Ubiquiti has released critical security patches for six vulnerabilities, while other major industry developments include a botnet takedown, new phishing threats, and emerging hardware-based tracking techniques.
Key Points
- Ubiquiti patched six security flaws in its equipment, including one critical vulnerability rated 9.1 and another scoring a perfect 10.0 on the CVE scale.
- A coalition including CrowdStrike and Google successfully disrupted the Glassworm botnet, which targeted open-source repositories like NPM and PyPI to steal credentials.
- The FBI issued a warning regarding Kali365, a "Phishing-as-a-Service" platform that automates credential theft for Microsoft 365 accounts.
- Researchers identified a new side-channel attack called FROST, which uses SSD performance timing via JavaScript to fingerprint devices and monitor user activity.
- Microsoft is enhancing C# memory safety in .NET 11 to prevent common vulnerabilities like use-after-free errors by adopting stricter object lifetime enforcement.