04 Mar Researcher bitsquats Microsoft’s windows.com to steal traffic A researcher was able to bitsquat Microsoft’s windows.com domain by cybersquatting variations of windows.com. Adversaries can abuse this tactic to conduct automated attacks or collect data due to the nature of bit flipping. […]
04 Mar Hacked SendGrid accounts used in phishing attacks to steal logins A phishing campaign targeting users of Outlook Web Access and Office 365 services collected thousands of credentials relying on trusted domains such as SendGrid. […]
04 Mar Windows DNS SIGRed bug gets first public RCE PoC exploit A working proof-of-concept (PoC) exploit is now publicly available for the critical SIGRed Windows DNS Server remote code execution (RCE) vulnerability. […]
04 Mar DHS orders agencies to urgently patch or disconnect Exchange servers The Department of Homeland Security’s cybersecurity unit has ordered federal agencies to urgently update or disconnect Microsoft Exchange on-premises products on their networks. […]
03 Mar Cybersecurity firm Qualys likely latest victim of Accellion hacks Cybersecurity firm Qualys is the latest victim to have suffered a data breach after a zero-day vulnerability in their Accellion FTA server was exploited to steal hosted files. […]
03 Mar State hackers rush to exploit unpatched Microsoft Exchange servers Multiple state-sponsored hacking groups are actively exploiting critical Exchange bugs Microsoft patched Tuesday via emergency out-of-band security updates. […]
03 Mar Cash App phishing kit deployed in the wild, courtesy of 16Shop The developer of the 16Shop phishing kit has added a new component that targets users of the popular Cash App mobile payment service. […]
02 Mar Microsoft fixes actively exploited Exchange zero-day bugs, patch now Microsoft has released emergency out-of-band security updates for all supported Microsoft Exchange versions that fix four zero-day vulnerabilities actively exploited in targeted attacks. […]
02 Mar Oxfam Australia confirms data breach after stolen info sold online Oxfam Australia has confirmed a data breach after suffering a cyberattack and their donor databases put up for sale on a hacker forum in January. […]
02 Mar Microsoft 365 Defender Threat Analytics enters public preview Microsoft announced the addition of Threat Analytics for Microsoft 365 Defender customers and the roll-out of Microsoft 365 Insider Risk Management Analytics, both in public preview. […]