KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
Hijacking Traffic To Microsoft’s Windows.com With Bitflipping A researcher was able to “bitsquat” Microsoft’s windows.com domain by cybersquatting variations of windows.com. However, this technique differs from cases where typosquatting domains are used for phishing activities in that it requires no action on the victim’s part. This is due to the nature of a concept known as bit
Hacked SendGrid Accounts Used In Phishing Attacks To Steal Logins A phishing campaign targeting users of Outlook Web Access and Office 365 services collected thousands of credentials relying on trusted domains such as SendGrid. The threat actor behind this activity, which received the name “Compact,” has been operating since at least the beginning of 2020
Windows DNS SIGRed Bug Gets First Public RCE PoC Exploit A working proof-of-concept (PoC) exploit is now publicly available for the critical SIGRed Windows DNS Server remote code execution (RCE) vulnerability. Microsoft issued security updates to address the security flaw tracked as CVE-2020-1350 on July 14, 2020, together with a registry-based workaround that helps protect affected Windows servers from
DHS Orders Agencies To Urgently Patch Or Disconnect Exchange Servers The Department of Homeland Security’s cybersecurity unit has ordered federal agencies to urgently update or disconnect Microsoft Exchange on-premises products on their networks. The Cybersecurity and Infrastructure Security Agency (CISA) issued the Emergency Directive 21-02 Wednesday after Microsoft patched four zero-day Exchange bugs in emergency