Remove 04
Remove 2020 Remove Data Remove Information Security Remove Security
article thumbnail

Google addresses a high severity flaw in V8 engine in Chrome

Security Affairs

Google has released security updates for Chrome 90 that address a new high severity vulnerability, tracked as CVE-2021-21227, that resides in the V8 JavaScript engine used by the web browser. The CVE-2021-21227 flaw is linked to the CVE-2020-16040 and CVE-2020-15965 vulnerabilities that were addressed by Google in 2020.

article thumbnail

Grandoreiro Malware implements new features in Q2 2020

Security Affairs

The updated Grandoreiro Malware equipped with latenbot-C2 features in Q2 2020 now extended to Portuguese banks. Cybercriminals attempt to compromise computers to generate revenue by exfiltrating information from victims’ devices, typically banking-related information. Figure 1: Grandoreiro email template Q2 2020 (Portugal).

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Google fixes the second zero-day in Chrome in 2 weeks actively exploited

Security Affairs

Google released Chrome 86.0.4240.183 for Windows, Mac, and Linux to fix 10 security vulnerabilities, including an RCE zero-day exploited in the wild. The zero-day flaw was discovered on October 29, 2020 by Google white-hat hacker Samuel GroĂź of Google Project Zero and Clement Lecigne of Google’s Threat Analysis Group.

Libraries 112
article thumbnail

Russian telco Rostelecom hijacks traffic for IT giants, including Google, Amazon and Facebook

Security Affairs

According to the BGPmon.net , starting from 2020-04-01 19:27:28 its service detected a possible BGP hijack, the prefix involved is 31.13.64.0 /19, Many examples were just posted on @bgpstream , see for example this example for @Facebook [link] pic.twitter.com/6aEzFyIfCv — BGPmon.net (@bgpmon) April 5, 2020.

IT 97
article thumbnail

North Korea-linked Lazarus APT used Windows Update client and GitHub in recent attacks

Security Affairs

This threat actor has been active since at least 2009, possibly as early as 2007, and it was involved in both cyber espionage campaigns and sabotage activities aimed to destroy data and disrupt systems. The group keeps updating its toolset to evade security mechanisms.” ” reads t he analysis published by Malwarebytes.

article thumbnail

Lampion malware origin servers geolocated in Turkey

Security Affairs

This malware appears to be on the rise at the end of February 2020, after a fresh update where its operators introduced a new obfuscation layer on the first stage of the threat. On February 27th, 2020, another template email was spread impersonating the Portuguese Government Finance & Tax (Portal das Finanças – ATA).

article thumbnail

Hackers target zero-day flaws in enterprise Draytek network devices

Security Affairs

0-day Since 2019-12-04 08:22:29 (UTC), we have been witnessing ongoing 0 day attack targeting a network CPE vendor (not the big players, but there are about ~100,000 devices online according to public available data). ” reads the security bulletin. 0-day And sending the captured files to a receiver at 103.82.143.51. .”