Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cyberattackers have been exploiting a previously unknown vulnerability in Microsoft 365’s account management system, allowing them to hijack user accounts and siphon off sensitive emails related to payroll and finance. This sophisticated phishing campaign has left several high-profile organizations scrambling to contain the damage. The attack works by targeting users of Microsoft 365, sending carefully … Read more

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A new wave of attacks, dubbed NatJack, is making headlines in the cybersecurity world by hijacking TCP sessions and spoofing DNS queries through manipulation of NAT tables. This sophisticated threat targets organizations with a history of identity exposure, exploiting vulnerabilities that have been present for years but only recently come to light. NatJack works by … Read more

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A critical Linux vulnerability, lurking in the code for almost two decades, has finally been exposed. The flaw, located in the Session Traversal Utilities for NAT (STUN) extension of the Stream Control Transmission Protocol (SCTP), allows local users to gain root access on affected systems and even escape from containers. This security hole, identified as … Read more

Growing Up The Hard Way

Identity exposure has become a rampant issue in modern cybersecurity, with far-reaching consequences that go beyond mere data breaches. CyberNews.work has obtained 11 real stories of individuals who’ve had their identities compromised, leading to devastating attacks on their personal and professional lives. What’s striking is how these incidents often unfold through a process called cross-domain … Read more

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A Highly Skilled Threat Actor Group Has Been Linked to a Series of Redis Attacks, Starting in 2020 and Continuing Through Supply Chain Campaigns, Exposing Thousands of Organizations to Identity-Based Breach Routes. The team behind TeamPCP, a sophisticated threat actor group known for its advanced attack tactics and techniques, has been quietly exploiting vulnerabilities in … Read more

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A Critical Flaw in GitHub’s CI Workflow Exposes Sensitive Secrets, Leaving Developers Vulnerable GitHub’s Continuous Integration (CI) workflow has been compromised by a pair of vulnerabilities that allow an attacker to access sensitive secrets. The flaws, identified as CVE-2023-1234 and CVE-2023-5678, affect the popular Claude Code and Gemini CLI tools used in GitHub’s CI/CD pipelines. … Read more

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware can abuse Windows Hello for Business Keys, allowing attackers to gain persistent access to Entra ID credentials, a type of identity and access management (IAM) solution. This vulnerability affects organizations that use Entra ID in conjunction with Windows Hello for Business, which is designed to provide an additional layer of security through biometric authentication. … Read more

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A New Type of Attack Hijacks Online Sessions and Disguises Hackers as Legitimate Websites Researchers have uncovered a sophisticated cyberattack technique called NatJack, which allows hackers to intercept and manipulate online sessions between users and their intended destinations. The attack method involves manipulating network address translation (NAT) tables, allowing attackers to hijack TCP sessions and … Read more

Snowflake Hacker Pleads Guilty in US Court

A Snowflake Hack Affects Over 165 Organizations, Exposing Billions of Sensitive Records Connor Riley Moucka, a 26-year-old Canadian national, has pleaded guilty to his role in a massive cybercrime campaign that compromised the sensitive data of over 165 organizations using Snowflake data storage accounts. The plea deal comes with a possible sentence of more than … Read more

Critical Vulnerabilities Patched With Chrome 151 Update

Chrome 151 Update Fixes 41 Critical Vulnerabilities, Users Urged to Update Immediately Google has rolled out a fresh Chrome update, version 151, which patches an alarming 41 critical and high-severity vulnerabilities. This latest iteration of the popular browser addresses security flaws that could potentially lead to data corruption, crashes, and even arbitrary code execution. The … Read more