Microsoft Teams now lets admins block external bots from meetings

Microsoft has rolled out a new feature to its popular team collaboration platform, Teams, aimed at protecting users from external bots joining meetings. The company is allowing administrators to automatically block all identified external bots from participating in Teams meetings, adding an extra layer of security to its existing bot protection policies. This move comes … Read more

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest Falls Victim to Elaborate Social Engineering Attack, but Security Measures Keep Breach at Bay A sophisticated social engineering attack has targeted cybersecurity firm ReliaQuest, with hackers impersonating a member of the security team to trick employees into accessing a fake single sign-on (SSO) page. Although the attackers were able to gain temporary access to … Read more

TikTok reaches $400M settlement with US over COPPA violations

TikTok Agrees to $400 Million Settlement with US Over Alleged COPPA Violations A major settlement has been reached between TikTok, its parent company ByteDance, and the US Department of Justice. The social media platform will pay a staggering $400 million to resolve allegations that it violated the Children’s Online Privacy Protection Act (COPPA), a law … Read more

Hackers target WordPress sites in miniOrange auth bypass attacks

Cybersecurity researchers have discovered a pair of critical vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing hackers to forge SAML responses and log in as administrators without needing valid credentials. This exploit has been observed in exploitation attempts targeting several thousand websites running the affected plugins. The miniOrange SAML SSO … Read more

South Korean startup platform breach exposes key management failures

South Korea’s government-backed startup platform suffered a devastating data breach in July, revealing a critical failure in encryption key management that left sensitive information exposed. The incident highlights the importance of proper encryption key management and serves as a stark reminder that even encrypted data can be compromised when organizations fail to protect their keys. … Read more

Microsoft Teams now lets admins block external bots from meetings

Microsoft has introduced a new feature in its popular collaboration platform, Teams, designed to strengthen meeting security by automatically blocking external bots from joining meetings. This move comes as part of an ongoing effort to mitigate the rising threat of attacks that exploit Teams vulnerabilities for unauthorized access and lateral movement on enterprise networks. The … Read more

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity firm ReliaQuest has confirmed that it was targeted by attackers who attempted to steal sensitive information after impersonating one of its security employees. The incident highlights the growing threat of social engineering tactics, where hackers use human psychology to gain access to systems and data. The attack began when an individual claiming to be … Read more

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have uncovered a sophisticated threat campaign that leverages a clever technique called “clickjacking” to deliver malicious payloads, including the notorious Amatera malware. This scheme, known as WordlistLoader, has been observed in the wild, targeting users across various industries and compromising their systems with alarming ease. At its core, WordlistLoader is a type of … Read more

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

Cybersecurity threats are becoming increasingly sophisticated, and one emerging trend is the use of artificial intelligence (AI) to compromise industrial control systems. Recent reports have revealed that attackers are leveraging AI-powered tools to exploit vulnerabilities in programmable logic controllers (PLCs), which are critical components of modern industrial infrastructure. The impact of these attacks is significant, … Read more