Aggregator
CVE-2024-54418 | Diversified Technology DTC Documents Plugin up to 1.1.05 on WordPress cross-site request forgery
Multiple Russian Actors Attacking Orgs To Hack Microsoft 365 Accounts via Device Code Authentication
Security researchers at Volexity have uncovered multiple Russian threat actors conducting sophisticated social engineering and spear-phishing campaigns targeting Microsoft 365 accounts through Device Code Authentication exploitation. The attacks, observed since mid-January 2025, involve three distinct groups: “CozyLarch (APT29),” “UTA0304,” and “UTA0307.” The threat actors impersonate officials from organizations like the US Department of State, Ukrainian […]
The post Multiple Russian Actors Attacking Orgs To Hack Microsoft 365 Accounts via Device Code Authentication appeared first on Cyber Security News.
新型 “whoAMI” 攻击利用AWS AMI 名称混淆实现远程代码执行
报告:攻击面扩大,汽车网络威胁激增
分析:网安巨头缘何急于收购DSPM初创企业?
Palo Alto防火墙又被黑:最新漏洞披露后第二天就遭利用
CVE-2007-1287 | PHP 4.4.4/4.4.5/4.4.6/6.0 phpinfo cross site scripting (EDB-3405 / Nessus ID 25830)
反射DLL注入技术深度解析与实战
Indian Post Office Portal Exposed Thousands of KYC Records With Username & Mobile Number
The Indian Post Office portal was found vulnerable to an Insecure Direct Object Reference (IDOR) attack, exposing sensitive Know Your Customer (KYC) data of thousands of users. This breach highlights the critical need for robust security measures in government-operated digital platforms, especially those handling sensitive personal information like Aadhaar and PAN details. What Happened? According […]
The post Indian Post Office Portal Exposed Thousands of KYC Records With Username & Mobile Number appeared first on Cyber Security News.
New Android Security Feature that Blocks Changing Sensitive Setting During Calls
Google has unveiled a groundbreaking security feature in Android 16 Beta 2 aimed at combating phone scams by blocking users from altering sensitive settings during active phone calls. This feature, currently live in the beta version, prevents enabling permissions like sideloading apps and granting accessibility access, both of which are commonly exploited by scammers. Phone […]
The post New Android Security Feature that Blocks Changing Sensitive Setting During Calls appeared first on Cyber Security News.