Wednesday , November 6 2024
android

Google fixes two Android zero-days: Demand Immediate Patching

In its November 2024 security update, Google fixed 40 vulnerabilities in Android, including two that are actively exploited: CVE-2024-43047 and CVE-2024-43093.

Google’s announcement gives minimal information about the exploitation, stating only that “there are indications that the following may be under limited, targeted exploitation.”

APT36 to attack Windows Systems Absuing Google Drive & Slack

ElizaRAT is malware that mainly targets Windows systems and acts as a remote access tool (RAT), allowing attackers to access...
Read More
APT36 to attack Windows Systems Absuing Google Drive & Slack

Google fixes two Android zero-days: Demand Immediate Patching

In its November 2024 security update, Google fixed 40 vulnerabilities in Android, including two that are actively exploited: CVE-2024-43047 and...
Read More
Google fixes two Android zero-days: Demand Immediate Patching

GitHub launched an AI tool to build apps without code

GitHub has launched an AI tool called 'Spark' that allows users to create apps using natural language, eliminating the need...
Read More
GitHub launched an AI tool to build apps without code

Hacker offer Titas gas root access to sale

"A threat actor has reportedly claimed to gain root-level access to Titas Gas’s firewall server and is actively offering this...
Read More
Hacker offer Titas gas root access to sale

New malware FakeCall intercepts your calls to the bank

Zimperium researchers have found a new version of FakeCall malware for Android that threatens financial security. This malware redirects users'...
Read More
New malware FakeCall intercepts your calls to the bank

Hikvision Patches Security Flaw in Network Cameras

Hikvision, a top provider of network cameras, has issued firmware updates to fix a security vulnerability that could reveal users'...
Read More
Hikvision Patches Security Flaw in Network Cameras

SonicWall report
Government Sector faces 236% Surge in Malware Attacks

Global threat actors have significantly increased attacks on government sectors, with malware-driven attempts rising by triple digits in the first...
Read More
SonicWall report  Government Sector faces 236% Surge in Malware Attacks

Bangladesh Kubernetes User Group Meetup successfully completed

Meetup of Bangladesh Kubernetes User Group was held at Banani Club 9294, Dhaka on Thursday, 31 October 2024. A lively...
Read More
Bangladesh Kubernetes User Group Meetup successfully completed

Bangladesh Bank issues cyber threat alert

Bangladesh Bank issues alert on cyber threat. In its alert the central bank said, according to Bangladesh cyber security intelligence...
Read More
Bangladesh Bank issues cyber threat alert

Hacker claim data breach: bank confirms blaming third party

Interbank, a major financial institution in Peru, has confirmed a data breach after a hacker leaked stolen data online. Formerly...
Read More
Hacker claim data breach: bank confirms blaming third party

CVE-2024-43047 is a critical vulnerability (CVSS 7.8) found in Qualcomm’s Digital Signal Processor (DSP) service. Discovered by Google Project Zero, Amnesty International’s Security Lab, and researcher Conghui Wang, this zero-day issue affects many Qualcomm chipsets. Exploiting this use-after-free vulnerability could allow attackers to gain higher privileges and compromise devices. Qualcomm released a patch in October, and its inclusion in the November Android security update will ensure wider distribution and fixes.

The update is crucial due to the active exploitation of CVE-2024-43093, a privilege escalation vulnerability affecting Android versions 12, 13, 14, and 15. This flaw puts a large part of the Android ecosystem at risk.

In typical fashion, Google is delivering the update in two patch levels:

November 1 Patch Level (2024-11-01): Focuses on important Android parts, like the system and framework.

November 5 Patch Level (2024-11-05): Targets vulnerabilities in specific hardware components, including those from Qualcomm, MediaTek, and Imagination Technologies.

Android users should install the November security update immediately when it’s available. Quick action is essential to protect against the active exploitation of vulnerabilities.

Check Also

Internet archive

2nd time hacker breached Internet Archive

The Internet Archive was breached again, this time through their Zendesk email support platform, following …

Leave a Reply

Your email address will not be published. Required fields are marked *