Why the company took so long to address the issue is not known given that most other stakeholders had a fix out for the issue months ago.
Follow Dark Reading:
 June 20, 2024
LATEST SECURITY NEWS & COMMENTARY
Microsoft, Late to the Game on Dangerous DNSSEC Zero-Day Flaw
Why the company took so long to address the issue is not known given that most other stakeholders had a fix out for the issue months ago.
Scattered Spider Pivots to SaaS Application Attacks
Microsoft last year described the threat actor — known as UNC3944, Scattered Spider, Scatter Swine, Octo Tempest, and 0ktapus — as one of the most dangerous current adversaries.
'ONNX' MFA Bypass Targets Microsoft 365 Accounts
The service, likely a rebrand of a previous operation called "Caffeine," mainly targets financial institutions in the Americas and EMEA and uses malicious QR codes and other advanced evasion tactics.
Emojis Control the Malware in Discord Spy Campaign
Pakistani hackers are spying (▀̿Ĺ̯▀̿ ̿) on the highly sensitive organizations in India by using emojis (Ծ_Ծ) as malicious commands (⚆ᗝ⚆) and the old Dirty Pipe Linux flaw.
Apple Intelligence Could Introduce Device Security Risks
The company focused heavily on data and system security in the announcement of its generative AI platform, Apple Intelligence, but experts worry that companies will have little visibility into data security.
PoC Exploit Emerges for Critical RCE Bug in Ivanti Endpoint Manager
A new month, a new high-risk Ivanti bug for attackers to exploit — this time, an SQL injection issue in its centralized endpoint manager.
Hamas Hackers Sling Stealthy Spyware Across Egypt, Palestine
The Arid Viper APT group is deploying AridSpy malware with Trojanized messaging applications and second-stage data exfiltration.
Space: The Final Frontier for Cyberattacks
A failure to imagine — and prepare for — threats to outer-space related assets could be a huge mistake at a time when nation-states and private companies are rushing to deploy devices in a frantic new space race.
North Korea's Moonstone Sleet Widens Distribution of Malicious Code
The recently identified threat actor uses public registries for distribution and has expanded capabilities to disrupt the software supply chain.
'Sleepy Pickle' Exploit Subtly Poisons ML Models
A model can be perfectly innocent, yet still dangerous if the means by which it's packed and unpacked are tainted.
Name That Toon: Future Shock
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.
The Software Licensing Disease Infecting Our Nation's Cybersecurity
Forcing Microsoft to compete fairly is the most important next step in building a better defense against foreign actors.
Addressing Misinformation in Critical Infrastructure Security
As the lines between the physical and digital realms blur, widespread understanding of cyber threats to critical infrastructure is of paramount importance.
MORE NEWS / MORE COMMENTARY
HOT TOPICS
Why Trading Privacy for 'Free' Web Services Must End
Meta's new subscription model points out the need for clearer and stricter regulations — ones that prioritize consumer privacy and control of personal data.

How Cybercrime Empires Are Built
Strong partnerships and collaborations between industry and law enforcement are the most critical ways to take down cybercrime groups before they grow.

Understanding Security's New Blind Spot: Shadow Engineering
In the rush to digital transformation, many organizations are exposed to security risks associated with citizen developer applications without even knowing it.

MORE
PRODUCTS & RELEASES
EDITORS' CHOICE
Critical VMware Bugs Open Swaths of VMs to RCE, Data Theft
A trio of bugs could allow hackers to escalate privileges and remotely execute code on virtual machines deployed across cloud environments.
LATEST FROM THE EDGE

How Cybersecurity Can Steer Organizations Toward Sustainability
By integrating environmental initiatives, social responsibility, and governance into their strategies, security helps advance ESG goals.
LATEST FROM DR TECHNOLOGY

CHERI Alliance Aims to Secure Hardware Memory
The consortium of private companies and academia will focus on ways to protect hardware memory from attacks.
LATEST FROM DR GLOBAL

Singapore Extradites Suspected Cybercrime Scammers from Malaysia
Cops decimate cybercrime infrastructure used to steal data from nearly 2,000 people in Singapore last year.
WEBINARS
WHITE PAPERS
FEATURED REPORTS
View More Dark Reading Reports >>
Dark Reading Weekly
-- Published By Dark Reading
Informa Tech Holdings LLC | Registered in the United States
with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
To opt-out of any future Dark Reading Weekly Newsletter emails, please respond here.
Thoughts about this newsletter? Give us feedback.
Keep This Newsletter Out Of Your SPAM Folder
Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list:
If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation.
We take your privacy very seriously. Please review our Privacy Statement.