Tag: EN

Forgotten UEFI shims undermining Secure Boot

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities This article has been indexed from WeLiveSecurity Read the original article: Forgotten UEFI shims undermining Secure Boot

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below – @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) “The This…

Microsoft Patches 570 CVEs in Record Patch Tuesday

Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes This article has been indexed from www.infosecurity-magazine.com Read the original article: Microsoft Patches…

OpenAI Plans Smart Speaker In First Hardware Foray

Start-up reportedly planning to launch ChatGPT-powered speaker this year, as it faces Apple lawsuit claiming theft of hardware secrets This article has been indexed from Silicon UK Read the original article: OpenAI Plans Smart Speaker In First Hardware Foray

SonicWall warns of active exploitation of two SMA 1000 zero-days

SonicWall warns of active attacks exploiting two SMA 1000 zero-days, including a flaw enabling arbitrary command execution. SonicWall confirmed the active exploitation of two zero-day vulnerabilities affecting Secure Mobile Access (SMA) 1000 appliances. The vulnerabilities were internally discovered and reported…

Fluke – 821,100 breached accounts

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact…

This fake Apple app can unlock your Mac’s password vault

Disguised as Apple’s CrashReporter, CrashStealer steals passwords, browser data, crypto wallets, and other sensitive information. This article has been indexed from Malwarebytes Read the original article: This fake Apple app can unlock your Mac’s password vault

AWS retools Security Hub for AI and multicloud threats

AWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings was never the hard part.…