Hackers Leverages Teams Chat to Steal Credentials from a Targeted Organization

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Threat intelligence identifies Midnight Blizzard (previously tracked as NOBELIUM) as a highly targeted social engineering attack. The attacker uses compromised Microsoft 365 tenants owned by small businesses to create …

Chrome Security Update: 15 Critical Vulnerabilities Fixed, Over $60,000 Rewarded

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has published a security update for Chrome, updating the Stable channel for Mac and Linux to 115.0.5790.170 and 115.0.5790.170/.171 for Windows.  The release of this upgrade will take place over …

Hackers Exploit Salesforce Email Zero-day Flaw in Facebook Targeted Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploited a 0-day vulnerability in Salesforce’s email services and SMTP servers. Malicious email traffic is often concealed within email gateway services that are considered legitimate and trustworthy. Gateways are …

Ivanti MobileIron API Access Flaw let Attackers Access Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Ivanti’s MobileIron Core 11.2 version. This flaw can be exploited by a malicious actor to gain unauthorized access to restricted functions. MobileIron core is a product …

Hackers Train AI-powered cybercrime tools to Launch Sophisticated Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

There have been several reports recently about cybercriminals using AI-powered tools for malicious purposes which can give a paradise of information for nefarious purposes. Some of the recently popular malicious …

BloodHound: Open-source Pentesting Tool to Map Active Directory & Azure Attack Path

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SpecterOps announced BloodHound Community Edition (CE), which will be available in early access on August 8, 2023! SpecterOps is a cybersecurity company that provides services and training solutions to help …

Cloud Hosting Provider Accused for Providing Infrastructure to 17 State-sponsored Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The potentially unaware C2P entities that serve as legit businesses could be exploited easily by threat actors for attack campaigns and other illicit purposes. While scenario like this could allow …

Hackers Use Google AMP Pages to Bypass Enterprise Email Security Measures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing tactic was discovered that takes advantage of Google Accelerated Mobile Pages (AMP), which is known to be successful in bypassing email security infrastructure. An open-source HTML framework …