An unpatched vulnerability affecting the RainLoop webmail client can be exploited to hijack a user’s session and steal their emails, according to application security firm Sonar.
VMware’s Head of Cybersecurity Strategy Discusses Modern Bank Heists
Digital Bank Heists – Because That’s Where the Money Is Today
The financial sector is in the crosshairs of criminal cartels and nation-state actors. Criminals seek a lucrative market, and nation-states treat profit as a form of sanctions-busting.
Audio Codec Made by Apple Introduced Serious Vulnerabilities in Millions of Android Phones
An open source audio codec developed by Apple is affected by serious vulnerabilities that have been pushed to millions of Android devices by some of the world’s largest mobile chipset manufacturers.
Catalan Chief Accuses Spain’s Intelligence Agency of Hacking
The head of Catalonia’s regional government is accusing Spain’s intelligence agency of conducting what he calls “massive political espionage” on the northeastern region’s independence movement and says that relations with Spain’s national authorities are “on hold” as a consequence.
Google, Mandiant Share Data on Record Pace of Zero-Day Discoveries
Google and Mandiant separately called attention to a dramatic surge in the discovery of in-the-wild zero-day attacks and warned that nation-state APT actors, ransomware gangs and private mercenary exploit firms are burning through zero-days at record pace.
Meta Offers Rewards for Flaws Allowing Attackers to Bypass Integrity Checks
Facebook parent company Meta today announced that its bug bounty program will cover vulnerabilities that can be exploited to bypass integrity safeguards.
ICS Exploits Earn Hackers $400,000 at Pwn2Own Miami 2022

Pwn2Own Miami 2022, a hacking contest focusing on industrial control systems (ICS), has come to an end, with contestants earning a total of $400,000 for their exploits.
Today’s Network is Different, Not Dead – Here’s How You Secure It
Access Bypass, Data Overwrite Vulnerabilities Patched in Drupal
Drupal on Wednesday announced the release of security updates to resolve a couple vulnerabilities that could lead to access bypass and data overwrite.
Cisco Patches Virtual Conference Software Vulnerability Reported by NSA
Cisco on Wednesday announced the release of patches for several high-severity vulnerabilities in its products, including a bug reported by the National Security Agency (NSA).












