Zacco logotypeDigital Trust

Discover

Weekly News Digest

Each week Zacco tracks the latest cyber security threats, current industry news or trends and insights into the latest protection best practice. The Cyber Security Digest is a weekly compilation of the most significant developments within both cybersecurity and digital protection space, with links to further information on how it might affect you, your company or your clients.

Essential reading for cyber security professionals, as well as the general public, to keep you informed of current events and emerging threats.

Tor browser not to be used until critical Firefox bugs are fixed

The Maintainers of the Talis project have issued a warning that the Tor browser bundled with the operating system is unsafe for accessing or entering sensitive information. This issue comes out after Mozilla issued fixes for two critical Zero-day flaws in its Firefox browser, a modified version of this acts as the base for the Tor browser.

Read more

Android app exposed to High Severity vulnerability

Security researchers from Microsoft have identified a high severity vulnerability in a framework used in Android apps. Multiple large mobile service providers have been observed to have security flaws in their apps. All the involved parties have taken the necessary steps to fix it.

Read more

Nikkei an Asian media company suffered a Ransomware attack

Nikkei Japanese-based media company disclosed a ransomware attack on Thursday. Unauthorised access to servers was detected on 13th May and it was immediately shut down to minimize the impact. The compromised servers likely contained customer data but the company is not aware of the data leak.

Read more

Google fixes a high severity bug

Google addressed a high severity bug in the OAuth client library for Java. The vulnerability tracked as CVE-2021-22573 has a severity point of 8.7 out of 10. The vulnerability if compromised would have allowed threat actors to compromise tokens and deploy arbitrary payloads.

Read more

Poisoned resume sent to steal credentials and bank details

Hackers conducted a phishing campaign which had a malicious zip file with “more-eggs” malware that targeted job hunting professionals on Linkedln. The malware steals credentials like usernames and passwords for corporate bank accounts, email accounts, and IT admin accounts.

Read more