April 22, 2022 at 01:21PM

■■■■■ Hackers earn $400K for zero-day ICS exploits demoed at Pwn2Own. https://mobile.twitter.com/thezdi/status/1517155487401189376 https://www.bleepingcomputer.com/news/security/hackers-earn-400k-for-zero-day-ics-exploits-demoed-at-pwn2own/ https://t.me/cKure/11241

April 21, 2022 at 10:43PM

■■■□□ Data-Leak: Bob’s Red Mill Natural Foods issued a data breach notice on April 15 after learning that it had fallen victim to a data scraping cyber-attack that began two months ago. https://ago.vermont.gov/blog/2022/04/15/bobs-red-mill-natural-foods-data-breach-notice-to-consumers/ https://t.me/cKure/11236

April 21, 2022 at 05:12PM

■■■■■ Zero-Day: Three security vulnerabilities have been disclosed in the audio decoders of Qualcomm and MediaTek chips that, if left unresolved, could allow an adversary to remotely gain access to media and audio conversations from affected mobile devices. The impact of an RCE vulnerability can range from malware execution to an attacker gaining control over…

April 20, 2022 at 12:39PM

■■■■■ More than 100 different Lenovo consumer laptop computers, used by millions of people worldwide, contain firmware-level vulnerabilities that give attackers a way to drop malware that can persist on a system even after a hard-drive replacement or operating system re-install. Two of the vulnerabilities (CVE-2021-3971 and CVE-2021-3972) involve Unified Extensible Firmware Interface (UEFI) drivers…

April 19, 2022 at 03:26PM

■■■■□ Zero-Day: Newly found zero-click iPhone exploit used in NSO spyware attacks. https://www.bleepingcomputer.com/news/security/newly-found-zero-click-iphone-exploit-used-in-nso-spyware-attacks/ https://t.me/cKure/11232