Cyber News & Articles

Cyber News & Articles

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API 

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure.
The flaws, discovered by Melbourne-based cybersecurity company Stratus Security, have been addressed as of May 2024. Two of the three shortcomings reside in Power Platform’s OData Web API Filter, while the third vulnerability is rooted in the FetchXML

read more
Cyber News & Articles

Cross-Domain Attacks: A Growing Threat to Modern Security and How to Combat Them 

In the past year, cross-domain attacks have gained prominence as an emerging tactic among adversaries. These operations exploit weak points across multiple domains – including endpoints, identity systems and cloud environments – so the adversary can infiltrate organizations, move laterally and evade detection. eCrime groups like SCATTERED SPIDER and North Korea-nexus adversaries such as FAMOUS

read more
Cyber News & Articles

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT 

Cybersecurity researchers have discovered a malicious package on the npm package registry that masquerades as a library for detecting vulnerabilities in Ethereum smart contracts but, in reality, drops an open-source remote access trojan called Quasar RAT onto developer systems.
The heavily obfuscated package, named ethereumvulncontracthandler, was published to npm on December 18, 2024, by a user

read more
Cyber News & Articles

Three Russian-German Nationals Charged with Espionage for Russian Secret Service 

German prosecutors have charged three Russian-German nationals for acting as secret service agents for Russia.
The individuals, named Dieter S., Alexander J., and Alex D., have been accused of working for a foreign secret service. Dieter S. is also alleged to have participated in sabotage operations as well as taking pictures of military installations with an aim to endanger national security.

read more
Cyber News & Articles

The AI Fix #31: Replay: AI doesn’t exist 

Mark and I took a break for the new year, but we’ll be back for a new episode of “The AI Fix” podcast at the usual time next week.

In the meantime, here is another chance to hear one of our favourite episodes again. The very first episode from April 2024…

Graham attempts to convince Mark that AI doesn’t, in fact, exist. We aren’t going to spoil it for you, but we can tell you that his theory starts in a bad hotel room in San Francisco, features some Wizard of Oz style sleight of hand by Amazon, and ends with ChatGPT refusing to supply some offensive terms for Gary Barlow.

read more
Cyber News & Articles

New “DoubleClickjacking” Exploit Bypasses Clickjacking Protections on Major Websites 

Threat hunters have disclosed a new “widespread timing-based vulnerability class” that leverages a double-click sequence to facilitate clickjacking attacks and account takeovers in almost all major websites.
The technique has been codenamed DoubleClickjacking by security researcher Paulos Yibelo.
“Instead of relying on a single click, it takes advantage of a double-click sequence,” Yibelo said.

read more
Cyber News & Articles

Iranian and Russian Entities Sanctioned for Election Interference Using AI and Cyber Tactics 

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday leveled sanctions against two entities in Iran and Russia for their attempts to interfere with the November 2024 presidential election.
The federal agency said the entities – a subordinate organization of Iran’s Islamic Revolutionary Guard Corps and a Moscow-based affiliate of Russia’s Main Intelligence

read more
Cyber News & Articles

New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy 

The U.S. Department of Justice (DoJ) has issued a final rule carrying out Executive Order (EO) 14117, which prevents mass transfer of citizens’ personal data to countries of concern such as China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela.
“This final rule is a crucial step forward in addressing the extraordinary national security threat posed of our

read more
Cyber News & Articles

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents 

The United States Treasury Department said it suffered a “major cybersecurity incident” that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents. 
“On December 8, 2024, Treasury was notified by a third-party software service provider, BeyondTrust, that a threat actor had gained access to a key used by the vendor to secure a cloud-based

read more

CALL US TODAY TO SPEAK TO A SECURITY EXPERT: 720.221.6804

X