Phishers exploit Zoom, WebEx brands to target businesses

Proofpoint researchers have spotted and documented email phishing campaigns targeting US companies in a variety of industries with emails impersonating Zoom and Cisco (WebEx). Phishing emails impersonating Zoom and WebEx “Video conferencing has become … Continue reading Phishers exploit Zoom, WebEx brands to target businesses

Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures

In episode 117 for April 20th 2020: More problems for Zoom with tens of thousands of compromised credentials and zero-day exploits, the $5 million dollar reward for information on North Korean hackers, and why it might not be the best idea to post your… Continue reading Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures

Finding Zoom Meeting Details in the Wild

The popular web conference platform Zoom has been in the storm for a few weeks. With the COVID19 pandemic, more and more people are working from home and the demand for web conference tools has been growing. Vulnerabilities have been discovered in the Zoom client and, based on the fact

[The post Finding Zoom Meeting Details in the Wild has been first published on /dev/random]

Continue reading Finding Zoom Meeting Details in the Wild

This Week in Security: Git, Patch Tuesday, Anti-Cheat, and Vulnerable Documentation

Git released an update on Tuesday, fixing an issue that could result in leaking credentials. The vulnerability was in how Git handles an HTTP URL containing a newline. Looking at the commits in 2.26.1, we can find an example of an attack:
url = "https://one.example.com?%0ahost=two.example.com/foo.git"

So doing a git pull …read more

Continue reading This Week in Security: Git, Patch Tuesday, Anti-Cheat, and Vulnerable Documentation

Zoom Zero-Days For Sale: Critical RCE at $500,000

Another day, another Zoom infosec dumpster fire.
The post Zoom Zero-Days For Sale: Critical RCE at $500,000 appeared first on Security Boulevard.
Continue reading Zoom Zero-Days For Sale: Critical RCE at $500,000

Zoom Zero-Day Windows Vulnerability Selling for $500,000

A couple of zero-day Zoom vulnerabilities are reportedly for sale online, including one for Windows and one for macOS, with the asking price for the Windows one topping $500,000, according to a Motherboard report. Zero-day vulnerabilities are the most … Continue reading Zoom Zero-Day Windows Vulnerability Selling for $500,000