Threat actors affiliated with the Play ransomware strain are leveraging a never-before-seen exploit method that bypasses Microsoft's ProxyNotShell URL rewrite mitigation to gain remote code execution through Outlook Web Access (OWA).
U.S. consumers continue to lag in identifying and defending against cybersecurity threats even though the average prevalence of connected devices per household has risen by 25% between 2020 and 2022, according to TechRepublic.
Armorblox uses natural language understanding to thwart attack on large educational institution that used social engineering to bypass Office 365 security.
Google has made client-side encryption for Gmail available in beta for its clients using the Google Workspace Enterprise Plus, Education Plus, and Education Standard plans, SiliconAngle reports.
Companies must communicate clear expectations when contracting with pentesters, red teams and vulnerability hunters in order to set key ground rules for what data and systems can be accessed, what’s off limits and who is responsible if something breaks. Of course, if you set too many restrictions and parameters, then how do you really know if you’r...
Private Minecraft servers are being targeted by the novel cross-platform botnet MCCrash, which could facilitate distributed denial-of-service attacks, according to The Hacker News.
The FBI, Food and Drug Administration, and Department of Agriculture have warned that U.S. food suppliers had hundreds of thousands of dollars in shipments stolen in business email compromise attacks, according to CNN.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.