Tag Microsoft

Celebrity TikTok Accounts Hacked with Zero-Click Attack Through DMs

TikTok Confirms Security Breach Targeting High-Profile Accounts TikTok has recently acknowledged a significant security vulnerability that has allowed threat actors to take control of prominent accounts on its platform. This incident, which has raised serious concerns about user safety and data security, was initially reported by Semafor and Forbes, highlighting…

Read MoreCelebrity TikTok Accounts Hacked with Zero-Click Attack Through DMs

Microsoft Releases Fixes for 90 Vulnerabilities, Featuring 10 Critical Zero-Day Flaws

On Tuesday, Microsoft released a set of critical updates addressing a total of 90 security vulnerabilities within its software, including ten zero-day exploits. Notably, six of these zero-days are actively being leveraged in real-world attacks, raising significant concerns regarding the potential for widespread exploitation in the wild. The vulnerabilities span…

Read MoreMicrosoft Releases Fixes for 90 Vulnerabilities, Featuring 10 Critical Zero-Day Flaws

GitHub Vulnerability ‘ArtiPACKED’ Poses Risk of Repository Takeover

A recently identified vulnerability in GitHub Actions artifacts, referred to as ArtiPACKED, poses significant risks to repository security and organizational cloud operations. This attack vector could allow malicious entities to gain unauthorized control over repositories and infiltrate cloud environments associated with these repositories. The vulnerability results from a mix of…

Read MoreGitHub Vulnerability ‘ArtiPACKED’ Poses Risk of Repository Takeover

The Overlooked Vulnerability of Executives: Non-Human Identities

For years, the focus of corporate cybersecurity has been on protecting the perimeter of systems, creating a clear division between secured internal environments and the threatening outside world. Organizations invested in robust firewalls and advanced detection systems, banking on the belief that preventing unauthorized access from external sources was sufficient…

Read MoreThe Overlooked Vulnerability of Executives: Non-Human Identities

China’s Salt Typhoon Breaches AT&T and Verizon, Compromising Wiretap Data: Report

A sophisticated hacking group, known as Salt Typhoon and believed to be linked to China, has infiltrated major U.S. telecom providers AT&T, Verizon, and Lumen Technologies, compromising wiretap systems crucial for criminal investigations. The breach raises significant national security concerns in the United States and jeopardizes critical telecommunications infrastructure. Reports…

Read MoreChina’s Salt Typhoon Breaches AT&T and Verizon, Compromising Wiretap Data: Report

Russian National Charged with Cyber Attacks on Ukraine Prior to 2022 Invasion

Russian National Indicted for Cyber Attacks Against Ukraine Amid Invasion The U.S. Department of Justice has charged a 22-year-old Russian individual, Amin Timovich Stigal, for his alleged involvement in launching disruptive cyber attacks directed at Ukraine and its allied nations during the critical period leading up to Russia’s military invasion…

Read MoreRussian National Charged with Cyber Attacks on Ukraine Prior to 2022 Invasion

Researchers Reveal TLS Bootstrap Vulnerability in Azure Kubernetes Clusters

Cybersecurity experts have recently identified a significant vulnerability within Microsoft Azure Kubernetes Services (AKS) that could be exploited to elevate user privileges and potentially gain unauthorized access to sensitive service credentials used within the cluster. This flaw poses serious risks to organizations leveraging AKS, particularly those using specific configurations like…

Read MoreResearchers Reveal TLS Bootstrap Vulnerability in Azure Kubernetes Clusters

Exploitation of Microsoft MSHTML Vulnerability to Distribute MerkSpy Spyware

Cybersecurity Threat: Surveillance Tool MerkSpy Exploits Microsoft MSHTML Vulnerability Recent reports from Fortinet’s FortiGuard Labs indicate the emergence of a sophisticated surveillance tool known as MerkSpy, which is being used by unidentified threat actors to compromise systems through a now-patched vulnerability in Microsoft’s MSHTML. This malicious campaign is primarily targeting…

Read MoreExploitation of Microsoft MSHTML Vulnerability to Distribute MerkSpy Spyware