April 17, 2023, 3:24 p.m. | Olivia William

Information Security Buzz informationsecuritybuzz.com

The Chinese app for e-commerce Pinduoduo is suspected of having used a high-severity Android vulnerability as a zero-day to spy on its users, in line with the U.S. Cybersecurity and Infrastructure Security Agency (CISA). For unpatched Android devices, this security hole in the Android Framework (identified as CVE-2023-20963) enables attackers to increase their privileges without […]

agency android android devices android framework android vulnerability app attackers chinese cisa commerce cve cybersecurity devices e-commerce flaw framework grc high identity and access management (iam) infrastructure infrastructure security malware and vulnerabilities news & analysis pinduoduo privileges security severity spy strategy and planning unpatched vulnerability zero-day

More from informationsecuritybuzz.com / Information Security Buzz

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Security Engineer 2

@ Oracle | BENGALURU, KARNATAKA, India

Oracle EBS DevSecOps Developer

@ Accenture Federal Services | Arlington, VA

Information Security GRC Specialist - Risk Program Lead

@ Western Digital | Irvine, CA, United States

Senior Cyber Operations Planner (15.09)

@ OCT Consulting, LLC | Washington, District of Columbia, United States

AI Cybersecurity Architect

@ FactSet | India, Hyderabad, DVS, SEZ-1 – Orion B4; FL 7,8,9,11 (Hyderabad - Divyasree 3)