Security News

GitHub's Secret Scanning Feature Now Covers AWS, Microsoft, Google, and Slack
2023-10-06 08:53

GitHub has announced an improvement to its secret scanning feature that extends validity checks to popular services such as Amazon Web Services (AWS), Microsoft, Google, and Slack. Validity...

Microsoft officially removes Cortana for Windows 11 Insiders
2023-10-05 20:29

Microsoft finally removed the Cortana standalone app from Windows 11 in the latest preview build for Insiders in the Canary Channel. "Support for Cortana in Teams mobile, Microsoft Teams display, and Microsoft Teams Rooms will end in the fall of 2023. Voice assistance in Outlook mobile and Microsoft 365 mobile will also end in the fall of 2023," Microsoft said at the time.

Microsoft Redesigns OneDrive for Business Layout
2023-10-05 20:06

Microsoft OneDrive for Business has been redesigned and has a new upgrade roadmap, which includes the Copilot natural language AI assistant, Microsoft announced on October 3. New layout and features are now visible in Microsoft OneDrive for Business.

Microsoft releases new, faster Teams app for Windows and Mac PCs
2023-10-05 16:00

A new, redesigned, and faster Microsoft Teams application is generally available for all Windows and macOS users starting today. As revealed when the new Teams was made available as a preview release in March, the new client will launch three times faster, enabling users to switch between chats and channels up to 1.7 times faster than the Classic Teams app.

BYOD should stand for bring your own disaster, according to Microsoft ransomware data
2023-10-05 13:03

Microsoft research says that 80-90 percent of ransomware attacks over the past year originated from unmanaged devices. The threat BYOD presents is compounded by the steep rise in overall ransomware incidents this year; Microsoft says human-operated ransomware attacks are up by more than 200 percent since September 2022.

Microsoft: Hackers target Azure cloud VMs via breached SQL servers
2023-10-04 14:53

Hackers have been observed trying to breach cloud environments through Microsoft SQL Servers vulnerable to SQL injection. The attacks Microsoft observed start with exploiting an SQL injection vulnerability in an application in the target's environment.

Microsoft Warns of Cyber Attacks Attempting to Breach Cloud via SQL Server Instance
2023-10-04 10:18

Microsoft has detailed a new campaign in which attackers unsuccessfully attempted to move laterally to a cloud environment through a SQL Server instance. "The attackers initially exploited a SQL...

Microsoft now lets you play a game during Windows 11 installs
2023-10-03 18:59

Users are now encouraged to take a break and indulge in a surfing game while waiting for their systems to update, as first spotted by The Verge while installing Windows 11 on a Surface Laptop Studio 2. Initially launched in May 2020 when bundled with the Microsoft Edge web browser, the Surf game is a modern rendition of the classic SkiFree game, part of Microsoft's Entertainment Pack 3 for Windows 3.0, released in October 1991.

Microsoft Edge, Teams get fixes for zero-days in open-source libraries
2023-10-03 14:54

Microsoft released emergency security updates for Edge, Teams, and Skype to patch two zero-day vulnerabilities in open-source libraries used by the three products. The libwebp library is used by a large number of projects for encoding and decoding images in the WebP format, including modern web browsers like Safari, Mozilla Firefox, Microsoft Edge, Opera, and the native Android web browsers, as well as popular apps like 1Password and Signal.

EvilProxy uses indeed.com open redirect for Microsoft 365 phishing
2023-10-03 13:00

A recently uncovered phishing campaign is targeting Microsoft 365 accounts of key executives in U.S.-based organizations by abusing open redirects from the Indeed employment website for job listings. In August 2023, Proofpoint warned of another EvilProxy campaign, which distributed approximately 120,000 phishing emails to hundreds of organizations, targeting their employees' Microsoft 365 accounts.