Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

A new threat has emerged in the world of Android banking app security, as a group called Gigabud has developed a technique to evade malware detection by creating work profiles on compromised devices. This clever tactic allows malicious actors to bypass security checks and continue to siphon sensitive information from unsuspecting users. Gigabud’s method relies … Read more

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A Highly Sophisticated Attack Exploits PaperCut’s Vulnerabilities, Impacting Over 440 Instances Worldwide In a staggering display of cyber resilience, hackers have leveraged hundreds of AI agents to compromise over 440 instances of PaperCut, a popular print management system. The attack showcases the evolving tactics employed by modern attackers, who are increasingly using artificial intelligence (AI) … Read more

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

A pair of critical vulnerabilities in widely used VPN certificates has been disclosed by Check Point, leaving thousands of organizations and individuals vulnerable to unauthenticated remote code execution (RCE) attacks. The severity of these flaws is underscored by their 9.8 rating on the Common Vulnerability Scoring System (CVSS), making them among the most critical issues … Read more

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

Google Play’s Early Access Feature Exploited by Malicious Actors, Thousands of Deceptive Apps Pushed onto Users A disturbing trend has emerged in the world of Android app development, where malicious actors have been exploiting Google Play’s Early Access feature to push thousands of deceptive apps onto unsuspecting users. These apps, masquerading as legitimate software, are … Read more

New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws

Cybersecurity researchers have uncovered a sophisticated exploit kit dubbed “BlueMoon” that has been used by multiple cyber-espionage groups to target Windows and Chrome users. The BlueMoon kit takes advantage of zero-day vulnerabilities in Chromium-based browsers, including Google Chrome, and Windows operating systems, making it a highly effective tool for attackers. The BlueMoon kit is a … Read more

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Cybersecurity authorities have set a September 12 deadline for federal agencies and contractors to patch critical vulnerabilities in Cisco, Citrix, and Fortinet products. The move comes after the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed that these flaws are being exploited by attackers, highlighting the need for swift action to prevent further breaches. The … Read more

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Gigabud’s Android Work Profiles Expose Users to Banking App Malware Checks A disturbing trend has emerged in the world of mobile security, where a company called Gigabud is creating custom Android work profiles that can evade malware detection by banking apps. This revelation poses significant risks for users who rely on these apps for financial … Read more

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A sophisticated cyber attack has been uncovered, involving hundreds of artificial intelligence agents and compromising over 440 instances of a popular print management software, PaperCut. The attackers exploited vulnerabilities in the software’s architecture, leveraging identity exposure to create active attack paths that have left many organizations vulnerable. The attack, which was reportedly carried out using … Read more

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

A Critical Vulnerability in Popular VPN Certificates Exposes Users to Remote Code Execution Attacks Check Point, a leading cybersecurity firm, has disclosed two high-severity vulnerabilities affecting popular virtual private network (VPN) certificates. These flaws, rated 9.8 out of 10 for severity, enable unauthenticated remote code execution (RCE), leaving millions of users vulnerable to cyber attacks. … Read more