigabud banking Trojan.
The signees agree to establish “robust guardrails and procedures” around spyware, prevent the export of technology that will be used for malicious cyber activity, share information on spyware proliferation and work to raise awareness globally.
A group of 40 state attorneys general have sent a letter to Instagram and Facebook parent company Meta expressing “deep concern” over what they say is dramatic uptick of consumer complaints about account takeovers and lockouts. The attorneys general called on Meta to do a better job preventing accou…
A pair of critical bugs could open the door to complete system compromise, including access to location information, iPhone camera and mic, and messages. Rootkitted attackers could theoretically perform lateral movement to corporate networks, too.
The US cybersecurity agency CISA on Tuesday added flaws impacting Pixel phones and Sunhillo software to its Known Exploited Vulnerabilities (KEV) catalog. The exploited Pixel vulnerability is tracked as CVE-2023-21237. When it patched the flaw in June 2023, Google warned that it had been aware…
The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in “developing, operating, and distributing” commercial spyware designed to target government officials, journalists, and policy experts in the country.
“The proliferation of commercial spyware poses distinct and growing
Apple released emergency security updates to fix two iOS zero-day vulnerabilities that were exploited in attacks on iPhones. […]
The Treasury Department announced Tuesday it has sanctioned two people and a Greece-based commercial spyware company headed by a former Israeli military officer that developed, operated and distributed technology used to target U.S. government officials, journalists and policy experts. The sanctions…
The U.S. has imposed sanctions on two individuals and five entities linked to the development and distribution of the Predator commercial spyware used to target Americans, including government officials and journalists. […]
A U.S. judge has ordered NSO Group to hand over its source code for Pegasus and other products to Meta as part of the social media giant’s ongoing litigation against the Israeli spyware vendor.
The decision, which marks a major legal victory for Meta, which filed the lawsuit in October 2019 for using its infrastructure to distribute the spyware to approximately
Following a string of major public disclosures, Insikt Group has identified new infrastructure associated with operators of the mercenary mobile spyware Predator.
Avast discovered a live exploit chain where the Lazarus Group abused a zero-day in the AppLocker driver appid.sys (CVE-2024-21338) to escalate from user/local-service to kernel, yielding a kernel read/write primitive used to deploy an updated FudModule data-on…