Remove category microsoft-net
article thumbnail

Adobe Patch Tuesday fixed critical vulnerabilities in Magento, Acrobat and Reader

Security Affairs

” Below is the list of vulnerabilities addressed by the software vendor: Vulnerability Category Vulnerability Impact Severity CVSS base score CVSS vector CVE Number Out-of-bounds Write ( CWE-787 ) Arbitrary code execution Critical 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2024-20733 Use After Free ( CWE-416 ) Memory leak Important 5.5

Software 121
article thumbnail

Microsoft seized 41 domains used by Iran-linked Bohrium APT

Security Affairs

Microsoft’s Digital Crimes Unit (DCU) announced the seizure of domains used by Iran-linked APT Bohrium in spear-phishing campaigns. Microsoft’s Digital Crimes Unit (DCU) announced to have taken legal action to disrupt a spear-phishing operation linked to Iran-linked APT Bohrium. Middle East, and India. Pierluigi Paganini.

Phishing 111
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Cybercriminals Use Azure Front Door in Phishing Attacks

Security Affairs

Experts identified a spike in phishing content delivered via Azure Front Door (AFD), a cloud CDN service provided by Microsoft. USA) has identified a spike in phishing content delivered via Azure Front Door (AFD), a cloud CDN service provided by Microsoft. net – amazon-uk[.]azurefd[.]net. net – onlinesigninlogin[.]azurefd[.]net

Phishing 121
article thumbnail

New Woody RAT used in attacks aimed at Russian entities

Security Affairs

The attackers were delivering the malware using archive files and Microsoft Office documents exploiting the Follina Windows flaw ( CVE-2022-30190 ). Attacks exploiting the Windows Follina flaw were spotted on June 7, 2022, when researchers observed threat actors using a weaponized Microsoft Office document titled ???????.docx.

Malware 94
article thumbnail

10 Lessons Learned from the Top Cyber Threats of 2021

Security Boulevard

Microsoft Exchange Server Vulnerabilities. In January 2021, Volexity detected a large amount of egress data traffic on its customers’ Microsoft Exchange Servers [1]. In March 2021, Microsoft released several updates to patch zero day vulnerabilities found in Microsoft Exchange Server affecting versions 2010, 2013, 2016 and 2019 [2].

article thumbnail

Security Roundup August 2023

BH Consulting

She has been shortlisted for the Piccaso Privacy Awards 2023 in two categories: ESG privacy initiative, and the privacy award for achievement. Links we liked Five free online cybersecurity courses, via Help Net Security. MORE This free tool detects potentially malicious activity in Microsoft cloud platforms.

article thumbnail

Google ads lead to major malvertising campaign

Malwarebytes

Unsuspecting users searching for popular keywords will click an advert and their browser will get hijacked with fake warnings urging them to call rogue Microsoft agents for support. net/fC0deJdfd008f0d0CH888Err0r80dBG88/index.html. q=zillow&{…} Ad platform : clickserve.dartsearch.net/link/click?_v={…}

Scams 133