CISA and the FBI have issued a warning about a critical software vulnerability exploited by the LockBit ransomware group, known as Citrix Bleed. The flaw, disclosed and patched last month, has been exploited since August. Many instances remained unpatched as of last week. Calls intensified to patch the issue following Citrix’s disclosure in October. Boeing was recently targeted by LockBit, leading to the aerospace company sharing technical details with public agencies for further guidance.

Android spyware hidden in mapping software targets Russian soldiers
New Android malware targeting Russian military personnel has been discovered in a fake version of Alpine Quest, a mapping app often used by Russian soldiers.