Android Smartphones Vulnerable to Fingerprint Brute Force Attacks
Android Smartphones Vulnerable to Fingerprint Brute Force Attacks
  • Alert & Advisory
  • May 25, 2023

A new method of bypassing user authentication on smartphones running the Android, HarmonyOS, and iOS operating systems has been discovered. The method has been dubbed 'BrutePrint' by its discoverers, Tencent Labs and Zhejiang University, because it employs brute force attacks to crack modern smartphone authentication mechanisms such as fingerprints to bypass user authentication and take control of the device

Russian Snake Malware Infrastructure Identified Worldwide
Russian Snake Malware Infrastructure Identified Worldwide
  • Alert & Advisory
  • May 22, 2023

The US federal government recently stated that it legally broke into a global network of malware-infected computers used by the Russian government to conduct cyber-espionage for nearly two decades in order to shut down their online surveillance operation. The "Snake" espionage tool is a very sophisticated and powerful malware toolkit developed and deployed by a hacking group associated to Russia's Federal Security Service (FSB) Center 16 for long-term intelligence collection on sensitive targets. The group is called Turla (aka Iron Hunter, Secret Blizzard, SUMMIT, Uroburos, Venomous Bear, and Waterbug). The tool has been effectively used to conduct cyber-espionage campaigns against a variety of political, military, diplomatic, and research organizations all around the world. The Snake toolkit is designed to be stealthy and persistent, capable of evading detection and maintaining control of infected systems for extended periods of time.

Critical Vulnerability Discovered in Popular WordPress Plugin
Critical Vulnerability Discovered in Popular WordPress Plugin
  • Alert & Advisory
  • May 15, 2023

Popular WordPress plugin “Essential Addons for Elementor” by WPDeveloper was found to contain a vulnerability that could allow remote attackers to escalate privileges to an administrator on the site. The plugin has more than a million active installations and the vulnerability affects versions 5.4.0 to 5.7.1.

Dangerous Android Malware Infiltrates Google Play Store Apps
Dangerous Android Malware Infiltrates Google Play Store Apps
  • Alert & Advisory
  • April 19, 2023

Unintentionally, developers have included a dangerous third-party library in their apps that is capable of data theft and ad fraud. This malware has been found in 60 apps so far and has been dubbed 'Goldoson' by its discoverers, McAfee. So far, the affected apps have been either uninstalled or updated to remove the malicious library.

Security Advisory on Increasing Phishing Attacks
Security Advisory on Increasing Phishing Attacks
  • Alert & Advisory
  • April 11, 2023

Phishing is a type of cyberattack that employs social engineering techniques to persuade a potential victim(s) to reveal sensitive information via deceptive emails, text messages, phone calls, and/or social media. The attacker may be looking for personally identifiable information (PII), banking details, and account credentials. The goal could also be to trick the victim into downloading malware.

Related Articles