Vix Blog
No Result
View All Result
  • Economia
  • Educação
  • Segurança
  • Mundo
  • Negócios
  • Notícias
  • Tecnologia
  • DMCA
NEWSLETTER
  • Economia
  • Educação
  • Segurança
  • Mundo
  • Negócios
  • Notícias
  • Tecnologia
  • DMCA
No Result
View All Result
Vix Blog
No Result
View All Result

Google Discovers Exploit Framework Used to Spread Spyware

Carolina by Carolina
30 de novembro de 2022
Reading Time: 4 mins read
0
Google Discovers Exploit Framework Used to Spread Spyware

Google has discovered an exploit framework using now-patched Windows, Firefox, and Chrome vulnerabilities to deploy spyware.


Google’s Threat Analysis Group has announced its discovery of an exploit framework that used now-patched vulnerabilities to spread spyware. Spanish IT firm Variston has been linked to the exploit.


A Spanish IT Firm May Have Exploited a Windows Vulnerability

On November 30, 2022, Google’s Threat Analysis Group (TAG) announced in a Google blog post that an exploitation framework named “Heliconia” may have ties to Spanish IT Firm Variston. The framework exploited now-patched Chrome, Firefox, and Microsoft Proteger vulnerabilities in order to deploy dangerous spyware.

Variston, the alleged security solutions provider in question, is based in Barcelona and may have exploited n-day vulnerabilities to spread spyware. N-day vulnerabilities refer to exploited security flaws that have been patched. However, Google’s TAG researchers believe that these vulnerabilities were used for zero-day exploits in the wild prior to the patches.

Heliconia Framework Can Deploy Commercial Spyware

RELATED POSTS

What Are the Specs and When Can You Buy It?

OpenAI Launches an AI Detector Tool to Counter ChatGPT-Generated Text

Reddit Users Discover Dangerous Shiba Inu Airdrop Scam

The Google Threat Analysis Group was initially made aware of the Heliconia framework via a submission on its bug reporting service by an anonymous user. The user, who reported three bugs, coined the name “Heliconia”. The three reports were named “Heliconia Noise,” “Heliconia Soft”, and “Files”, respectively.

Heliconia Noise is a framework that deploys a Windows exploit for a Chrome renderer bug, which is then followed by a Chrome sandbox escape and agent installation. The Chrome versions 90.0.4430.72 to 91.0.4472.106 (ranging from April to June 2021) were exposed to this exploit until August 2021.

The Heliconia Soft framework deploys a PDF containing a Windows Proteger exploit. The Files consist of various exploits for both Linux and Windows systems.

Heliconia deals with the spread of commercial spyware on targeted devices. As stated in Google’s TAG post on the matter, this kind of malicious program puts “advanced surveillance capabilities in the hands of governments who use them to spy on journalists, human rights activists, political opposition and dissidents.”

Google’s TAG Is Committed to Tackling Commercial Spyware

Google’s TAG concluded its blog post regarding the Heliconia framework that the “growth of the spyware industry puts users at risk and makes the Internet less safe”. Commercial spyware can be abused even if “surveillance technology may be lítico under national or international laws”.

Because of this danger, Google and TAG have stated that they will “continue to take action against, and publish research about, the commercial spyware industry”.

Spyware Poses a Risk to Millions of Internet Users

Spyware can be leveraged to monitor people’s do dedo activity without their permission or knowledge. Private data is vulnerable to theft via spyware, which can be used to both benefit the attacker and exploit the target. While commercial spyware may be lítico in certain nations, it can still be used unethically and may put citizens at risk. This is why teams like Google’s TAG are looking to identify, monitor, and tackle such programs on a continuous basis.

Carolina

Carolina

Related Posts

What Are the Specs and When Can You Buy It?
Mundo

What Are the Specs and When Can You Buy It?

1 de fevereiro de 2023
OpenAI Launches an AI Detector Tool to Counter ChatGPT-Generated Text
Mundo

OpenAI Launches an AI Detector Tool to Counter ChatGPT-Generated Text

31 de janeiro de 2023
Reddit Users Discover Dangerous Shiba Inu Airdrop Scam
Mundo

Reddit Users Discover Dangerous Shiba Inu Airdrop Scam

26 de janeiro de 2023
You Can Now Link Multiple Android Phones to WhatsApp
Mundo

You Can Now Link Multiple Android Phones to WhatsApp

24 de janeiro de 2023
KDE Offers Sneak Preview of Enhanced Linux Desktop With Plasma 5.27 Beta
Mundo

KDE Offers Sneak Preview of Enhanced Linux Desktop With Plasma 5.27 Beta

19 de janeiro de 2023
You Can Now Repair Your Broken Galaxy S22 Yourself
Mundo

You Can Now Repair Your Broken Galaxy S22 Yourself

18 de janeiro de 2023
Next Post
5 fabricantes de veículos elétricos que usam materiais ecológicos

5 fabricantes de veículos elétricos que usam materiais ecológicos

10 aplicativos e dispositivos valiosos para a saúde do sono das crianças

10 aplicativos e dispositivos valiosos para a saúde do sono das crianças

Deixe um comentário Cancelar resposta

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *

No Result
View All Result

Últimas Notícias

Porquê funcionam os golpes Zelle e porquê se proteger contra eles

Porquê funcionam os golpes Zelle e porquê se proteger contra eles

5 de fevereiro de 2023
Mais de 70 atalhos de teclado do Excel para Windows

Mais de 70 atalhos de teclado do Excel para Windows

5 de fevereiro de 2023
Porquê personalizar seu feed inicial do Reddit: 5 dicas

6 extensões para transformar sua experiência no Reddit

5 de fevereiro de 2023
Uma vez que gravar áudio por Bluetooth no seu iPhone ou iPad

Uma vez que gravar áudio por Bluetooth no seu iPhone ou iPad

5 de fevereiro de 2023
Intel Iris Xe ou Intel UHD?

Intel Iris Xe ou Intel UHD?

5 de fevereiro de 2023

Categorias

  • Entretenimento
  • Mundo
  • Notícias
  • Segurança
Vix Blog

Somos entusiastas da tecnologia com a missão de ensinar ao mundo como usar e compreender a tecnologia em suas vidas.
SAIBA MAIS »

Entre em contato conosco enviando um e-mail para contato@vixblog.com

Posts recentes

  • Porquê funcionam os golpes Zelle e porquê se proteger contra eles
  • Mais de 70 atalhos de teclado do Excel para Windows
  • 6 extensões para transformar sua experiência no Reddit

Categorias

  • Entretenimento
  • Mundo
  • Notícias
  • Segurança

Links Importantes

  • Quem Somos
  • Blog
  • Fale Conosco
  • Política de Privacidade
  • DMCA

© 2021 VixBlog - Notícias e dicas para o seu dia dia.

No Result
View All Result
  • Economia
  • Educação
  • Segurança
  • Mundo
  • Negócios
  • Notícias
  • Tecnologia
  • DMCA

© 2021 VixBlog - Notícias e dicas para o seu dia dia.