Friday , October 18 2024

infosecbulletin

ESET RESEARCH
“eXotic” spyware espionage campaign targets India and Pakistan

phone

ESET researchers found a spying campaign targeting Android users. The campaign uses fake messaging apps that include XploitSPY malware. The campaign, called eXotic Visit, has been active from November 2021 to the end of 2023. Malicious Android apps were distributed through targeted campaigns using dedicated websites and the Google Play …

Read More »

CISA Releases Nine Industrial Control Systems Advisories

CISA

CISA issued nine advisories about Industrial Control Systems (ICS) on April 11, 2024. These advisories give important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-102-01 Siemens SIMATIC S7-1500 ICSA-24-102-02 Siemens SIMATIC WinCC ICSA-24-102-03 Siemens RUGGEDCOM APE1808 before V11.0.1 ICSA-24-102-04 Siemens RUGGEDCOM APE1808 ICSA-24-102-05 Siemens Scalance W1750D ICSA-24-102-06 …

Read More »

Apple alerts 92 nations to mercenary spyware attacks

Apple

Apple warned users in 91 other countries about a possible “mercenary spyware attack”. Apple notified Reuters that the company found evidence of attackers attempting to remotely compromise iPhones. Mercenary spyware attacks are rare but much more sophisticated than regular cybercriminal activity or malware, as stated in the email. Apple also …

Read More »

CISA Announces Malware Next-Gen Analysis

CISA

CISA has launched a new malware analysis system called Malware Next-Gen. It allows organizations to submit malware samples and suspicious artifacts for analysis, helping CISA to better support partners by automating analysis of new malware and improving cyber defense efforts. Network defenders need timely and useful information about malware, including …

Read More »

Fortinet Releases Security Updates for Multiple Products

Fortinet

Fortinet has released security updates for various products, including OS and FortiProxy, to fix vulnerabilities that could allow a cyber threat actor to take control of a system. CISA encourages users and administrators to take the following steps for enhanced security: FR-IR-23-345 FortiClientMac – Lack of configuration file validation: An …

Read More »