Google has patched a “high-severity” vulnerability that may be “under limited, targeted exploitation” in Android devices.
Google issued an advisory stating that the bug, known as CVE-2024-36971, affects the Linux kernel. This kernel is a crucial part of an operating system, connecting the software to the computer’s hardware.
According to Google, a vulnerability lets hackers run code on the device from a distance. Google hasn’t given details about the attacks or the attackers.
By infosecbulletin
/ Saturday , October 5 2024
National Attack Surface (NAS) report for the first half of 2024 reveals that 56.6% of cyberattacks in Bangladesh targeted educational...
Read More
By infosecbulletin
/ Saturday , October 5 2024
A new ransomware campaign is targeting individuals and organizations in the UK and US. The "Prince Ransomware" attack uses a...
Read More
By infosecbulletin
/ Friday , October 4 2024
CISA has issued an urgent alert about critical vulnerabilities being exploited in Synacor’s Zimbra Collaboration and Ivanti’s Endpoint Manager (EPM)....
Read More
By infosecbulletin
/ Friday , October 4 2024
ISACA 2024 survey report reveals that 66% of cybersecurity professionals find their jobs more stressful now than five years ago....
Read More
By infosecbulletin
/ Friday , October 4 2024
A recent study by ISACA shows that almost two-thirds of cybersecurity professionals report increasing job stress. The 2024 State of...
Read More
By infosecbulletin
/ Friday , October 4 2024
In September, cybersecurity experts discovered 31 new ransomware variants that threaten individuals and businesses. These programs encrypt valuable data, making...
Read More
By infosecbulletin
/ Thursday , October 3 2024
New guidance on ransomware, released during this week's International Counter Ransomware Initiative (CRI) meeting, encourages victims to report attacks to...
Read More
By infosecbulletin
/ Thursday , October 3 2024
Over 14 new security flaws have been found in DrayTek routers for homes and businesses, which could allow attackers to...
Read More
By infosecbulletin
/ Wednesday , October 2 2024
Hackers are exploiting a recently revealed RCE vulnerability in Zimbra email servers that can be activated by sending specially crafted...
Read More
By infosecbulletin
/ Wednesday , October 2 2024
CISA warns of two serious vulnerabilities in Optigo Networks ONS-S8 Aggregation Switches, which could allow authentication bypass and remote code...
Read More
In order for the exploit to work, the attacker must have system-level privileges, which are the highest level of access permissions.
Google’s August update fixed 47 flaws, including some in Arm, Imagination Technologies, MediaTek, and Qualcomm components. Most of these flaws were rated as “high severity.”
Clement Lecigne from Google’s Threat Analysis Group found a new Android zero-day. He usually reports on zero-day flaws used in espionage attacks.
Google researchers recently warned that zero-day exploits, which can compromise devices before their vulnerabilities are known, are increasingly being used by nation-state hackers and cybercriminals.
According to a report from Google in March, they found that there were 97 zero-day exploits in 2023, compared to 62 in 2022. This is a 50 percent increase. Out of these exploits, 48 were done by spies and 49 were done by hackers looking for financial gain.