Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day

October 23, 2024 at 02:08PM The North Korean Lazarus hacking group exploited a Google Chrome zero-day (CVE-2024-4947) through a fake DeFi game, targeting cryptocurrency users. Discovered by Kaspersky on May 13, 2024, the exploit gained access to sensitive data. Google issued a fix by May 25, 2024, addressing the vulnerability. ### Meeting Takeaways: **Incident Overview:** … Read more

Chrome 128 Update Resolves High-Severity Vulnerabilities

September 11, 2024 at 05:15AM Google announced a new Chrome 128 update addressing five vulnerabilities, with four high-severity flaws reported by external researchers. The flaws include heap buffer overflow in Skia, use-after-free in Media Router, type confusion in V8 JavaScript engine, and use-after-free in Autofill. Google rewarded bug bounties for the first two security defects … Read more

Google Now Offering Up to $250,000 for Chrome Vulnerabilities

August 28, 2024 at 02:09PM Google significantly increases rewards for Chrome browser vulnerabilities through its VRP. Researchers may now earn up to $250,000 for a single issue, with the highest payouts for memory corruption bugs in non-sandboxed processes. Additional rewards are possible for specific exploit conditions. Google also offers rewards for other vulnerability classes based … Read more

Google fixes fifth Chrome zero-day exploited in attacks this year

May 10, 2024 at 04:09AM Google has released a security update for the Chrome browser to fix the fifth zero-day vulnerability of 2024, which is a high-severity “user after free” issue in the Visuals component. The update addresses potential data leakage, code execution, and crashes. Users are advised to confirm they have the latest version … Read more