Remove Cloud Remove Libraries Remove Video
article thumbnail

Kalay cloud platform flaw exposes millions of IoT devices to hack

Security Affairs

FireEye Mandiant researchers have discovered a critical vulnerability in the Kalay cloud platform that exposes millions of IoT devices to attacks. Most of the devices using the platform are video surveillance products such as IP cameras and baby monitors, an attacker could exploit this flaw to eavesdrop audio and video data.

IoT 306
article thumbnail

Microsoft March 2022 Patch Tuesday updates fix 89 vulnerabilities

Security Affairs

Below is the complete list of vulnerabilities addressed by Microsoft: Tag CVE ID CVE Title Severity.NET and Visual Studio CVE-2022-24512.NET NET and Visual Studio Remote Code Execution Vulnerability Important.NET and Visual Studio CVE-2022-24464.NET

Libraries 291
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Free Download Manager backdoored to serve Linux malware for more than 3 years

Security Affairs

The executable is a backdoor that accesses the Linux API and invokes syscalls using the statically linked dietlibc library. “While checking videos on Free Download Manager that are hosted on YouTube, we identified several tutorials demonstrating how to install this software on Linux machines.” ” continues the report.

Cloud 329
article thumbnail

OnionPoison: malicious Tor Browser installer served through a popular Chinese YouTube channel

Security Affairs

The channel has more than 180,000 subscribers and according to Kaspersky the video with the malicious link had more than 64,000 views at the time of the discovery. The video was posted on January 2022, and according to Kaspersky’s telemetry, the first victims were compromised in March 2022.

Libraries 250
article thumbnail

Patch Tuesday, October 2023 Edition

Krebs on Security

However, as Bleeping Computer pointed out , this flaw is caused by a weakness in the open-source “ libvpx ” video codec library, which was previously patched as a zero-day flaw by Google in the Chrome browser and by Microsoft in Edge , Teams , and Skype products.

Libraries 290
article thumbnail

Attackers use encrypted RPMSG messages in Microsoft 365 targeted phishing attacks

Security Affairs

They are low volume, targeted, and use trusted cloud services to send emails and host content (Microsoft and Adobe). The page only displays a “Loading…Wait” message in the title bar, while in the background it relies on a Javascript that collects system information. “These phishing attacks are challenging to counter.

article thumbnail

My Take: Is Amazon’s Alexa+ a Gutenberg moment — or a corporate rerun of history’s greatest co-opt?

The Last Watchdog

It redefined logistics, rewrote cloud economics, and now positions itself to dominate the AI layer of reality itself. Whats more, it has fully integrated these capabilities into consumer interfacesfrom Prime Video to Amazon Pharmacy, from Alexa devices to Kuiper satellites. Amazon wasnt just an e-commerce innovator.