Category: Kamban

DigiCert is warning that it will be mass-revoking SSL/TLS certificates due to a bug in how the company verified if a customer owned or operated a domain and requires impacted customers to reissue certificates within 24 hours. It is unclear how many certificates will be revoked during this process, but the company says it affects approximately 0.4% of the…

Read More

Organizations invest time and money into staying safe from cyber threats, so it’s critical they can measure how well their cybersecurity investments are paying off. Take password policies. Every organization has one (even if it’s the standard settings in Active Directory) and they may have additional password management software on top. But if you’re not…

Read More

Microsoft is investigating an ongoing and widespread outage blocking access to some Microsoft 365 and Azure services. “We’re currently investigating access issues and degraded performance with multiple Microsoft 365 services and features. More information can be found under MO842351 in the admin center,” Redmond said. However, many users report having issues connecting to the Microsoft 365…

Read More

Image: MidjourneyThe United Kingdom’s Information Commissioner’s Office (ICO) revealed today that the Electoral Commission was breached in August 2021 because it failed to patch its on-premise Microsoft Exchange Server against ProxyShell vulnerabilities. Tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, these security flaws were chained to hack into the commission’s Exchange Server 2016 and deploy web shells,…

Read More

On February 21, 2024, Change Healthcare, a subsidiary of UnitedHealth Group and one of the largest healthcare payment processing companies in the United States, fell victim to a devastating ransomware attack. This incident, which has been described as the most significant and consequential cyberattack against the U.S. healthcare system in history, has had far-reaching implications…

Read More

A new version of the Android spyware ‘Mandrake’ has been found in five applications downloaded 32,000 times from Google Play, the platform’s official app store. Bitdefender first documented Mandrake in 2020, with the researchers highlighting the malware’s sophisticated spying capabilities and noting that it has operated in the wild since at least 2016. Kaspersky now…

Read More

Microsoft Outlook can be turned into a C2 beacon to remotely execute code, as demonstrated by a new red team post-exploitation framework named “Specula,” released today by cybersecurity firm TrustedSec. This C2 framework works by creating a custom Outlook Home Page using WebView by exploiting CVE-2017-11774, an Outlook security feature bypass vulnerability patched in October 2017.…

Read More

The rise of AI in cybersecurity presents both significant benefits and challenges. AI enhances threat detection, automates responses, and reduces costs, transforming the cybersecurity landscape. AI has been leveraged to predict attacker moves and detect vulnerabilities with high accuracy. However, it has also enabled sophisticated cyberattacks, such as deepfakes and adaptive malware, which can evade…

Read More

Apple has released the iOS 18.1 Beta to developers, allowing them to test some of its upcoming AI-powered Apple Intelligence features before they are released for testing in the public previews. Apple Intelligence was first unveiled at the company’s 2024 Worldwide Developer Conference, revealing Apple’s AI strategy for upcoming devices. The new AI platform introduces a…

Read More

Three individuals who orchestrated a massive software pirating operation involving the sale of Avaya business telephone system software licenses worth over $88,000,000 have been sentenced to prison. The three men, Raymond Bradley “Brad” Pearce, Dusti O. Pearce, and Jason M. Hines, were also ordered to forfeit large amounts of money as part of their sentencing,…

Read More