Zacco logotypeDigital Trust

Discover

Weekly News Digest

Each week Zacco tracks the latest cyber security threats, current industry news or trends and insights into the latest protection best practice. The Cyber Security Digest is a weekly compilation of the most significant developments within both cybersecurity and digital protection space, with links to further information on how it might affect you, your company or your clients.

Essential reading for cyber security professionals, as well as the general public, to keep you informed of current events and emerging threats.

The gaming hub flaw of HP OMEN affects millions of users

The cyber security firm SentinelOne has discovered a high severity flaw that affected the HP OMEN driver software. This flaw has left millions of gaming computers open to an array of attacks. Taking advantage of this vulnerability, threat actors can escalate privileges to kernel mode without administrator permissions, which can let them disable security products, overwrite system components, and corrupt the operating system.

Read more

Microsoft security patch September 2021

Microsoft has released fixes for 66 vulnerabilities for September 2021. Among 66, 3 are classified as critical 62 as important and 1 as moderate. Among 66 vulnerabilities, 74% of the vulnerabilities are locally exploitable and 20% are remotely exploitable

Read more

Apple fixes iMessage 0-click vulnerability

Apple recently released an update for iPhones, Mac, iPad and Apple Watch, which fixed several vulnerabilities also the once used to bypass OS defence. These were the Zero-Click vulnerability that was used to deploy NSO Pegasus Software

Read more

New Spook JS attack can bypass Google Chrome Site Isolation protection

The University of Michigan, University of Adelaide, Georgia Institute of Technology, and Tel Aviv University has budded the attack as Spook.js which is a JavaScript-based line of attack. An attacker who has control over the browser can know the website the user is browsing, retrieve sensitive data and can even recover login details

Read more

New Private compute services launched by Google for Android

Google introduced Android’s Private compute core Android 12 beta. It is an open-source, secure environment that is private by design, which stores personal information safe, private, and local on the phone. This creates more transparency, which allows users to know which apps are accessing their data and can take more control of the amount of data shared with apps

Read more

REvil Ransomware gang back online after 2 months

REvil Ransomware gang went off the grid after the attack on the technology service provider Kaseya. Now, after two months they are back online. It is also noticed that their Happy Blog data leak site and its payment/negotiation site has resurfaced online. It is not confirmed that if they are back in business

Read more

Microsoft warns about Azure Container Instances (ACI) vulnerability

Microsoft on Wednesday said that it has fixed an account take over vulnerability in Azure Container Instance. This vulnerability could have let attackers execute malicious commands on other user’s containers to steal customer secrets and images deployed in the platform. Microsoft says that this is the first cross-account container takeover in a public cloud

Read more

New Bluetooth bug allow hackers to perform ACE and Dos attacks on millions of devices

Recent research from Singapore university has revealed more than a dozen of vulnerabilities in Bluetooth classic [BR/EDR] protocol. These vulnerabilities can be utilized to implement various malicious actions to execute arbitrary code and take control of vulnerable systems. This vulnerability has affected the SoCs of several companies which include Intel, Qualcomm, Texas Instruments, Infineon (Cypress), and Silicon Labs

Read more

O. MG’s Data cable remotely steals data from Apple devices

O.MG data cables were the first release in Defcon 2019. These cables look like other cables available in the market but pose a security risk. The new cables come with upgraded features. The Geofencing feature allows users to trigger or block payloads, changing keyboard mappings and forge USB devices identities. When connected to a device they can record keystrokes and send the data to attackers over a mile’s distance

Read more

€225 million fine on WhatsApp due to GDPR violation

The instant messaging company WhatsApp which is now owned by Facebook has violated the actual General Data Protection Regulation (GDPR). The Irish data protection commission has now fined €225 million on WhatsApp for the lack of transparency on how it shares the European union’s user data with other Facebook companies

Read more

Data leak affects over 1 million Android Gamers

Security researchers from vpnMentor discovered that the Chinese mobile gaming company suffered a data breach that has affected more than 1 million android gamers. Exposed data includes IP addresses, IMEI numbers, Mobile application package doing the tracking, Device screen size – whether a device is ‘rooted’, Device model, Phone number (if any), Platform (Android/iOS), Net Type (Wi-Fi or cellular), Events (open, log in, level-up, etc).

Read more