Cybersecurity Architecture
Microsoft Teams: Lateral movement abuse exposed
Microsoft Teams: Lateral movement abuse exposed

18 May 2023

Researchers from the security company Proofpoint looked into the potential misuse of a Teams account by attackers and discovered some intriguing attack paths that might let criminals advance by launching more phishing attempts or tricking users into downloading harmful files. “ Proofpoint’s threat researchers recently analyzed over 450 million malicious sessions, detected throughout the second […]

Read More
WhatsApp introduce Chat Lock
WhatsApp introduce Chat Lock

16 May 2023

‘Chat Lock,’ a new WhatsApp privacy feature that enables users to prevent others from viewing their most private conversations, is currently being rolled out by Meta. “Locking a chat takes that thread out of your inbox and puts it behind its own folder that can only be accessed with your device’s password or biometric, like […]

Read More
Apple, Google team up vs. location-tracking
Apple, Google team up vs. location-tracking

4 May 2023

A proposed industry-wide protocol being developed by Apple and Google is intended to address safety concerns and warn consumers when they are being tracked without their knowledge or consent using gadgets like AirTags. On 2nd May 2023 the companies released a joint statement mentioning “Today Apple and Google jointly submitted a proposed industry specification to […]

Read More
Google issue warnings on a new scam
Google issue warnings on a new scam

27 Apr 2023

Users of Gmail are advised to keep a close eye on their inboxes for any believable scams that may attempt to steal their personal information. Users are presented with the fraud as a “Online Reward Program”. When users open the email, they are frequently informed that they have performed the 18.25 billionth Google search and […]

Read More
US, UK warn of hackers exploiting Cisco routers
US, UK warn of hackers exploiting Cisco routers

20 Apr 2023

Cybersecurity and intelligence organizations in the United Kingdom and the United States have issued alerts on Russian nation-state actors APT28 using vulnerabilities in Cisco networking hardware that have since been fixed to conduct reconnaissance and launch malware against targets. APT28, often referred to as Fancy Bear, STRONTIUM, Sednit, and Sofacy, is a government-sponsored hacker organization […]

Read More
New Emerging ransomware: RORSCHACH
New Emerging ransomware: RORSCHACH

6 Apr 2023

One of the fastest-encrypting ransomware strains, known as “Rorschach,” has been identified by security experts. It has also demonstrated sophisticated evasion skills in attacks across the globe. The ransomware was swiftly identified as an especially effective and seemingly unrelated strain after it was discovered during an attack on the Windows environment of an undisclosed US-based […]

Read More
Crown Resorts hacked, ransom demanded
Crown Resorts hacked, ransom demanded

30 Mar 2023

Crown representatives have admitted to falling victim to the Fortra GoAnywhere ransomware attack. An error in the GoAnywhere network was recently discovered by the ransomware organization Clop, which cybersecurity experts have since labeled a “zero-day” vulnerability. Due to a bug, Clop was able to sneak into GoAnywhere and steal info. More than 130 businesses’ data […]

Read More
TikTok Bans from Uk government devices
TikTok Bans from Uk government devices

23 Mar 2023

With immediate effect, the United Kingdom will prohibit TikTok from being used on any government-owned smartphones, joining other Western nations that have already done the same because to security concerns. “The security of sensitive government information must come first, so today we are banning this app on government devices. The use of other data-extracting apps […]

Read More
Shein’s Android app breached clipboard privacy.
Shein’s Android app breached clipboard privacy.

16 Mar 2023

According to a blog post by Microsoft Threat Intelligence, the Shein shopping platform app owned by a Chinese company was found to be accessing user clipboards on Android devices. “Microsoft discovered that an old version of the SHEIN Android application periodically read the contents of the Android device clipboard and, if a particular pattern was […]

Read More
LastPass breach caused by engineer’s outdated Plex software.
LastPass breach caused by engineer’s outdated Plex software.

9 Mar 2023

The LastPass breach was brought on by an engineer who neglected to update Plex on his personal computer. The LastPass recently revealed a “second attack,” in which a threat actor combined information obtained from a third-party data breach with information obtained from the August security breach. Then, to target the company, the attackers used a […]

Read More
LastPass Reveals more details on the breach
LastPass Reveals more details on the breach

2 Mar 2023

Threat actors obtained user information and partially encrypted password vault data, according to a compromise that LastPass announced in December. The organization has now revealed how the threat actors carried out this attack, claiming that they did so by using a senior DevOps engineer’s PC to install a keylogger using information obtained from two data […]

Read More
What to do after Twitter eliminates SMS 2FA for non-Blue users?
What to do after Twitter eliminates SMS 2FA for non-Blue users?

23 Feb 2023

On 15th Feburary 2022, Twitter on a blog post said “Phone-number based 2FA be used – and abused – by bad actors. So starting today, we will no longer allow accounts to enroll in the text message/SMS method of 2FA unless they are Twitter Blue subscribers. The availability of text message 2FA for Twitter Blue […]

Read More