Threat and Vulnerability Roundup for the week of July 30th to August 5th

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Threat and Vulnerability Roundup for this week is out! With great pride, Cyber Writes presents a weekly overview of the most recent cybersecurity news. We highlight notable vulnerabilities and …

New AD CTS Attack Vector Enables Lateral Movement Between Microsoft tenant

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to reports, the threat group known as “Nobelium” who were responsible for the SolarWinds attacks is now discovered to be targeting Microsoft tenants through the new Cross-Tenant Synchronisation (CTS) …

Hackers Using Fake Certificates to Infiltrate Corporate Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Using fake certificates, attackers gain unauthorized access to corporate network resources.  Attackers use such certificates to trick the Key Distribution Center (KDC) to get into the target company’s network. Shadow …

BlueCharlie Hacker Group Builds a 94-Domain Password Stealing Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are evolving their techniques and tools at a rapid pace that is completely changing the current threat scenario. BlueCharlie is a Russia-linked threat group that has been active …

Hackers Leverages Teams Chat to Steal Credentials from a Targeted Organization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Threat intelligence identifies Midnight Blizzard (previously tracked as NOBELIUM) as a highly targeted social engineering attack. The attacker uses compromised Microsoft 365 tenants owned by small businesses to create …

Chrome Security Update: 15 Critical Vulnerabilities Fixed, Over $60,000 Rewarded

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has published a security update for Chrome, updating the Stable channel for Mac and Linux to 115.0.5790.170 and 115.0.5790.170/.171 for Windows.  The release of this upgrade will take place over …

Hackers Exploit Salesforce Email Zero-day Flaw in Facebook Targeted Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploited a 0-day vulnerability in Salesforce’s email services and SMTP servers. Malicious email traffic is often concealed within email gateway services that are considered legitimate and trustworthy. Gateways are …