05 Mar Chrome extension turns on YouTube captions when eating noisy chips A new AI-powered Google Chrome extension will automatically turn on YouTube extensions if it detects you are eating noisy chips. […]
05 Mar Microsoft: Exchange updates can install without fixing vulnerabilities Due to the critical nature of recently issued Microsoft Exchange security updates, admins need to know that the updates may have installation issues on servers where User Account Control (UAC) is enabled. […]
05 Mar Ongoing phishing attacks target US brokers with fake FINRA audits The US Financial Industry Regulatory Authority (FINRA) has issued a regulatory notice warning US brokerage firms and brokers of an ongoing phishing campaign using fake compliance audit alerts to harvest information. […]
05 Mar Supermicro, Pulse Secure release fixes for ‘TrickBoot’ attacks Supermicro and Pulse Secure have released advisories warning that some of their motherboards are vulnerable to the TrickBot malware’s UEFI firmware-infecting module, known as TrickBoot. […]
04 Mar CompuCom MSP hit by DarkSide ransomware cyberattack US managed service provider CompuCom has suffered a DarkSide ransomware attack leading to service outages and customers disconnecting from the MSP’s network to prevent the spread of malware. […]
04 Mar VMware releases fix for severe View Planner RCE vulnerability VMware has addressed a high severity unauth RCE vulnerability in VMware View Planner, allowing attackers to abuse servers running unpatched software for remote code execution. […]
04 Mar Researcher bitsquats Microsoft’s windows.com to steal traffic A researcher was able to bitsquat Microsoft’s windows.com domain by cybersquatting variations of windows.com. Adversaries can abuse this tactic to conduct automated attacks or collect data due to the nature of bit flipping. […]
04 Mar Hacked SendGrid accounts used in phishing attacks to steal logins A phishing campaign targeting users of Outlook Web Access and Office 365 services collected thousands of credentials relying on trusted domains such as SendGrid. […]
04 Mar Windows DNS SIGRed bug gets first public RCE PoC exploit A working proof-of-concept (PoC) exploit is now publicly available for the critical SIGRed Windows DNS Server remote code execution (RCE) vulnerability. […]
04 Mar DHS orders agencies to urgently patch or disconnect Exchange servers The Department of Homeland Security’s cybersecurity unit has ordered federal agencies to urgently update or disconnect Microsoft Exchange on-premises products on their networks. […]