Advertisement
Top

Tag: Microsoft


Network security, Security

Microsoft opens early access to AI assistant for infosec, Security Copilot

October 23, 2023

Via: The Register

Microsoft is opening up the early access program for its flagship cybersecurity AI product, which marks the inevitable folding in of Copilot into its infosec suite. First teased in March, Security Copilot is embedded within the Microsoft 365 Defender XDR […]


Threats & Malware, Vulnerabilities

US cybercops urge admins to patch amid ongoing Confluence chaos

October 17, 2023

Via: The Register

US authorities have issued an urgent plea to network admins to patch the critical vulnerability in Atlassian Confluence Data Center and Server amid ongoing nation-state exploitation. The joint cybersecurity advisory from CISA, FBI, and Multi-State Information Sharing and Analysis Center […]


Cyber-crime, Malware

Microsoft Defender thwarted Akira ransomware attack on an industrial engineering firm

October 16, 2023

Via: Security Affairs

Microsoft announced that its Microsoft Defender for Endpoint helped to block a large-scale hacking campaign carried out by Akira ransomware operators (tracked by Microsoft as Storm-1567) The attack took place in early June 2023 and aimed at an industrial engineering […]


Threats & Malware, Vulnerabilities

Calls for Visual Studio security tweak fall on deaf ears despite one-click RCE exploit

October 13, 2023

Via: The Register

Perceived weaknesses in the security of Microsoft’s Visual Studio IDE are being raised once again this week with a fresh single-click exploit. Developed by Zhiniang Peng, principal security researcher and chief architect of security at Sangfor, the proof of concept […]


Threats & Malware, Vulnerabilities

curl vulnerabilities ironed out with patches after week-long tease

October 11, 2023

Via: The Register

After a week of rampant speculation about the nature of the security issues in curl, the latest version of the command line transfer tool was finally released today. Described by curl project founder and lead developer Daniel Stenberg as “probably […]


Cyber warfare, Cyber-crime

Unknown Cyberespionage Group Targeted Taiwan

October 10, 2023

Via: DataBreach Today

A previously undetected cyberespionage group spied against Taiwanese government agencies and the island-country’s manufacturing sector, say cybersecurity researchers. The Symantec Threat Hunter Team doesn’t attribute the threat group to any particular country, other than noting it likely operates “from a […]


Cloud security, Security

Microsoft unveils the next generation of OneDrive – and it might actually make you like using cloud storage

October 4, 2023

Via: TechRadar

Microsoft has officially unveiled the next generation of OneDrive, which is set to bring the cloud storage solution more closely in line with the rest of the company’s offerings, including Microsoft 365 apps like Teams and Outlook. The company is […]


Threats & Malware, Virus & Malware

Microsoft Bing Chat pushes malware via bad ads

September 29, 2023

Via: The Register

Microsoft introduced its Bing Chat AI search assistant in February and a month later began serving ads alongside it to help cover costs. However, some of those adverts served by Microsoft’s own ad platform have turned out to be malicious. […]


Cyber warfare, Cyber-crime

Chinese snoops stole 60K State Department emails in that Microsoft email heist

September 28, 2023

Via: The Register

Chinese snoops stole about 60,000 State Department emails when they broke into Microsoft-hosted Outlook and Exchange Online accounts belonging to US government officials over the summer. “No classified systems were hacked,” said State Department spokesperson Matthew Miller during a press […]


Access control, Security

Windows 11 is officially killing off passwords and bringing in passkeys

September 22, 2023

Via: TechRadar

Microsoft is expanding passkey support with Windows 11, meaning users will soon be able to take better advantage of the new technology. In a blog post on its site, the company said that with the upcoming update to the operating […]


Network security, Security

Broaden your cyber security knowhow at CyberThreat 2023

September 20, 2023

Via: The Register

Cyber security remains a top three priority for most, if not all, organisations. The risks associated with failure to implement adequate defences were once again highlighted by the ransomware incident which impacted several hospital computer systems across the US last […]


Network security, Security

Protecting Your Microsoft IIS Servers Against Malware Attacks

September 8, 2023

Via: The Hacker News

Microsoft Internet Information Services (IIS) is a web server software package designed for Windows Server. Organizations commonly use Microsoft IIS servers to host websites, files, and other content on the web. Threat actors increasingly target these Internet-facing resources as low-hanging […]


Data loss, Threats & Malware

Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security Breach

September 7, 2023

Via: The Hacker News

Microsoft on Wednesday revealed that a China-based threat actor known as Storm-0558 acquired the inactive consumer signing key to forge tokens and access Outlook by compromising an engineer’s corporate account. This enabled the adversary to access a debugging environment that […]


Threats & Malware, Virus & Malware

Phishing-as-a-Service Gets Smarter: Microsoft Sounds Alarm on AiTM Attacks

August 29, 2023

Via: The Hacker News

Microsoft is warning of an increase in adversary-in-the-middle (AiTM) phishing techniques, which are being propagated as part of the phishing-as-a-service (PhaaS) cybercrime model. In addition to an uptick in AiTM-capable PhaaS platforms, the tech giant noted that existing phishing services […]


Threats & Malware, Vulnerabilities

Experts Uncover How Cybercriminals Could Exploit Microsoft Entra ID for Elevated Privilege

August 28, 2023

Via: The Hacker News

Cybersecurity researchers have discovered a case of privilege escalation associated with a Microsoft Entra ID (formerly Azure Active Directory) application by taking advantage of an abandoned reply URL. “An attacker could leverage this abandoned URL to redirect authorization codes to […]


Cyber-crime, Malware

Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates

August 22, 2023

Via: The Hacker News

A previously undocumented threat cluster has been linked to a software supply chain attack targeting organizations primarily located in Hong Kong and other regions in Asia. The Symantec Threat Hunter Team, part of Broadcom, is tracking the activity under its […]


Threats & Malware, Vulnerabilities

Microsoft Releases Patches for 74 New Vulnerabilities in August Update

August 9, 2023

Via: The Hacker News

Microsoft has patched a total of 74 flaws in its software as part of the company’s Patch Tuesday updates for August 2023, down from the voluminous 132 vulnerabilities the company fixed last month. This comprises six Critical and 67 Important […]


Cyber-crime, Malware

LOLBAS in the Wild: 11 Living-Off-The-Land Binaries That Could Be Used for Malicious Purposes

August 8, 2023

Via: The Hacker News

Cybersecurity researchers have discovered a set of 11 living-off-the-land binaries-and-scripts (LOLBAS) that could be maliciously abused by threat actors to conduct post-exploitation activities. “LOLBAS is an attack method that uses binaries and scripts that are already part of the system […]


Network security, Security

Understanding Active Directory Attack Paths to Improve Security

August 8, 2023

Via: The Hacker News

Introduced in 1999, Microsoft Active Directory is the default identity and access management service in Windows networks, responsible for assigning and enforcing security policies for all network endpoints. With it, users can access various resources across networks. As things tend […]


Application security, Security

Google, Microsoft Take Refuge in Rust Language’s Better Security

August 4, 2023

Via: Dark Reading

When Fortanix launched in 2016, the company made a decision: It would commit to the one-year-old Rust’s programming language to benefit from its security strengths and performance. Seven years later, Fortanix’s commitment to Rust has proved to be a success. […]