Aggregator
New Microsoft Exchange Vulnerability Puts Hybrid Cloud Environments at Risk
Weaponizing Microsoft 365 Direct Send to Bypass Email Security Defenses
Security researchers at StrongestLayer, in collaboration with Jeremy, a seasoned Security Architect at a major manufacturing firm, have exposed a multi-layered spear phishing attack that exploits Microsoft 365’s Direct Send feature to infiltrate corporate email systems. The campaign, flagged initially by StrongestLayer’s AI system TRACE, masqueraded as innocuous voicemail notifications from services like RingCentral, but […]
The post Weaponizing Microsoft 365 Direct Send to Bypass Email Security Defenses appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Chanel Alerts Clients of Third-Party Breach
–269 °C, 1,5 ГПа, 30% пластичности. Китай создал броню, способную удерживать термояд
New Ghost Calls Attack Abuses Web Conferencing for Covert Command & Control
A sophisticated new attack technique called “Ghost Calls” exploits web conferencing platforms to establish covert command and control (C2) channels. Presented by Adam Crosser from Praetorian at Black Hat USA 2025, this groundbreaking research demonstrates how attackers can leverage the TURN protocol and legitimate conferencing infrastructure to bypass network security measures. Key Takeaways1. TURNt tool […]
The post New Ghost Calls Attack Abuses Web Conferencing for Covert Command & Control appeared first on Cyber Security News.
CISA Warns of ‘ToolShell’ Exploits Chain Attacks SharePoint Servers – Discloses IOCs and detection signatures
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an urgent analysis in early July 2025, detailing a sophisticated exploit chain targeting on-premises Microsoft SharePoint servers. Dubbed “ToolShell,” the campaign leverages two fresh vulnerabilities—CVE-2025-49706, a network spoofing flaw, and CVE-2025-49704, a remote code execution weakness—to gain unauthorized access and install stealthy webshells. Initial compromise begins […]
The post CISA Warns of ‘ToolShell’ Exploits Chain Attacks SharePoint Servers – Discloses IOCs and detection signatures appeared first on Cyber Security News.
WhatsApp Has Taken Down 6.8 Million Accounts Linked to Malicious Activities
WhatsApp has successfully dismantled 6.8 million accounts linked to fraudulent activities during the first half of 2024, representing a significant escalation in the platform’s fight against organized cybercrime. The takedown operation, announced by parent company Meta, specifically targeted scam centers operating across Southeast Asia that frequently exploit forced labor to execute sophisticated fraud schemes targeting […]
The post WhatsApp Has Taken Down 6.8 Million Accounts Linked to Malicious Activities appeared first on Cyber Security News.