CVE-2021-34392
Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.
Facebook has taken action against a group of hackers in China who were targeting dissidents, mostly Uyghurs from Xinjiang province, the company’s Cyber Espionage team said on Wednesday. “Today, we are sharing actions we took against a group of hackers in China known in the security industry as Earth Empusa or Evil Eye – to…
Security researchers document 21 major security vulnerabilities in Exim and warn that users are exposed to remote code execution flaws Security researchers at Qualys have discovered multiple gaping security holes in Exim, a widely deployed mail server that has been targeted in the past by advanced nation state-based threat actors. An advisory from Qualys documents…
The administrator of a Russian-speaking cybercriminal forum has held a contest for the community to share uncommon methods to target cryptocurrency-related technology. Members of the forum had one month to submit their papers and enter a competition that promised more than $100,000 in prizes. Eyes on digital assets The announcement came on April 20 and asked…
Security researcher and founder of PingSafe AI, Anand Prakash, discovered a flaw in the popular iPhone app “Automatic Call Recorder.” This bug allowed anyone to access call recordings from other users by knowing their phone number. As reported by TechCrunch, this security vulnerability exposed thousands of users’ recorded conversations. With a proxy tool such as…
A man washes a cow in the Mekong river in Phnom Penh November 7, 2012. REUTERS/Samrang Pring PHNOM PENH/HANOI, July 22 (Reuters) – Buried in a long U.S. indictment accusing China of a global cyberespionage campaign was a curious detail: Among the governments targeted by Chinese hackers was Cambodia, one of Beijing’s most loyal Asian…
3rd Party Risk Management , Business Continuity Management / Disaster Recovery , Critical Infrastructure Security ‘Free’ Decryptors and Promises of Retirement Plans Are Empty Criminal Marketing Spin Mathew J. Schwartz (euroinfosec) • May 21, 2021 “The affiliate program is closed. Stay safe and good luck,” DarkSide announced in this May 13 note. (Source:…