Category: News

Adobe Cloud Abused to Steal Office 365, Gmail Credentials

Threat actors are creating accounts within the Adobe Cloud suite and sending images and PDFs that appear legitimate to target Office 365 and Gmail users, researchers from Avanan discovered.

Widespread, Easily Exploitable Windows RDP Bug Opens Users to Data Theft

Most Windows versions are at risk of remote, unprivileged attackers abusing RDP from the inside to hijack smart cards and get unauthorized file system access.

Amazon, Azure Clouds Host RAT-ty Trio in Infostealing Campaign

A cloudy campaign delivers commodity remote-access trojans to steal information and execute code.

Stolen TikTok Videos, Bent on Fraud, Invade YouTube Shorts

Scammers easily game YouTube Shorts with viral TikTok content, bilking both creators and users.

New York AG Warns 17 Firms of Credential Attacks

Sponsored: Password security is highlighted in attorney general warning to New York state businesses.

Phishers Rip Off High-Profile EA Gamers

Electronic Arts blamed “human error” after attackers compromised customer support and took over and drained some of the top FIFA Ultimate Team player accounts.

Here’s REALLY How to Do Zero-Trust Security

It’s not about buying security products! Joseph Carson, chief security scientist from ThycoticCentrify, offers practical steps to start the zero-trust journey.

Microsoft Faces Wormable, Critical RCE Bug & 6 Zero-Days

The large January 2022 Patch Tuesday update covers nine critical CVEs, including a self-propagator with a 9.8 CVSS score.

MacOS Bug Could Let Creeps Snoop On You

The flaw could allow attackers to bypass Privacy preferences, giving apps with no right to access files, microphones or cameras the ability to record you or grab screenshots.

WordPress Bugs Exploded in 2021, Most Exploitable

Record-number WordPress plugin vulnerabilities are wicked exploitable even with low CVSS scores, leaving security teams blind to their risk.