Microsoft Bing penetrated through misconfiguration in Azure Active Directory
Researchers from security specialist Wiz Research penetrated the backend of Microsoft Bing through a misconfiguration in Azure App Services and Azure Functions. This allowed them to manipulate search results and add malicious code.
The security specialists discovered the so-called BingBang vulne... Read more
CrowdStrike invests in security startup Abnormal Security
CrowdStrike recently invested an undisclosed amount in security startup Abnormal Security through its investment fund CrowdStrike Falcon Fund. In addition, the two security providers will integrate each other's technology.
With the recent investment, the provider of cloud-based security solution... Read more
Cisco to acquire Lightspin to deliver “Contextual Cloud Security”
The US tech giant will round out its product offering with a "holistic solution" that provides end-to-end cloud security posture management (CSPM) across cloud-native resources.
This week Cisco announced that it is acquiring Lightspin Technologies, a Tel Aviv-based start-up that helps enterprise... Read more
802.11 WiFi protocol has a fundamental design flaw in security
The well-known IEE 802.11 WiFi protocol has a fundamental design flaw in its security, according to researchers at Northeastern University in Boston and KU Leuven. The flaw allows access points to leak so-called "network frames" in plaintext. Cisco has since acknowledged this risk as the first prov... Read more
IBM Aspera Faspex servers are being targeted by ransomware gangs
A vulnerability in IBM Aspera Faspex servers is being actively exploited by ransomware criminals, researchers warn.
Hackers are exploiting a critical vulnerability in an IBM file-exchange application. According to security researchers, the criminals are using the flaw to install ransomware on se... Read more
Acronis integrates Intel TDT technology for greater CPU efficiency
Acronis has integrated Intel Threat Detection Technology into several solutions. With this, this security vendor's platform offers better protection against new and more developed forms of malware.
According to Acronis, malware is becoming increasingly sophisticated. Consider the rapid rise of s... Read more
Exchange Online to block emails from “vulnerable” on-prem servers
Microsoft is enabling a new security feature to protect users from on-premise servers that have not updated their security.
Microsoft is enabling a new system for Exchange Online that will automatically start throttling and blocking emails sent from "persistently vulnerable Exchange servers" tha... Read more
As fear of cyber threats rises, organizations have to review their security strategy
“Frankly, I live in terror of a ransomware attack and state-sponsored intrusions.”
This quote from a business professional comes from the 2023 SonicWall Cyber Threat Report. It perfectly captures what organisations are currently very concerned about. Ransomware has been keeping organisations... Read more
Pwn2Own event yields 27 zero-days
Security researchers managed to discover as many as 27 zero-days in major enterprise software during the three days of the Pwn2Own Vancouver 2023 event. Zero-days were found in Windows 11, Ubuntu and macOS, among others, as well as in Oracle and VMware products and Tesla's firmware.
The various ... Read more
What are Passkeys? Removing the human element from authentication
For the longest time, the technology industry has been developing a future with password-free (passwordless) authentication. That future is now, with passkeys. But what are passkeys?
The FIDO Alliance was established with the goal of lessening the dependence on passwords almost ten years ago. An... Read more