Security News

Microsoft breach led to theft of 60,000 US State Dept emails
2023-09-28 20:45

Chinese hackers stole tens of thousands of emails from U.S. State Department accounts after breaching Microsoft's cloud-based Exchange email platform in May. During a recent Senate staff briefing, U.S. State Department officials disclosed that the attackers stole at least 60,000 emails from Outlook accounts belonging to State Department officials stationed in East Asia, the Pacific, and Europe, as Reuters first reported. Microsoft did not disclose specific details regarding the affected organizations, government agencies, or countries impacted by this email breach.

Internet and Email Usage Policy
2023-09-24 16:00

SAFE BROWSING. Use a modern, supported and up-to-date browser. Browsers will proactively warn users before accessing websites with expired security certificates or that are known to host malware.

Nigerian man pleads guilty to attempted $6 million BEC email heist
2023-09-22 19:24

Kosi Goodness Simon-Ebo, a 29-year-old Nigerian national extradited from Canada to the United States last April, pleaded guilty to wire fraud and money laundering through business email compromise. According to the plea agreement, the scammers had a high success ratio of roughly 1 to 7, making one million out of the almost seven million they attempted to steal.

Email forwarding flaws enable attackers to impersonate high-profile domains
2023-09-11 04:00

Sending an email with a forged address is easier than previously thought, due to flaws in the process that allows email forwarding, according to a research team led by computer scientists at the University of California San Diego. It's called forwarding-based spoofing, and researchers found that they can send email messages impersonating these organizations, bypassing the safeguards deployed by email providers such as Gmail and Outlook.

Microsoft: China stole secret key that unlocked US govt email from crash debug dump
2023-09-06 22:59

Mistakes were made, lessons learned, stuff now fixed, says Windows maker Remember that internal super-secret Microsoft security key that China stole and used to break into US government email...

Protect Your Email With This Top-Rated Tool — Just $40 for Labor Day
2023-08-31 09:00

Protect Your Email With This Top-Rated Tool - Just $40 for Labor Day Mail Backup X is one of the top-rated tools on the market for backing up and archiving your emails. It's so crucial that losing access to your email or mistakenly deleting certain email messages could become a serious headache in your life.

US govt email servers hacked in Barracuda zero-day attacks
2023-08-29 12:00

Suspected Chinese hackers disproportionately targeted and breached government and government-linked organizations worldwide in recent attacks targeting a Barracuda Email Security Gateway zero-day, with a focus on entities across the Americas. Barracuda warned customers that the vulnerability was being exploited to breach ESG appliances on May 20, when it also patched all vulnerable devices remotely.

Urgent FBI Warning: Barracuda Email Gateways Vulnerable Despite Recent Patches
2023-08-25 08:27

The U.S. Federal Bureau of Investigation is warning that Barracuda Networks Email Security Gateway appliances patched against a recently disclosed critical flaw continue to be at risk of potential compromise from suspected Chinese hacking groups. It also deemed the fixes as "Ineffective" and that it "Continues to observe active intrusions and considers all affected Barracuda ESG appliances to be compromised and vulnerable to this exploit."

FBI: Who was going around hijacking Barracuda email boxes? China, probably
2023-08-25 00:17

The FBI has warned owners of Barracuda Email Security Gateway appliances the devices are likely undergoing attack by snoops linked to China, and removing the machines from service remains the safest course of action. On Wednesday, the FBI pushed that recommendation in a flash alert [PDF] that stated it "Strongly advises all affected ESG appliances be isolated and replaced immediately."

Cybercriminals turn to AI to bypass modern email security measures
2023-08-23 03:30

Cybercriminals employ artificial intelligence to create complex email threats like phishing and business email compromise attacks, while modern email security systems use AI to counter these attacks, according to Perception Point and Osterman Research. Cybercriminals have shown rapid adoption of AI tools to their favor with 91.1% of organizations reporting that they have already encountered email attacks that have been enhanced by AI, and 84.3% expecting that AI will continue to be utilized to circumvent existing security systems.