Security news that informs and inspires

2376 articles by

Attackers Verify O365 Credentials On Microsoft Entra ID

Attackers are cross-checking stolen Office 365 credentials on Microsoft Entra ID in real-time after victims type them into a malicious phishing page, researchers from Armorblox said.

Phishing, Office 365, Azure, Azure AD, Active Directory

Raccoon Attack Can Compromise Some TLS Connections

A new technique called the Raccoon attack can break the confidentiality of some TLS connections under certain circumstances.

Encryption, Vulnerability

Traditional is Best When Converting Stolen Money to Clean Cash

SWIFT and BAE Systems analyzed the web of businesses, money mules, and intermediate accounts used to transfer stolen money around the world until it becomes hard to trace.

Cybercrime, Financial Services, Cryptocurrency

Attackers Use Cloud Tool to Target Docker, Kubernetes

An attack group TeamTNT is using Weave Scope, an open source cloud monitoring and control tool to compromise Docker and Kubernetes instances as part of a cryptocurrency mining operation, security company Intezer said.

Cloud, Kubernetes, Docker

Attacks Target Critical Flaw in WordPress File Manager Plugin

Attackers are actively exploiting a critical bug in the File Manager WordPress plugin.

Vulnerability, Wordpress