Midnight Blizzard Escalates Spear-Phishing Attacks On Over 100 Organizations

Russian hackers, known as Midnight Blizzard, launch targeted spear-phishing on U.S. officials, exploiting RDP files to gain access to data. Continue reading Midnight Blizzard Escalates Spear-Phishing Attacks On Over 100 Organizations

Russian Cozy Bear Hackers Phish Critical Sectors with Microsoft, AWS Lures

Russian state-sponsored hackers Cozy Bear are targeting over 100 organizations globally with a new phishing campaign. This sophisticated… Continue reading Russian Cozy Bear Hackers Phish Critical Sectors with Microsoft, AWS Lures

Google Catches Russian APT Reusing Exploits From Spyware Merchants NSO Group, Intellexa

Google TAG publishes evidence showing identical or striking similarities between exploits used by Russia’s APT29 and commercial spyware vendors.
The post Google Catches Russian APT Reusing Exploits From Spyware Merchants NSO Group, Intellexa appeared f… Continue reading Google Catches Russian APT Reusing Exploits From Spyware Merchants NSO Group, Intellexa

Microsoft Alerts More Customers to Email Theft in Expanding Midnight Blizzard Hack

Shockwaves from the Russian government’s hack of Microsoft’s corporate infrastructure continue to spread as the victim pool widens.
The post Microsoft Alerts More Customers to Email Theft in Expanding Midnight Blizzard Hack appeared first on SecurityW… Continue reading Microsoft Alerts More Customers to Email Theft in Expanding Midnight Blizzard Hack

BeyondTrust Report: Microsoft Security Vulnerabilities Decreased by 5% in 2023

Refreshed software and collaboration with the security researcher community may have contributed to the 5% drop. Continue reading BeyondTrust Report: Microsoft Security Vulnerabilities Decreased by 5% in 2023

US Government on High Alert as Russian Hackers Steal Critical Correspondence From Microsoft

The US government says Midnight Blizzard’s compromise of Microsoft corporate email accounts “presents a grave and unacceptable risk to federal agencies.”
The post US Government on High Alert as Russian Hackers Steal Critical Correspondence From Microso… Continue reading US Government on High Alert as Russian Hackers Steal Critical Correspondence From Microsoft

CISA emergency directive tells agencies to fix credentials after Microsoft breach

CyberScoop first reported on the existence of the directive, which calls the pilfered emails “a grave and unacceptable risk to agencies.”

The post CISA emergency directive tells agencies to fix credentials after Microsoft breach appeared first on CyberScoop.

Continue reading CISA emergency directive tells agencies to fix credentials after Microsoft breach