Aggregator
New Account Takeover Campaign Leverages Pentesting Tool to Attack Entra ID User Accounts
A sophisticated account takeover campaign has emerged, exploiting a legitimate penetration testing framework to compromise Microsoft Entra ID environments across hundreds of organizations worldwide. The malicious activity, which began intensifying in December 2024, demonstrates how cybercriminals are increasingly weaponizing security tools originally designed for defensive purposes. The campaign leverages TeamFiltration, a publicly available pentesting framework […]
The post New Account Takeover Campaign Leverages Pentesting Tool to Attack Entra ID User Accounts appeared first on Cyber Security News.
Apache CloudStack 严重漏洞可用于执行权限操作
Microsoft 365 Copilot 中存在零点击AI数据泄露漏洞
Weekly Update 456
It's time to fly! It's two months to the day since we came back from the last European trip, again spending the time with some of the agencies and partners we've fostered at HIBP over the years. This time, it's the driving
DeepSeek стал приманкой. А вы — уловом
Hackers Launch Coordinated Attack on Apache Tomcat Manager from 400 Unique IPs
Cybersecurity researchers at GreyNoise Intelligence have identified a significant coordinated attack campaign targeting Apache Tomcat Manager interfaces across the globe. On June 5, 2025, the company’s threat detection systems registered activity levels far exceeding normal baselines, with nearly 400 unique IP addresses participating in what appears to be a large-scale reconnaissance and access attempt operation. […]
The post Hackers Launch Coordinated Attack on Apache Tomcat Manager from 400 Unique IPs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
【漏洞预警】Apache Kafka Connect高危漏洞(CVE-2025-27817)可致任意文件读取,影响核心数据安全!
Fog ransomware attack uses unusual mix of legitimate and open-source tools
奇安信集团2025年06月补丁库更新通告-第一次更新
【已复现】契约锁电子签章系统远程代码执行漏洞(QVD-2025-23408)安全风险通告
工业自动化PROFINET协议库P-Net 高危漏洞预警
Europol Says Criminal Demand for Data is “Skyrocketing”
Операция Frontier+: когда онлайн-роман заканчивается не свадьбой, а уголовным делом
ИИ официально принят в разведку — теперь он читает то, что раньше знали только избранные
U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog
New Campaign Targets Entra ID User Accounts Using Pentesting Tool for Account Takeover
Proofpoint Threat Intelligence has uncovered a large-scale Account Takeover (ATO) campaign, internally tracked as UNK_SneakyStrike, that leverages the open-source penetration testing framework TeamFiltration to target Microsoft Entra ID user accounts across global organizations. The campaign, which began in late 2024, has targeted over 80,000 user accounts across hundreds of cloud tenants to date, with several […]
The post New Campaign Targets Entra ID User Accounts Using Pentesting Tool for Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.