Tag: security

Watch out for suspicious Microsoft Azure Monitor alerts – it could be this shifty new callback phishing attack

Phishing campaign abuses Microsoft Azure Monitor alerts Fake “suspicious charges” emails bypass protections using legitimate domain Attackers craft alerts with custom messages, similar to past Google Tasks and PayPal abuse Microsoft Azure Monitor is the latest in the long line of legitimate tools being abused in phishing attacks. If you…

Read More

Secure your Microsoft system or suffer the same fate as Stryker – US tells companies to secure corporate accounts

CISA warns US firms after Stryker Intune wipe Urges stronger endpoint management configs, least privilege, MFA, multi-admin approvals FBI and Microsoft coordinating to counter Handala-linked Iranian hacktivists The US Cybersecurity and Infrastructure Security Agency (CISA) is urging businesses in the country to harden their endpoint management system configurations and avoid…

Read More

A $10K Bounty Awaits Anyone Who Can Hack Ring Cameras to Stop Sharing Data With Amazon

The Fulu Foundation, a nonprofit that pays out bounties for removing user-hostile features, is hunting for a way to keep Ring cameras from sending data to Amazon—without breaking the hardware. Source

Read More

Home Depot reportedly left internal systems at risk for over a year

Home Depot exposed a GitHub token for a year, granting access to critical internal systems Researcher warnings were ignored until media intervened, after which the token was revoked Similar leaks across GitHub/GitLab show widespread risks from hardcoded secrets and misconfigured repos Home Depot kept access to its internal systems open…

Read More

Former Accenture employee charged by DoJ for cloud security fraud

A former Accenture employee has been charged by the DoJ The employee is accused of misrepresenting security frameworks to gain and maintain government contracts Accenture didn’t comply with FedRamp, but agencies were led to believe it did The US Justice Department has confirmed a former product manager at Accenture, Hilmer,…

Read More

Hackers posing as law enforcement are tricking Big Tech to get access to private data

Cybercriminals impersonate law enforcement to trick tech firms into handing over user data Tactics include typosquatted police emails & BEC‑compromised official inboxes Tech companies now rely on vetted data‑request portals to reduce fraudulent disclosures While most data theft happens through software vulnerabilities and phished login credentials, sometimes big technology corporations…

Read More