Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks

01/07/2024 0 Comments 0 tags

A trio of security flaws has been uncovered in the CocoaPods dependency manager for Swift and Objective-C Cocoa projects that could be exploited to stage software supply chain attacks, putting

Indian Software Firm’s Products Hacked to Spread Data-Stealing Malware

01/07/2024 0 Comments 0 tags

Installers for three different software products developed by an Indian company named Conceptworld have been trojanized to distribute information-stealing malware. The installers correspond to Notezilla, RecentX, and Copywhiz, according to

CapraRAT Spyware Disguised as Popular Apps Threatens Android Users

01/07/2024 0 Comments 0 tags

The threat actor known as Transparent Tribe has continued to unleash malware-laced Android apps as part of a social engineering campaign to target individuals of interest. “These APKs continue the

New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems

01/07/2024 0 Comments 0 tags

OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems. The vulnerability has

End-to-End Secrets Security: Making a Plan to Secure Your Machine Identities

01/07/2024 0 Comments 0 tags

At the heart of every application are secrets. Credentials that allow human-to-machine and machine-to-machine communication. Machine identities outnumber human identities by a factor of 45-to-1 and represent the majority of

Juniper Networks Releases Critical Security Update for Routers

01/07/2024 0 Comments 0 tags

Juniper Networks has released out-of-band security updates to address a critical security flaw that could lead to an authentication bypass in some of its routers. The vulnerability, tracked as CVE-2024-2973,

Google to Block Entrust Certificates in Chrome Starting November 2024

29/06/2024 0 Comments 0 tags

Google has announced that it’s going to start blocking websites that use certificates from Entrust starting around November 1, 2024, in its Chrome browser, citing compliance failures and the certificate

GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others

28/06/2024 0 Comments 0 tags

GitLab has released security updates to address 14 security flaws, including one critical vulnerability that could be exploited to run continuous integration and continuous deployment (CI/CD) pipelines as any user.

Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data

28/06/2024 0 Comments 0 tags

The North Korea-linked threat actor known as Kimsuky has been linked to the use of a new malicious Google Chrome extension that’s designed to steal sensitive information as part of

New SnailLoad Attack Exploits Network Latency to Spy on Users’ Web Activities

28/06/2024 0 Comments 0 tags

A group of security researchers from the Graz University of Technology have demonstrated a new side-channel attack known as SnailLoad that could be used to remotely infer a user’s web