A voicemail-themed phishing campaign is hitting specific industry verticals across the country, bent on scavenging credentials that can be used for a range of nefarious purposes.
| LATEST SECURITY NEWS & COMMENTARY | Microsoft 365 Users in US Face Raging Spate of Attacks A voicemail-themed phishing campaign is hitting specific industry verticals across the country, bent on scavenging credentials that can be used for a range of nefarious purposes. MetaMask Crypto-Wallet Theft Skates Past Microsoft 365 Security The credential-phishing attack leverages social engineering and brand impersonation techniques to lead users to a spoofed MetaMask verification page. 56 Vulnerabilities Discovered in OT Products From 10 Different Vendors Deep-dive study unearthed security flaws that could allow remote code execution, file manipulation, and malicious firmware uploads, among other badness. Capital One Attacker Exploited Misconfigured AWS Databases After bragging in underground forums, the woman who stole 100 million credit applications from Capital One has been found guilty. Atlassian Confluence Server Bug Under Active Attack to Distribute Ransomware Most of the attacks involve the use of automated exploits, security vendor says. Internet Explorer Now Retired but Still an Attacker Target Though the once-popular browser is officially now history as far as Microsoft support goes, adversaries won't stop attacking it, security experts say. Russia's APT28 Launches Nuke-Themed Follina Exploit Campaign Researchers have spotted the threat group, also known as Fancy Bear and Sofacy, using the Windows MSDT vulnerability to distribute information stealers to users in Ukraine. GitHub's MFA Plans Should Spur Rest of Industry to Raise the Bar We as industry leaders should be building on what individual platforms like GitHub are doing in two critical ways: demanding third parties improve security and creating more interoperable architectures. The Cybersecurity Diversity Gap: Advice for Organizations Looking to Thrive Companies need to fill some of the 3.5 million empty cybersecurity seats with workers who bring different experiences, perspectives, and cultures to the table. Cut a few doors and windows into the security hiring box. Getting a Better Handle on Identity Management in the Cloud Treat identity management as a first-priority problem, not something to figure out later while you get your business up and running in the cloud. Name That Toon: Cuter Than a June Bug Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card. MORE NEWS / MORE COMMENTARY | |
|
Dark Reading Weekly -- Published By Dark Reading Informa Tech Holdings LLC | Registered in the United States with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
| To opt-out of any future Dark Reading Weekly Newsletter emails, please respond here. | Thoughts about this newsletter? Give us feedback. |
Keep This Newsletter Out Of Your SPAM Folder Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list: | If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation. | We take your privacy very seriously. Please review our Privacy Statement. |
|
|