Apple, an American multinational technology firm, has released security upgrades for iOS, iPadOS, macOS, and Safari to address a new WebKit vulnerability that has been actively exploited in the wild. This is the company's third zero-day fix since early 2022, as per sources. The vulnerability, which has been assigned the number CVE-2022-22620, is a use-after-free flaw in the WebKit web browser engine used by Safari. It can be exploited by sending specially crafted web content, resulting in arbitrary code execution. Further, the patches are available for iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation), iPhone 6s and later, as well as macOS devices running Big Sur and macOS Catalina, as well as a standalone Safari update.
The ongoing TeamPCP software supply chain campaign has compromised the official Microsoft DurableTask Python client hosted on PyPI. Researchers identified malicious versions of the...
Security researchers discovered a software supply chain attack involving a malicious Go package named github.com/shopsprint/decimal, a typosquatted clone of the legitimate github.c...
Security researchers have uncovered a new information-stealing malware called Gremlin Stealer that employs advanced evasion and infrastructure-hiding techniques to compromise Windo...