Saturday , November 23 2024

Vulnerabilities

Hackers Manipulate Font Size to Bypass Office 365 Security

ZeroFont Phishing is a new yet old technique for sending Phishing emails. It allows threat actors to bypass security mechanisms and successfully send phishing emails. Using this technique, attackers were able to evade Microsoft’s Natural Language Processing, which was serving as portion against phishing emails for Office users. Office 365 …

Read More »

Air Canada admits hack of employee data

Air Canada, the national airline of Canada, has acknowledged a “brief” breach in its security controls. Air Canada confirmed that an incident occurred, but they did not give details about when or how much personal information was accessed by the attacker. “An unauthorized group briefly obtained limited access to an …

Read More »

Researcher awarded discovering a Two-Factor Authentication bypass in Facebook

Bassem Bazzoun, a security researcher awarded for $25,300 and ranked 2nd place on the conference Leaderboard for discovering a Two-Factor Authentication bypass in Facebook during Meta bug bounty Researchers conference in Seoul, South Korea, 2023. If you’re curious about the technical details of how he managed to bypass Facebook’s two-factor …

Read More »

Chrome extensions can steal plaintext passwords from websites

A team of researchers from the University of Wisconsin-Madison has uploaded to the Chrome Web Store a proof-of-concept extension that can steal plaintext passwords from a website’s source code. An examination of the text input fields in web browsers revealed that the coarse-grained permission model underpinning Chrome extensions violates the principles …

Read More »

Credentials of NASA, Tesla, Verizon, and 2K others leaked by workplace safety organization

The National Safety Council has leaked nearly 10,000 emails and passwords of their members, exposing 2000 companies, including governmental organizations and big corporations. The National Safety Council (NSC) is a non-profit organization in the United States providing workplace and driving safety training. On its digital platform, NSC provides online resources …

Read More »

20% of malware attacks bypass antivirus protection

SpyCloud reports that 53% of security leaders are extremely concerned about attacks that use malware to steal authentication data. Only less than 1% of leaders are not concerned at all. Malware infection responses: Many people still don’t have the tools to investigate the security and organizational impact of these infections …

Read More »

Apple Issues an Emergency Patch to Address a Zero-Day Flaw

Apple released Rapid Security Response updates for its Safari web browser, iOS, iPadOS, and macOS to address a zero-day vulnerability that was being actively exploited. By exploiting the WebKit vulnerability known as CVE-2023-37450, malicious actors may execute arbitrary code while handling specially designed web content. The iPhone maker said it …

Read More »

Google Patches 46 Android Vulnerabilities, Including 3 Actively Exploited

Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Three of these vulnerabilities have been identified as actively exploited in targeted attacks. One vulnerability, tracked as CVE-2023-26083, is a memory leak flaw affecting the Arm Mali GPU driver for Bifrost, Avalon, and …

Read More »