JPCERT/CC links Japan’s recent data leaks to mobile API abuse and known software flaws, including an exploited Metabase SQL injection bug.
A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
The malware is believed to have been introduced somewhere in the device supply chain, but it remains unclear who is responsible for modifying the firmware or at what stage the tampering occurred.
The malware is embedded directly into the firmware of low-cost Android devices using MediaTek chipsets, giving it system-level privileges that allow it to install and remove applications, grant sensitive permissions, and execute remotely downloaded code without user interaction.
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.
The operator uses mostly throwaway accounts, but researchers identified at least 700 accounts that appear to belong to legitimate developers.
The malicious repositories use convincing README instructions with a download button pointing to a ZIP archive containing the initial payload, SmartLoader, that is used to distribute other malware.
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition.
The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3,000 and Nexus 9,000 Series switches.
“This is an extraordinary glimpse into the distant universe,” team co-leader Manisha Caleb from the Sydney Institute for Astronomy said in a statement sent to Space.com. “We have caught a fast radio burst from a time when the universe was only about three billion years old, and we have used that brief flash of radio light to learn about the matter it has travelled through over billions of years.”
The team’s research was published on Thursday (Oct. 8) in the journal Science.
Summary: Researchers at the University of Oxford have discovered that human microglia can selectively prune away toxic alpha-synuclein aggregates from dopamine-producing neurons without destroying the host nerve cells. Utilizing co-cultures of human induced pluripotent stem cell (iPSC)-derived neurons and microglia, the team demonstrated that microglia employ “trogocytosis”, a precise cellular nibbling mechanism, regulated by GPNMB, P2RY12, and CD22 signaling pathways, along with an IL-10 molecular brake. The findings identify a distinct, neuroprotective microglial subtype that shields neurons in Parkinson’s disease.
When people think of the plague, they might think of medieval peasants with painful lumps under their arms, being treated by doctors wearing creepy bird-like masks.
But the disease still persists today, and can be lethal if not treated quickly.
Now, almost 700 years after the Black Death killed 50 percent of the European population, we may soon have a new vaccine for this notoriously deadly disease.