Google’s latest Android security update addresses 107 vulnerabilities across Framework, System, kernel and vendor components. The company warns two of the flaws have been exploited in limited, targeted attacks, raising urgency for enterprises to push December updates and OEM patches quickly across fleets.
Source: SecurityWeek
Data breach at South Korea’s “Amazon” Coupang may impact 65% of the population
Online retail giant Coupang apologized after a massive breach prompted an emergency government meeting in Seoul. Early estimates suggest up to 33.7 million accounts could be affected, underscoring third-party and data governance risks at national scale while the investigation continues.
Source: Recorded Future News (The Record)
Police dismantle Cryptomixer, seize $29M in Bitcoin used to launder cybercrime proceeds
European law enforcement took down the Cryptomixer service under Operation Olympia, disrupting a laundering hub tied to ransomware and other illicit activity. Authorities seized servers and funds, signaling growing regulatory pressure on crypto obfuscation services used to cash out attacks.
Source: SecurityWeek
New Albiriox Android MaaS enables full on-device fraud and remote control
Researchers detail Albiriox, a malware-as-a-service banking trojan offered for roughly $720/month, that lets criminals take real-time control of compromised phones. With a hardcoded target list of 400+ financial apps and advanced screen manipulation, it dramatically elevates mobile fraud risk.
Source: SecurityWeek
CISA adds ScadaBR flaw to KEV after hacktivist ICS attack
CISA added CVE-2021-26829, a cross-site scripting bug in ScadaBR, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. OT/ICS operators should prioritize patching and restrict internet exposure of HMIs and consoles to reduce risk of lateral movement and process disruption.
Source: SecurityWeek
Seven-year browser extension campaign backdoored 4.3M Chrome/Edge users
Investigators uncovered a long-running operation that turned popular browser extensions into spyware and backdoors, exfiltrating data to servers in China. Some malicious add-ons reportedly remain in the Microsoft Edge store, making extension inventory and allowlisting a priority control.
Source: The Register
India orders undeletable government app on all new smartphones within 90 days
New directives require handset makers to preinstall the Sanchar Saathi app—meant to combat telecom fraud—on every device sold in India, with removal blocked. The mandate raises significant privacy, enterprise policy, and supply chain governance questions for vendors and organizations operating in the country.
Source: The Register
You May Also Be Interested In...
MuddyWater cyber campaign adds new backdoors in latest wave of attacks
AI models block 87% of single attacks, but just 8% when attackers persist
Accepting Microsoft Teams guest invitations could pose a security risk