Microsoft Entra ID’s Administrative Units Weaponized to Gain Stealthy Persistence

Datadog Security Labs recently revealed a security risk within Microsoft Entra ID, showing how its administrative units (AUs) can be weaponized by attackers to create persistent backdoor access.

Cyware News – Latest Cyber News – ​Read More

Adversarial attacks on AI models are rising: what should you do now?

With AI’s growing influence across industries, malicious attackers continue to sharpen their tradecraft to exploit ML models.Read More

Security News | VentureBeat – ​Read More

Ivanti’s Cloud Service Appliance Attacked via Second Vuln

The critical bug, CVE-2024-8963, can be used in conjunction with the prior known flaw to achieve remote code execution (RCE).

darkreading – ​Read More

Citrine Sleet Poisons PyPI Packages With Mac & Linux Malware

A North Korean advanced persistent threat (APT) actor (aka Gleaming Pisces) tried to sneak simple backdoors into public software packages.

darkreading – ​Read More

More than $44 million in cryptocurrency stolen from Singaporean platform BingX

Singaporean crypto platform BingX said Friday that more than $44 million was stolen from their platform in a cyberattack.

The Record from Recorded Future News – ​Read More

Zero-Click MediaTek Bug Opens Phones, Wi-Fi to Takeover

Critical-rated CVE-2024-20017 allows remote code execution (RCE) on a range of phones and Wi-Fi access points from a variety of OEMs.

darkreading – ​Read More

Police Broke Tor Anonymity to Arrest Dark Web Users in Major CSAM Bust

German authorities dismantled Boystown, a notorious Dark Web platform for CSAM, by deanonymizing Tor users in 2021. This…

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Airline exec settles hack-for-hire case against law firm, pledging to ‘vigorously’ prosecute other alleged conspirators

The aviation executive Farhad Azima settled litigation this week against the law firm Dechert and two of its former attorneys who he alleged were involved in the hacking of his personal accounts in order to smear his reputation.

The Record from Recorded Future News – ​Read More

Ukraine Bans Telegram Messenger App on State-Issued Devices Because of Russian Security Threat

Ukraine issued the Telegram ban for the official devices of government employees, military personnel, security and defense workers, and critical infrastructure employees.

The post Ukraine Bans Telegram Messenger App on State-Issued Devices Because of Russian Security Threat appeared first on SecurityWeek.

SecurityWeek – ​Read More

Internet surveillance firm Sandvine says it’s leaving 56 “non-democratic” countries

Sandvine sold its internet surveillance products to authoritarian regimes, including Belarus, Egypt, Eritrea, the United Arab Emirates, and Uzbekistan.

© 2024 TechCrunch. All rights reserved. For personal use only.

Security News | TechCrunch – ​Read More