Remove 2022 Remove Blog Remove Education Remove Libraries
article thumbnail

Researchers disclose critical sandbox escape bug in vm2 sandbox library

Security Affairs

The development team behind the vm2 JavaScript sandbox library addressed a critical Remote Code Execution vulnerability. servers, it has approximately four million weekly downloads and its library is part of 722 packages. servers, it has approximately four million weekly downloads and its library is part of 722 packages.

article thumbnail

New Android malicious library Goldoson found in 60 apps +100M downloads

Security Affairs

The Goldoson library was discovered by researchers from McAfee’s Mobile Research Team, it collects lists of applications installed on a device, and a history of Wi-Fi and Bluetooth devices information, including nearby GPS locations. The experts have found more than 60 applications in Google Play that were containing the malicious library.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

List of Data Breaches and Cyber Attacks in September 2022 – 35.6 Million Records Breached

IT Governance

Welcome to our September 2022 list of data breaches and cyber attacks. Our blog has become the go-to source for monthly data breach statistics, and we’ve been producing this series for over seven years. That’s because we’re looking for ways to improve the way we deliver this data. Cyber attacks. Ransomware. Data breaches. million).

article thumbnail

List of data breaches and cyber attacks in May 2022 – 49.8 million records breached

IT Governance

Welcome to our May 2022 review of data breaches and cyber attacks. The post List of data breaches and cyber attacks in May 2022 – 49.8 million records breached appeared first on IT Governance UK Blog. We identified 77 security incidents during the month, resulting in 49,782,129 compromised records. Get started. Ransomware.

article thumbnail

CISA adds MinIO, PaperCut, and Chrome bugs to its Known Exploited Vulnerabilities catalog

Security Affairs

The vulnerability is an Integer overflow in the Skia graphics library, the issue was reported by Clément Lecigne of Google’s Threat Analysis Group on April 12, 2023. A remote attacker who had compromised the renderer process can exploit the integer overflow in the Skia library to potentially perform a sandbox escape via a crafted HTML page.

IT 85
article thumbnail

Google fixed the second actively exploited Chrome zero-day of 2023

Security Affairs

The vulnerability is an Integer overflow in the Skia graphics library, the issue was reported by ClĂ©ment Lecigne of Google’s Threat Analysis Group on April 12, 2023. Google rolled out emergency fixes to address another actively exploited high-severity zero-day flaw, tracked as CVE-2023-2136 , in its Chrome web browser.

article thumbnail

Google fixed the first Chrome zero-day of 2023

Security Affairs

We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.” ” concludes the advisory.