Security News

Malicious Microsoft VSCode extensions target devs, crypto community
2024-12-18 17:47

Malicious Visual Studio Code extensions were discovered on the VSCode marketplace that download heavily obfuscated PowerShell payloads to target developers and cryptocurrency projects in supply...

Microsoft won't let customers opt out of passkey push
2024-12-18 17:30

Enrolment invitations will continue until security improves Microsoft last week lauded the success of its efforts to convince customers to use passkeys instead of passwords, without actually...

CISA orders federal agencies to secure Microsoft 365 tenants
2024-12-17 20:01

​CISA has issued this year's first binding operational directive (BOD 25-01), ordering federal civilian agencies to secure their Microsoft 365 cloud environments by implementing a list of required...

Attackers Exploit Microsoft Teams and AnyDesk to Deploy DarkGate Malware
2024-12-17 16:35

A new social engineering campaign has leveraged Microsoft Teams as a way to facilitate the deployment of a known malware called DarkGate. "An attacker used social engineering via a Microsoft Teams...

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks
2024-12-17 14:11

A new phishing campaign has been observed employing tax-themed lures to deliver a stealthy backdoor payload as part of attacks targeting Pakistan. Cybersecurity company Securonix, which is...

Week in review: Microsoft fixes exploited 0-day, top cybersecurity books for your holiday gift list
2024-12-15 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes exploited zero-day (CVE-2024-49138) On December 2024 Patch Tuesday, Microsoft...

Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others
2024-12-11 20:57

December marked a quiet month with 70 vulnerabilities patched, plus updates from outside of Microsoft.

Microsoft lifts Windows 11 24H2 block on PCs with USB scanners
2024-12-11 19:06

Microsoft has lifted a compatibility block preventing Windows 11 24H2 upgrades after fixing a bug causing USB connection issues to some scanners. [...]

Microsoft MFA AuthQuake Flaw Enabled Unlimited Brute-Force Attempts Without Alerts
2024-12-11 14:32

Cybersecurity researchers have flagged a "critical" security vulnerability in Microsoft's multi-factor authentication (MFA) implementation that allows an attacker to trivially sidestep the...

Microsoft enforces defenses preventing NTLM relay attacks
2024-12-11 12:59

Since making Kerberos the default Windows authentication protocol in 2000, Microsoft has been working on eventually retiring NTLM, its less secure and obsolete counterpart. Until NTLM gets...