Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

New Wave of Cyberattacks Targeting MS Exchange Servers

By Waqas Cybercriminals are leveraging two exploit chains (ProxyNotShell/OWASSRF) to target Microsoft Exchange servers, as warned by Bitdefender Labs. This is a post from HackRead.com Read the original post: New Wave of Cyberattacks Targeting MS Exchange Servers

HackRead
#vulnerability#web#microsoft#rce#ssrf#auth
Researchers Pioneer PoC Exploit for NSA-Reported Bug in Windows CryptoAPI

The security vulnerability allows attackers to spoof a target certificate and masquerade as any website, among other things.

Over 4,500 WordPress Sites Hacked to Redirect Visitors to Sketchy Ad Pages

A massive campaign has infected over 4,500 WordPress websites as part of a long-running operation that's been believed to be active since at least 2017. According to GoDaddy-owned Sucuri, the infections involve the injection of obfuscated JavaScript hosted on a malicious domain named "track[.]violetlovelines[.]com" that's designed to redirect visitors to unwanted sites. The latest operation is

Micorosft Down – Xbox, Azure, MS365 and MS Teams Down

By Waqas The service outage began on Wednesday, January 25th, 2023, at around 8:30 AM, Greenwich Mean Time (GMT). This is a post from HackRead.com Read the original post: Micorosft Down – Xbox, Azure, MS365 and MS Teams Down

What is Stakeholder-Specific Vulnerability Categorization?

By Waqas It’s a decision tree that’s all about you (and your company). That’s a bit of an oversimplification, but… This is a post from HackRead.com Read the original post: What is Stakeholder-Specific Vulnerability Categorization?

Microsoft to Block Excel Add-ins to Stop Office Exploits

The company will block the configuration files, which interact with Web applications — since threat actors increasingly use the capability to install malicious code.

IoT vendors faulted for slow progress in setting up vulnerability disclosure programs

Manufacturer complacency ‘translates into an unacceptable risk for consumers’, warns security expert

The Unrelenting Menace of the LockBit Ransomware Gang

The notorious Russian-speaking cybercriminals grew successful by keeping a low profile. But now they have a target on their backs.

Emotet Malware Makes a Comeback with New Evasion Techniques

The Emotet malware operation has continued to refine its tactics in an effort to fly under the radar, while also acting as a conduit for other dangerous malware such as Bumblebee and IcedID. Emotet, which officially reemerged in late 2021 following a coordinated takedown of its infrastructure by authorities earlier that year, has continued to be a persistent threat that's distributed via

CVE-2023-21796

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability