Security Affairs newsletter Round 334

A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box.

If you want to also receive for free the international press subscribe here.

Threat actors exploit a flaw in Coinbase 2FA to steal user fundsFlubot Android banking Trojan spreads via fake security updatesThTim’s RED Team Research reports 3 new CVEs, two of which in 4G/5GBaby died at Alabama Springhill Medical Center due to cyber attackHydra Android trojan campaign targets customers of European banksNeiman Marcus discloses data breach, payment card data exposedGoogle fixes 2 new actively exploited zero-day flaws in ChromeWeaponizing Apple AirTag to lure users to malicious sitesExperts show how to make fraudulent payments using Apple Pay with VISA on locked iPhonesPopular Android apps with 142.5 million collective installs leak user dataThreat actors use recently discovered CVE-2021-26084 Atlassian ConfluenceCISA releases Insider Risk Mitigation Self-Assessment ToolFacebook released Mariana Trench tool to find flaws in Android and Java appsExpert discloses new iPhone lock screen vulnerability in iOS 15GriftHorse malware infected more than 10 million Android phones from 70 countriesNSA, CISA release guidance on hardening remote access via VPN solutionsGroup-IB CEO was put under arrest on treason chargesExperts observed for the first time FinFisher infections involving usage of a UEFI bootkitTrend Micro fixes a critical flaw in ServerProtec Solution, patch it now!A complete PoC exploit for CVE-2021-22005 in VMware vCenter is available onlineRussia-linked Nobelium APT group uses custom backdoor to target Windows domainsERMAC, a new banking Trojan that borrows the code from Cerberus malwareNew BloodyStealer malware is targeting the gaming sectorExpert found RCE flaw in Visual Studio Code Remote Development ExtensionJupyter infostealer continues to evolve and is distributed via MSI installersTelegram is becoming the paradise of cyber criminalsGerman Federal Office for Information Security (BSI) investigates Chinese mobile phonesPort of Houston was hit by an alleged state-sponsored attackJSC GREC Makeyev and other Russian entities under attackGoogle TAG spotted actors using new code signing tricks to evade detectionFollow me on Twitter: @securityaffairs and Facebook

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}

try {
window._mNHandle.queue.push(function (){
window._mNDetails.loadTag(“816788371”, “300×250”, “816788371”);
});
}
catch (error) {}
Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

The post Security Affairs newsletter Round 334 appeared first on Security Affairs.