How 1-Time Passcodes Became a Corporate Liability

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Phishers are enjoying remarkable success using text messages to steal remote access credentials and one-time passcodes from employees at some of the world’s largest technology companies and customer support firms. …

Critical Atlassian Bitbucket Server and Data Center Flaw Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian revealed a critical security flaw in Bitbucket Server and Data Center that allows attackers to execute malicious code on vulnerable instances. The critical flaw is tracked as (CVE-2022-36804), a …

AiTM Phishing Attack Targeting Enterprise Users of Microsoft & Gmail Email Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An AiTM-based phishing campaign targeting enterprise users of Microsoft products such as email services. Even Google Workspace users have also been targeted by threat actors behind a large-scale campaign. AiTM …

ChromeOS Remote Memory Corruption Flaw Let Attackers Perform DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft identified a memory corruption vulnerability in ChromeOS triggered remotely, which could allow attackers to carry out either a denial-of-service (DoS) or remote code execution (RCE). Researchers mention that the …

8-Year-Old Linux Kernel Bug ‘No Pipe but as Nasty as Dirty Pipe’ Found

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have revealed details about a long-standing security vulnerability that has been active in the Linux kernel for over eight years. The cybersecurity analysts from Northwestern University (Zhenpeng Lin, Yuhang …

Critical Amazon Ring Flaw Could Allow Attackers to Access Camera Recordings

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Checkmarx, a global software security company based in Atlanta observed a vulnerability in the Ring Android app that could allow a malicious application installed on the user’s phone to expose …