Month: May 2023

May 05, 2023Ravie LakshmananMobile Security / Android Various sectors in East Asian markets have been subjected to a new email phishing campaign that distributes a previously undocumented strain of Android malware called FluHorse that abuses the Flutter software development framework. “The malware features several malicious Android applications that mimic legitimate applications, most of which have
0 Comments
May 05, 2023Ravie LakshmananCyber Threat / Malware The North Korean state-sponsored threat actor known as Kimsuky has been discovered using a new reconnaissance tool called ReconShark as part of an ongoing global campaign. “[ReconShark] is actively delivered to specifically targeted individuals through spear-phishing emails, OneDrive links leading to document downloads, and the execution of malicious
0 Comments
May 04, 2023Ravie LakshmananServer Security / Vulnerability Cybersecurity researchers have found a way to exploit a recently disclosed critical flaw in PaperCut servers in a manner that bypasses all current detections. Tracked as CVE-2023-27350 (CVSS score: 9.8), the issue affects PaperCut MF and NG installations that could be exploited by an unauthenticated attacker to execute
0 Comments
Microsoft has offered to charge different prices for its Office product with and without its Teams app to stave off a possible EU antitrust investigation and fine, two people familiar with the matter said. Microsoft has been seeking to address the EU competition enforcer’s concerns since last year after Salesforce-owned workspace messaging app Slack complained
0 Comments
May 04, 2023Ravie LakshmananAPI Management / Vulnerability Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive information or backend services. This includes two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API
0 Comments