Cyber Defense Advisors

Month: December 2022

  • by
  • December 2, 2022

CISA Warns of Multiple Critical Vulnerabilities Affecting Mitsubishi Electric PLCs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week released an Industrial Control Systems (ICS) advisory warning of multiple vulnerabilities in Mitsubishi Electric GX Works3 engineering software. “Successful exploitation of these vulnerabilities could allow unauthorized users to gain access to the MELSEC iQ-R/F/L series CPU modules and the MELSEC iQ-R series OPC UA server

Cyber News, Cyber Threat Trends
  • by
  • December 2, 2022

Hackers Sign Android Malware Apps with Compromised Platform Certificates

Platform certificates used by Android smartphone vendors like Samsung, LG, and MediaTek have been found to be abused to sign malicious apps. The findings were first discovered and reported by Google reverse engineer Łukasz Siewierski on Thursday. “A platform certificate is the application signing certificate used to sign the ‘android’ application on the system image,” a report […]

Cyber News, Cyber Threat Trends

‘Black Proxies’ Enable Threat Actors to Conduct Malicious Activity

First used as botnets, their lucrative nature turned them into independent criminal enterprises

Cyber News, Cyber Threat Trends

Google Increases Android Security With Memory-Safe Programming Languages

The number of memory safety vulnerabilities in Android dropped from 223 in 2019 to 85 in 2022

Cyber News, Cyber Threat Trends

Let’s Make Security Easy

You flick through some reels and an ad for “a more private phone” crops up. You scroll through your news feed and catch wind of yet another data breach at a major retailer. You see a post from a friend who says their social media account was hacked. Maybe you don’t think about security every […]

Cyber News, Cyber Threat Trends

How To Help Your Family Protect Their Online Data

Whether you’re standing around the water cooler at work, waiting for your kids at the school gate or sitting around the dinner table, data breaches are without doubt the hot topic of conversation. In late September, we were all shaken when news of the biggest Australian data breach to date broke – a record 10 […]

Cyber News, Cyber Threat Trends

Hackers Use Archive Files and HTML Smuggling to Bypass Detection Tools

HP’s latest report suggests 44% of malware was delivered via archive files in Q3 2022

Cyber News, Cyber Threat Trends
  • by
  • December 2, 2022

Security Announcements at AWS re:Invent 2022

Some thoughts on security announcements to date at AWS re:Invent More posts on AWS Security Watching Werner Vogel’s Keynote In this post I’m just compiling some of the security announcements at AWS re:Invent. I’ll have to go back and take a look at them more in detail later as, unfortunately and fortunately, someone hired me to teach […]

Cyber News, Cyber Threat Trends

Industry Coalition Urges Congress to Hold off on SBOMs Requirements for Defense Contractors

The coalition outlined the need to refine SBOM requirements before making it an obligation for defense contractors

Cyber News, Cyber Threat Trends