Security News

Office 365: A Favorite for Cyberattack Persistence
2020-10-13 13:20

Threat actors are consistently leveraging legitimate services and tools from within Microsoft Office 365 to pilfer sensitive data and launch phishing, ransomware, and other attacks across corporate networks from a persistent position inside the cloud-based suite, new research has found. Office 365 user account takeover - particularly during the COVID-19 pandemic with so many working from home - is one of the most effective ways for an attacker to gain a foothold in an organization's network, said Chris Morales, head of security analytics at Vectra AI. From there, attackers can move laterally to launch attacks, something that researchers observed in 96 percent of the 4 million Office 365 customers sampled between June to August 2020.

Microsoft adds consent phishing protection to Office 365
2020-10-07 16:10

Microsoft announced that consent phishing protections including OAuth app publisher verification and app consent policies are now generally available in Office 365. These protections are designed to defend Office 365 users from an application-based phishing attack variant known as consent phishing.

HP expands its Bug Bounty Program to focus on office-class print cartridge security vulnerabilities
2020-10-02 03:30

HP has expanded its Bug Bounty Program to focus specifically on office-class print cartridge security vulnerabilities. As part of this program, HP has engaged with Bugcrowd to conduct a three-month program in which four professional white hat hackers have been challenged to identify vulnerabilities in HP Original print cartridges.

Microsoft Office 365 Phishing Attack Uses Multiple CAPTCHAs
2020-10-01 18:27

Researchers are warning of an ongoing Office 365 credential-phishing attack that's targeting the hospitality industry - and using visual CAPTCHAs to avoid detection and appear legitimate. Though the use of CAPTCHAS in phishing attacks is nothing groundbreaking, this attack shows that the technique works - so much so that the attackers in this campaign used three different CAPTCHA checks on targets, before finally bringing them to the phishing landing page, which poses as a Microsoft Office 365 log-in page.

OAuth Consent Phishing Ramps Up with Microsoft Office 365 Attacks
2020-09-30 21:29

According to researchers from Proofpoint, targets receive a well-crafted lures asking them to click a link which carries them to the legitimate Microsoft third-party apps consent page. "The ability to perform reconnaissance on an O365 account supplies an actor with valuable information that can later be weaponized in business email compromise attacks or account takeoversThe minimal [read-only] permissions requested by these apps also likely help them appear inconspicuous if an organization's O365 administrator audits connected apps for their users' accounts."

APT28 Mounts Rapid, Large-Scale Theft of Office 365 Logins
2020-09-11 20:28

The Russia-linked threat group known as APT28 has changed up its tactics to include Office 365 password-cracking and credential-harvesting. The attacks utilized a daily average of 1,294 IPs associated with 536 netblocks and 273 ASNs; and, organizations typically see more than 300 authentication attempts per hour per targeted account over the course of several hours or days.

Office 365 Phishing Attack Leverages Real-Time Active Directory Validation
2020-09-11 20:28

Researchers have uncovered a phishing attack using a new technique: Attackers are making use of authentication APIs to validate victims' Office 365 credentials - in real time - as they enter them into the landing page. Office 365 requires app registrations to use APIs - but registrations require only an email address, making them seamless for attackers to leverage.

How COVID-19 affected remote work, customer engagements, and return to the office plans
2020-09-07 03:30

Top-tier enterprises were 2.6 times as likely to have grown revenue, 2.5 times as likely to have reached profit goals and 2.1 times as likely to have high employee satisfaction numbers during the COVID-19 pandemic, according to a Catchpoint survey of 200 enterprise CIOs and 200 enterprise work-from-home managers. Top tier are organizations that performed the best in terms of business and IT metrics and bottom tier performed the worst.

NETGEAR Orbi Pro WiFi 6 Tri-band Mesh System expands network coverage for SMBs and home offices
2020-09-04 00:45

The Orbi Pro WiFi 6 Tri-band Mesh System is an industry leading tri-band WiFi 6 multi-node mesh system designed to grow with small businesses and home offices as the need to expand their area of network coverage increases. Featuring the latest WiFi data security standard, WPA3, along with 4 SSIDs and VLAN support, the Orbi Pro WiFi 6 Mesh System provides a secure network while also isolating connections for separate activities, making it the ideal solution for today's work from home paradigm.

How IoT sensors and analytics can make inside air safer for schools and offices
2020-09-03 17:04

Advanced building controls can help keep air clean to reduce the risk of the spreading coronavirus indoors while sensors can send an alert if a room goes over capacity.