DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

Cybersecurity researchers have uncovered a sophisticated threat actor exploiting a previously unknown vulnerability in Microsoft’s device-code flow, which allows attackers to gain unauthorized access to Microsoft 365 (M365) accounts. The technique, dubbed “DEBULL Tooling,” has been used to target high-profile organizations and individuals worldwide. At its core, the attack relies on manipulating the device-code flow, … Read more

Webinar tomorrow: Why modern email attacks require a new approach to defense

Email Attacks Evolve, Leaving Traditional Security Measures in Shambles As security teams continue to invest heavily in advanced technologies such as secure email gateways and multi-factor authentication, phishing, business email compromise (BEC), and account takeover (ATO) attacks remain some of the most persistent threats facing organizations today. Despite these efforts, attackers are finding new ways … Read more

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Suspected China-Aligned Hackers Target Universities with Roundcube Flaws, Exposing Sensitive Data A highly sophisticated hacking campaign, linked to suspected Chinese actors, has been exploiting vulnerabilities in the widely-used email client software Roundcube against universities worldwide. The cyberattacks have compromised sensitive student and faculty data, highlighting the critical need for robust security measures in higher education … Read more

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

The Rise of AI-Powered Code Injection: A New Threat Landscape for Organizations Cybersecurity experts have long warned about the dangers of compromised software supply chains, but a recent trend is taking this threat to the next level. Artificial intelligence (AI) models are increasingly being used to write malicious code, injecting vulnerabilities into software that can … Read more

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

A Flaw in Writer AI Exposes Session Tokens Across Tenants, Raising Concerns Over Data Security A vulnerability in the Writer AI platform has been discovered, allowing unauthorized access to session tokens across different tenants. The flaw, which affects the popular content creation tool, could potentially enable hackers to compromise sensitive data and gain control over … Read more

CISO Conversations: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

Tarah Wheeler, a cybersecurity leader with an unconventional background, has taken the industry by storm. As Chief Information Security Officer (CISO) at TPO Group, Wheeler’s journey into cybersecurity was far from intentional – it was more like being “hit over the head” with a baseball bat and dragged into the arena. Wheeler’s passion lies in … Read more

Microsoft to enable Windows settings backup by default for orgs

In a significant shift, Microsoft is set to make Windows settings backup and restore an essential feature by default for organizations using its Enterprise systems. Starting with Windows 11 version 26H2, the long-awaited tool will be automatically enabled on eligible devices, saving IT administrators time and effort in managing user data. The Windows settings backup … Read more

New Januscape Linux flaw allows VM escape on Intel, AMD devices

A devastating Linux kernel vulnerability has been discovered, allowing attackers to escape virtual machines and execute code on the host with root privileges. Dubbed Januscape, this critical flaw affects both Intel and AMD processor architectures, posing a significant risk to multi-tenant public cloud environments. Januscape stems from a 16-year-old weakness in the shadow MMU emulation … Read more

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

A sophisticated cyberattack campaign, allegedly linked to China-aligned hackers, has been targeting universities worldwide, exploiting vulnerabilities in the popular email client software Roundcube. The attackers have compromised numerous institutions’ networks, compromising sensitive data and disrupting academic activities. At the heart of this campaign lies a clever exploitation of Roundcube’s security flaws by AI-powered vulnerability scanners. … Read more