A critical vulnerability (CVE-2022-46337) in Apache Derby allows authentication bypass via LDAP injection, rated 9.1 on the CVSS scale. Attackers can exploit this flaw to access or modify sensitive data, create databases, and execute malicious code. Affected versions include 10.1.1.0 to 10.16.1.1. Upgrade to Derby 10.17.1.0 for protection; IBM offers patches for its impacted products.

SuperCard X Android malware use stolen cards in NFC relay attacks
Android devices are being targeted by a new malware-as-a-service (MaaS) platform, SuperCard X. The malware uses NFC relay attacks to conduct fraudulent point-of-sale and ATM