Threat actors could steal authentication tokens using the new reverse-proxy phishing-as-a-service platform EvilProxy in an effort to evade multi-factor authentication on Microsoft, Google, Facebook, Apple, Twitter, GoDaddy, GitHub, and PyPi, according to BleepingComputer.
Threat actor mx1r, which is believed to be a member of Evil Corp affiliate UNC2165, has been suspected to have targeted an unnamed workforce management corporation in April with the attack infrastructure leveraged in the ransomware attack against Cisco the following month, reports The Hacker News.
Vulnerabilities affecting certain Contec Health patient monitor medical devices could allow a DDoS attack or the extraction of patient health information.
Apple has released an updated version of its XProtect malware defense app to Mac devices running macOS Monterey, Big Sur, and Catalina, Ars Technica reports.
Older iPhones, iPod touch, and iPads have been given security updates to fix an actively exploited critical out-of-bounds write issue in WebKit, tracked as CVE-2022-32893, which could be exploited by threat actors to facilitate the execution of arbitrary code, The Hacker News reports.
Security expert says the Anti-Malware Testing Standards Organization's security guidelines are "step in the right direction" for Internet of Things vendors.
Fraudulent American Express email bypassed Google Workspace security and directed users to spoofed page to enter credentials, Amorblox researchers reported.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.