Security News

UN hacked: Attackers got in via SharePoint vulnerability
2020-01-30 13:49

The UN did not share that discovery with the authorities, the public, or even the potentially affected staff, and we now know about it only because TNH reporters got their hands on a confidential report by the UN. How was the UN hacked? According to the report, the attack started in July 2019, when the attackers managed to compromise a server located at the UN Office in Vienna through CVE-2019-0604, a security hole in Microsoft SharePoint patched by Microsoft in February 2019 and subsequently widely exploited by attackers to hit a variety of targets worldwide.

UN didn't patch SharePoint, covered up massive hack of multiple key systems – and kept most staff in the dark
2020-01-29 22:39

The United Nations' European headquarters in Geneva and Vienna were hacked last summer, putting thousands of staff records at miscreants' fingertips. Despite the size and extent of the hack, the UN decided to keep it secret.

Tracking President Trump with cellphone location data, Greta-Thunberg-themed malware, SharePoint patch, and more
2019-12-21 14:05

Including: Nasty Mac malware and gas-pump infections Roundup Here's a catch-up of security news beyond everything else we've covered.…

Microsoft Issues Out-of-Band Update for SharePoint Bug
2019-12-18 19:14

An attacker could exploit CVE-2019-1491 to obtain sensitive information that could be used to mount further attacks.

SharePoint Online scam – sadly, phishing’s not dead
2019-07-23 17:02

Not all phishes contain easily spotted errors or obviously dodgy web links - here's how to stay safe...

Week in review: New Intel CPU vulnerabilities, SharePoint servers under attack
2019-05-19 17:00

Here’s an overview of some of last week’s most interesting news and articles: High-risk vulnerability in Cisco’s secure boot process impacts millions of devices Red Balloon Security has discovered...

Microsoft SharePoint Vulnerability Exploited in the Wild
2019-05-13 06:32

A critical vulnerability in Microsoft’s SharePoint collaboration platform has been exploited in the wild to deliver malware. read more

FIN7 Linked to Escalating Active Exploits for Microsoft SharePoint Bug
2019-05-10 21:29

Using a bug patched in March, the attacks are starting to ramp up worldwide.

Office 365 Phishing Campaign Hides Malicious URLs in SharePoint Files
2018-08-15 16:06

Researchers say the "PhishPoint" tactic has already impacted 10 percent of Office 365 users globally.

New Office 365 phishing attack uses malicious links in SharePoint documents
2018-08-15 11:45

Fake emails targeting Office 365 users via malicious links inserted into SharePoint documents are the latest trick phishers employ to bypass the platform’s built-in security, Avanan researchers...