An unpatched vulnerability affecting the RainLoop webmail client can be exploited to hijack a user’s session and steal their emails, according to application security firm Sonar.
Audio Codec Made by Apple Introduced Serious Vulnerabilities in Millions of Android Phones
An open source audio codec developed by Apple is affected by serious vulnerabilities that have been pushed to millions of Android devices by some of the world’s largest mobile chipset manufacturers.
Google, Mandiant Share Data on Record Pace of Zero-Day Discoveries
Google and Mandiant separately called attention to a dramatic surge in the discovery of in-the-wild zero-day attacks and warned that nation-state APT actors, ransomware gangs and private mercenary exploit firms are burning through zero-days at record pace.
Meta Offers Rewards for Flaws Allowing Attackers to Bypass Integrity Checks
Facebook parent company Meta today announced that its bug bounty program will cover vulnerabilities that can be exploited to bypass integrity safeguards.
ICS Exploits Earn Hackers $400,000 at Pwn2Own Miami 2022

Pwn2Own Miami 2022, a hacking contest focusing on industrial control systems (ICS), has come to an end, with contestants earning a total of $400,000 for their exploits.
Access Bypass, Data Overwrite Vulnerabilities Patched in Drupal
Drupal on Wednesday announced the release of security updates to resolve a couple vulnerabilities that could lead to access bypass and data overwrite.
Cisco Patches Virtual Conference Software Vulnerability Reported by NSA
Cisco on Wednesday announced the release of patches for several high-severity vulnerabilities in its products, including a bug reported by the National Security Agency (NSA).
Organizations Warned of Attacks Exploiting Recently Patched Windows Vulnerability
The US Cybersecurity and Infrastructure Security Agency (CISA) says a recently patched Windows Print Spooler vulnerability has been exploited in attacks.
Serious Vulnerabilities Found in AWS’s Log4Shell Hot Patches
Hot patches made available by Amazon Web Services (AWS) in response to the recent Log4j vulnerabilities could be exploited for privilege escalation or to escape containers, according to Palo Alto Networks.
Oracle Releases 520 New Security Patches With April 2022 CPU
Oracle on Tuesday announced the release of 520 security fixes as part of its April 2022 Critical Patch Update (CPU), including nearly 300 for vulnerabilities that can be exploited remotely without authentication.












