Attackers have been leveraging a novel phishing approach that involves the creation of an unusual link with an "@" symbol in between, which browsers identify as legitimate domains and therefore allows evasion of security systems, according to Threatpost.
BleepingComputer reports that threat actors have been deploying the "highly sophisticated" IceApple post-exploitation framework on Microsoft Exchange Servers.
Microsoft has issued a fix for a Windows Local Security Authority spoofing zero-day vulnerability, which could be abused to force domain controller authentication through the Windows NT LAN Manager protocol, BleepingComputer reports.
Oregon's ORESTAR state campaign finance reporting system may have been compromised just a week prior to the state's primary election after a ransomware attack against campaign finance firm C&E Systems' web hosting provider Opus Interactive, according to the Associated Press.
Information-stealing Saintstealer malware does not only steal usernames, passwords, and credit card details but also exfiltrates various system data, The Hacker News reports.
The Hacker News reports the emergence of new REvil ransomware samples, indicating that the ransomware operation has returned after being inactive for six months.
A prominent tech trade group is asking the Securities and Exchange Commission to hold off implementing a slew of new cybersecurity-related regulations, saying it could confuse industry and step on similar efforts by other agencies.
The Internet Security Alliance weighed in on cybersecurity reporting rules proposed by the Securities and Exchange Commission that would require organizations to report significant incidents within four days.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.