Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover

Cybersecurity researchers at Wiz found CosmosEscape in Azure’s Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found. Continue reading Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover

LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people. Continue reading LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw. Continue reading 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw. Continue reading 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

EY confirmed the theft of client tax documents from its third-party support platform. ShinyHunters claims responsibility and is threatening to publish the data. Continue reading ShinyHunters Claims Ernst & Young (EY) Data Breach, Threatens July 31 Leak

Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations Continue reading Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections

Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation

Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates. Continue reading Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens. Continue reading Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts