Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.
This is not a remote attack. It requires
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes
This mature portfolio of EDR-terminating tools is centered around a framework that’s known as GentleKiller.
“They also incorporate third-party or
Texas govt data breach exposes over 3 million driver’s licenses
AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
Steer the agent to load an attacker’s web page, and that page’s JavaScript can reach a privileged local service on the same machine and spawn a process on the host.
No credentials, no sign-in screen, and no further user interaction once
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
The post In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum appeared first on SecurityWeek.
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
“With these actions we deprive cybercriminals of access to infected computer systems,” Maikel Rollman of the Netherlands National High Tech Crime Unit said.
“This prevents
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
The sweeping campaign, believed to be the work of Russian-speaking threat actors, has been codenamed FortiBleed. The number of compromised devices stands at
