Context over chaos. Disconnected technologies, siloed data, and reactive processes can only get you so far. Protecting businesses in today’s threat landscape demands more than a set of security tools – it requires context.
That's where Avertium comes in
Security. It’s in our DNA. It’s elemental, foundational. Something that an always-on, everything’s-IoT-connected world depends on.
Helping mid-to-enterprise organizations protect assets and manage risk is our only business. Our mission is to make our customers’ world a safer place so that they may thrive in an always-on, connected world.
Best-in-class technology from our partners... backed by service excellence from Avertium.
Interested in becoming a partner?
With Avertium's deal registration, partners can efficiently and confidently connect with Avertium on opportunities to protect your deals.
Microsoft Copilot for Security analyzes and synthesizes high volumes of security data which can help healthcare cybersecurity teams do more with less.
Dive into our resource hub and explore top
cybersecurity topics along with what we do
and what we can do for you.
On March 23, 2022, Google was alerted about a dangerous zero-day vulnerability found in all Chromium based browsers. An anonymous sender discovered the vulnerability, which is being tracked as CVE-2022-1096. The bug is a type confusion vulnerability and is currently being exploited by threat actors in the wild – making all Chromium based browsers vulnerable to attacks. The browsers included are: Microsoft’s Edge, Amazon Silk, Brave, Opera, Samsung Internet, Vivaldi, and Yandex.
CVE-2022-1096 affects 2 billion users and the threat level is rated “high” by Google. The vulnerability is a type confusion weakness located in the Chrome V8 JavaScript and WebAssembly engine. This flaw allows threat actors to execute arbitrary code on victim devices and allows the threat actor to trick Chrome into running malicious code. V8 is a component within Chrome that processes JavaScript, which is the engine that’s at the heart of Chrome.
Type confusion is a coding issue that happens when a threat actor creates two pointers to the same object with incompatible type tags – tricking the recipient into thinking that they are being sent valid data when they are not. Attacks on the V8 component of Chrome are not common but are among the most dangerous. Google has not released the details surrounding the bug because their policy is to restrict details until an update is installed by a majority of its users.
“Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.” - Google
CISA has ordered that all private and public sectors patch devices as soon as possible. Although Google has released an emergency update with a security fix in Chrome (99.0.4844.84), an official patch for Windows, Mac, and Linux will not be released for a couple of weeks. CVE-2022-1069 has come after two North Korean state-sponsored threat actors exploited another Chrome zero-day flaw (CVE-2022-0609).
CVE-2022-0609 is a remote code execution (RCE) flaw that allowed for threat actors to exploit a use-after-free vulnerability found in Chrome’s animation component. The vulnerability was found by Google’s TAG team and was exploited by two groups, tracked as Operation Dream Job and Operation AppleJeus. The threat actors targeted U.S. based organizations within news media, IT, cryptocurrency, and fintech industries. The vulnerability has since been successfully patched by Google.
CVE-2022-1096
CVE-2022-0609
Google Issues Warning For Billions Of Chrome Users (forbes.com)
Google Chrome Zero-Day Bugs Exploited Weeks Ahead of Patch | Threatpost
Chrome Releases: Stable Channel Update for Desktop (googleblog.com)
CVE-2022-1096 - Security Update Guide - Microsoft - Chromium: CVE-2022-1096 Type Confusion in V8
CISA warns orgs to patch actively exploited Chrome, Redis bugs (bleepingcomputer.com)
Brave Release Notes | Brave Browser
Google Chrome zero-day fix issued (scmagazine.com)
Countering threats from North Korea (blog.google)
You're Not My Type (Ch. 5, Sec. 7) [Securing Java]
Chrome for Mac update fixes a critical security hole | Macworld
Chrome Releases: Stable Channel Update for Desktop (googleblog.com)
Related Reading:
Authentication Company, Okta, Breached by Lapsus$
Contact us for more information about Avertium’s managed security service capabilities.