Lazarus Trojanized DeFi app for delivering malware

We recently discovered a Trojanized DeFi application that was compiled in November 2021. This application contains a legitimate program called DeFi Wallet that saves and manages a cryptocurrency wallet, but also implants a full-featured backdoor. Continue reading Lazarus Trojanized DeFi app for delivering malware

Google pushes emergency update for Chrome zero-days, the latest in a hectic year for vulnerabilities

Google Chrome has issued emergency updates for two zero-day flaws that attackers are exploiting, the second pair for the browser in a month. It’s been a record year for such flaws, which previously unknown to the vendor. Chrome itself has caught 12 zero-days to date in 2021 compared to eight in all of 2020, according to Google’s Project Zero “0day in the Wild” database, which tracks zero-days. By many measurements, Chrome is the world’s most popular browser, with one report putting its user count at nearly 3.3 billion. That makes it a lucrative target for hackers. There doesn’t appear to be just one answer for the rise in zero-days in 2021, even as more people seem to invest in hacking techniques. Defenders are also improving their own detection skills. “Google is aware the exploits” for the two flaws “exist in the wild,” the company wrote on Thursday. Google otherwise didn’t […]

The post Google pushes emergency update for Chrome zero-days, the latest in a hectic year for vulnerabilities appeared first on CyberScoop.

Continue reading Google pushes emergency update for Chrome zero-days, the latest in a hectic year for vulnerabilities