Cloud
Cloud platforms, services, and infrastructure
Phishing Kit GhostCode Extracts Microsoft 365 Credentials via OAuth Exploitation
GhostCode, a new phishing kit, exploits OAuth 2.0 device code authentication to compromise Microsoft 365 accounts, highl...
Navigating AI Governance: 16 Essential Tools for Safeguarding LLMs
Explore 16 key tools that empower teams to ensure the responsible governance of AI, addressing security, compliance, and...
Microsoft Updates Cloud Addresses for M365 and Teams: What You Need to Know
Microsoft is changing the addresses for M365 and Teams services, requiring organizations to update settings for continue...
Exploiting Trust: Fake Verification Attacks on India's STPI Site
A recent incident involving India's STPI revealed a malicious fake Cloudflare verification page that could trick users i...
ServiceNow's Strategic Shift: Navigating AI and Cybersecurity Disruptions
ServiceNow adapts to market changes by pivoting towards AI-driven solutions and cybersecurity, rethinking pricing models...
Social Engineering Exploits Passkey Myths to Compromise Microsoft 365 Accounts
Attackers leverage passkey-themed scams to gain unauthorized access to Microsoft 365 accounts, showing the vulnerabiliti...
Exploiting ChatGPT: How a Hidden Flaw Allowed Gmail Data Extractions
A vulnerability in ChatGPT let attackers siphon data from victims' Gmail accounts unnoticed, prompting necessary securit...
Mars Security Transforms Threat Detection with Automated Real-Time Intelligence
Mars Security enhances enterprise SOCs with a new automated system that translates threat intelligence into actionable d...
Palo Alto Networks Highlights AI's Role in Rapid Ransomware Attacks
AI-driven tactics are hastening ransomware attacks, posing new challenges for security teams to respond efficiently and...
Anthropic Launches Enterprise Frontier Safeguards for Enhanced AI Monitoring
Anthropic's new Enterprise Frontier Safeguards framework offers enterprises an innovative way to monitor AI misuse while...
Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
A sophisticated attack leverages fake CAPTCHA prompts, tricking users into executing malicious commands that compromise...
China-linked Threat Actors Target Critical Network Infrastructure for Espionage
A new report reveals a China-linked cyber group exploiting Cisco routers and authentication systems, raising security co...
Rust Package Backdoor Exposes Developers to Malicious Code During Build
Recent attacks on Rust packages have revealed vulnerabilities that allow backdoors to execute during build processes, po...
Critical Citrix NetScaler Updates Demand Urgent Action Amid Rising Cyber Threats
Citrix urges immediate patching for critical vulnerabilities in NetScaler devices, highlighting heightened risks and the...
Airlock Digital Achieves PROTECTED Level in IRAP Assessment, Enhances Security Credibility
Airlock Digital's recent PROTECTED level IRAP assessment strengthens its security posture, affirming its capacity to mee...
New Threats in AI Development: Safeguarding Python Packages from Malicious Intrusions
Recent supply chain attacks on Python packages, especially in AI development, highlight urgent security needs for develo...
Reassessing Cybersecurity: How a Software Provider Uncovered Hidden Risks in its Cloud Infrastructure
A recent insider threat test revealed critical vulnerabilities in a healthcare software provider's cloud security, leadi...
Reassessing Cybersecurity Fundamentals in an AI-Driven Landscape
As AI tools transform the cybersecurity field, experts emphasize a renewed focus on foundational security practices that...
Microsoft Averts Major Security Breach in Azure Cosmos DB with Swift Fixes
A critical vulnerability in Azure Cosmos DB was swiftly addressed by Microsoft after its discovery by security firm Wiz,...
CISA’s Strategic Blueprint for Isolating Critical Infrastructure from Cyber Threats
CISA and global partners have released a structured six-step guide to help organizations effectively isolate their criti...