KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
Microsoft Warns Of Incoming Windows Zerologon Patch Enforcement Microsoft today warned admins that updates addressing the Windows Zerologon vulnerability will transition into the enforcement phase starting next month. Zerologon is a critical 10/10 rated security flaw tracked as CVE-2020-1472 which, when successfully exploited, enables attackers to elevate privileges to domain administrator and take control over the domain. “We are reminding our customers
Undisclosed Apache Velocity XSS Vulnerability Impacts GOV Sites An undisclosed Cross-Site Scripting (XSS) vulnerability in Apache Velocity Tools can be exploited by unauthenticated attackers to target government sites, including NASAand NOAA. Although 90 days have elapsed since the vulnerability was reported and patched, BleepingComputer is not aware of a formal disclosure made by the project. Apache Velocity is a
UN Data Breach Exposes Over 100,000 UN Employees’ Details Sakura Samurai discovered an endpoint that exposed GitHub credentials on a United Nations Environment Program (UNEP) subdomain, which allowed them to access more than 100,000 UN employees’ records. A group of cybersecurity researchers from Sakura Samurai accessed around 100,000 personal records and login credentials of United Nations’ (UN)
Verified Twitter Accounts Hacked In $580k ‘Elon Musk’ Crypto Scam Threat actors are hacking verified Twitter accounts in an Elon Musk cryptocurrency giveaway scam that has recently become widely active. There is nothing new about cryptocurrency scams on Twitter, especially ones pretending to be giveaways from Elon Musk. In 2018, scammers raked in $180,000 using