Monday , May 20 2024
Samsung

Samsung mobile devices 25 flaws patched

Samsung has patched 25 vulnerabilities in its mobile devices. This is to strengthen them against code execution and privilege escalation attacks. Samsung is continuously working to improve the security of its smartphones and tablets, protecting the safety and privacy of its users.

Samsung recently disclosed vulnerabilities, known as Samsung Vulnerabilities and Exposures (SVE) items, in their latest security bulletin.

BCSI BLOG POST
SonicWALL Vulnerability Traded; threating for Corporate network in Bangladesh

SonicWALL SSL-VPN provides secure remote access to an organization's internal network and resources through an encrypted SSL connection. This kind...
Read More
BCSI BLOG POST  SonicWALL Vulnerability Traded; threating for Corporate network in Bangladesh

Banking trojan Grandoreiro targeting about 1,500 banks over 60 countries

The banking trojan "Grandoreiro" is spreading widely through a phishing campaign in over 60 countries, aiming at customer accounts of...
Read More
Banking trojan Grandoreiro targeting about 1,500 banks over 60 countries

Australian gov.t warns of ‘large-scale ransomware data breach’

Australian police are investigating a big data breach in a healthcare company after a ransomware attack on Thursday. The website...
Read More
Australian gov.t warns of ‘large-scale ransomware data breach’

Patch Now: CISA Warns of Actively Exploited D-Link Router Vulnerabilities

he U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced that two security flaws in D-Link routers have been added to...
Read More
Patch Now: CISA Warns of Actively Exploited D-Link Router Vulnerabilities

New “Antidot” Banking Trojan disguised Fake Google Play Updates

The "Antidot" Android Banking Trojan pretends to be a Google Play update app and targets Android users in different regions....
Read More
New “Antidot” Banking Trojan disguised Fake Google Play Updates

CISA Published Encrypted DNS Implementation Guidance

CISA published a guide on using Encrypted Domain Name System (DNS) for federal civilian agencies to improve cybersecurity and meet...
Read More
CISA Published Encrypted DNS Implementation Guidance

Cyble Research
Transparent Tribe & SideCopy: A Cyber Alliance Targeting India

Cyble Research and Intelligence Labs found that two cyber threat groups, Transparent Tribe (APT36) and SideCopy, are using advanced strategies...
Read More
Cyble Research  Transparent Tribe & SideCopy: A Cyber Alliance Targeting India

Recordedfuture report
Hackers Exploit GitHub to Spread Malware targeting operating systems

Recorded Future's Insikt Group has discovered a major cyber threat campaign carried out by Russian-speaking hackers, possibly located in the...
Read More
Recordedfuture report  Hackers Exploit GitHub to Spread Malware targeting operating systems

ALERT
CISA issued Seventeen Industrial Control Systems Advisories

ISA issued seventeen advisories about Industrial Control Systems (ICS) on May 16, 2024. These advisories give important information about security...
Read More
ALERT  CISA issued Seventeen Industrial Control Systems Advisories

Intel released 41 Security Advisories Over 90 Vulnerabilities

Intel released 41 security advisories this Patch Tuesday, which contain information about over 90 vulnerabilities in their products. The company...
Read More
Intel released 41 Security Advisories Over 90 Vulnerabilities

The problems affected different parts of Samsung devices, such as the operating system, firmware, and Samsung’s own software.

The vulnerabilities could let bad actors run harmful code on the devices or increase their privileges, getting unauthorized access to important information or system functions.

Samsung quickly responded to security threats, showing their commitment to protecting users from cyber threats.

SVE-2023-1778 (CVE-2024-20866):
There was a vulnerability in the Setupwizard that allowed unauthorized users to bypass device setup authentication. The patch for this vulnerability fixed the issue by removing unnecessary internet access during setup to prevent unauthorized access.

SVE-2023-2193 (CVE-2024-20855):
There was a problem with access control in the multitasking framework, which could have let unauthorized users access and control multitasking functions, allowing privilege escalation attacks. The update fixed this by imposing stricter access controls.

SVE-2023-2265 (CVE-2024-20856):
Samsung’s Secure Folder had a security flaw that allowed hackers to bypass authentication and access private data stored in it. The flaw has been fixed.

SVE-2024-0092 (CVE-2024-20861) and SVE-2024-0096 (CVE-2024-20862):

SveService had vulnerabilities: a use-after-free issue and an out-of-bounds write flaw. Both could allow arbitrary code execution. The patches fixed these memory corruption issues to prevent exploitation.

SVE-2024-0234 (CVE-2024-20865):
An authentication bypass in the bootloader allowed physical attackers to flash any images. The patch has added verification checks to prevent unauthorized flashing, improving the security of the device’s boot process.

SVE-2024-0357 (CVE-2024-20864):
A security issue in DarManagerService was fixed. This issue could have allowed unauthorized access, which could lead to further attacks.

The fixed vulnerabilities were included in a larger security update from Google that addressed issues with the Android operating system.

Check Also

adobe

Adobe Patches Multiple Code Execution Flaws

Adobe released security updates for the vulnerabilities in Adobe software. Bad actors could exploit some …

Leave a Reply

Your email address will not be published. Required fields are marked *