Security News

Microsoft: China stole secret key that unlocked US govt email from crash debug dump
2023-09-06 22:59

Mistakes were made, lessons learned, stuff now fixed, says Windows maker Remember that internal super-secret Microsoft security key that China stole and used to break into US government email...

Protect Your Email With This Top-Rated Tool — Just $40 for Labor Day
2023-08-31 09:00

Protect Your Email With This Top-Rated Tool - Just $40 for Labor Day Mail Backup X is one of the top-rated tools on the market for backing up and archiving your emails. It's so crucial that losing access to your email or mistakenly deleting certain email messages could become a serious headache in your life.

US govt email servers hacked in Barracuda zero-day attacks
2023-08-29 12:00

Suspected Chinese hackers disproportionately targeted and breached government and government-linked organizations worldwide in recent attacks targeting a Barracuda Email Security Gateway zero-day, with a focus on entities across the Americas. Barracuda warned customers that the vulnerability was being exploited to breach ESG appliances on May 20, when it also patched all vulnerable devices remotely.

Urgent FBI Warning: Barracuda Email Gateways Vulnerable Despite Recent Patches
2023-08-25 08:27

The U.S. Federal Bureau of Investigation is warning that Barracuda Networks Email Security Gateway appliances patched against a recently disclosed critical flaw continue to be at risk of potential compromise from suspected Chinese hacking groups. It also deemed the fixes as "Ineffective" and that it "Continues to observe active intrusions and considers all affected Barracuda ESG appliances to be compromised and vulnerable to this exploit."

FBI: Who was going around hijacking Barracuda email boxes? China, probably
2023-08-25 00:17

The FBI has warned owners of Barracuda Email Security Gateway appliances the devices are likely undergoing attack by snoops linked to China, and removing the machines from service remains the safest course of action. On Wednesday, the FBI pushed that recommendation in a flash alert [PDF] that stated it "Strongly advises all affected ESG appliances be isolated and replaced immediately."

Cybercriminals turn to AI to bypass modern email security measures
2023-08-23 03:30

Cybercriminals employ artificial intelligence to create complex email threats like phishing and business email compromise attacks, while modern email security systems use AI to counter these attacks, according to Perception Point and Osterman Research. Cybercriminals have shown rapid adoption of AI tools to their favor with 91.1% of organizations reporting that they have already encountered email attacks that have been enhanced by AI, and 84.3% expecting that AI will continue to be utilized to circumvent existing security systems.

'Millions' of spammy emails with no opt-out? That'll cost you $650K, Experian
2023-08-22 21:58

Experian has agreed to cough up $650,000 after being accused of spamming people with no opt-out button. According to the Feds [PDF], California-based Experian Consumer Services, also known as ConsumerInfo.com, spammed folks with marketing offers after they signed up for free accounts to limit third-party access to their credit reports.

Organizations invest in AI tools to elevate email security
2023-08-21 03:30

To counteract new and emerging threat methods enhanced by artificial intelligence, specialized email security vendors are leveraging a synergy of AI and human insights to enhance email security, according to IRONSCALES and Osterman Research. Over 74% of respondents have experienced an increase in the use of AI by cybercriminals in the past six months, and over 85% believe that AI will be used to circumvent their existing email security technologies.

Hotmail email delivery fails after Microsoft misconfigures DNS
2023-08-18 15:44

Hotmail users worldwide have problems sending emails, with messages flagged as spam or not delivered after Microsoft misconfigured the domain's DNS SPF record. The email issues began late last night, with users and admins reporting on Reddit, Twitter, and Microsoft forums that their Hotmail emails were failing due to SPF validation errors.

New Wave of Attack Campaign Targeting Zimbra Email Users for Credential Theft
2023-08-18 11:48

A new "Mass-spreading" social engineering campaign is targeting users of the Zimbra Collaboration email server with an aim to collect their login credentials for use in follow-on operations. "Initially, the target receives an email with a phishing page in the attached HTML file," ESET researcher Viktor Šperka said in a report.