News
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 118
- Bitdefender finds preinstalled Android malware you can’t uninstall, seen in 150 countries
- Nippon Columbia malware incident exposes 8.6 million karaoke fan records
- Security Affairs newsletter Round 599 by Pierluigi Paganini – INTERNATIONAL EDITION
Malware
- ASOS breach update: Hackers stole customer details and shopping searches
- Attackers hijack country-code domains to impersonate Google and other services
- Amazon has an uncomfortably personal profile on you
- Meta’s Muse AI files away your friendships, arguments, and secrets
Threat Actors
- Making sure the checks get printed
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
- Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
- Solving the Continuous Authorization Conundrum
Vulnerabilities
- GNUnet P2P Framework 0.26.2
- CVE-2026-59508 Interuse i-Bos CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE-2026-59508 Interuse i-Bos CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Exploit for Deserialization of Untrusted Data in Facebook React