Has Microsoft cut security corners once too often?

Credit to Author: eschuman@thecontentfirm.com| Date: Mon, 07 Aug 2023 10:00:00 -0700

As Microsoft revealed tidbits of its post-mortem investigation into a Chinese attack against US government agencies via Microsoft, two details stand out: the company violated its own policy and did not store security keys within a Hardware Security Module (HSM) — and the keys were successfully used by attackers even though they had expired years earlier. 

This is simply the latest example of Microsoft quietly cutting corners on cybersecurity and then only telling anyone when it gets caught. 

To read this article in full, please click here

Read more

TargetCompany Ransomware Abuses FUD Obfuscator Packers

Credit to Author: Don Ovid Ladores| Date: Mon, 07 Aug 2023 00:00:00 +0000

In this entry, we detail our analysis of how the TargetCompany ransomware abused an iteration of fully undetectable (FUD) obfuscator engine BatCloak to infect vulnerable systems.

Read more

The end looms for Meta’s behavioural advertising in Europe

Categories: Personal

Tags: meta

Tags: Facebook

Tags: EU

Tags: legal

Tags: litigation

Tags: behavioural

Tags: advertising

Tags: tracking

We take a look at what appears to be the beginning of the end for Meta’s behavioural advertising in Europe.

(Read more…)

The post The end looms for Meta’s behavioural advertising in Europe appeared first on Malwarebytes Labs.

Read more

Microsoft Teams used in phishing campaign to bypass multi-factor authentication

Categories: Business

Categories: News

Tags: Microsoft Teams

Tags: social engineering

Tags: bypass

Tags: MFA

Tags: authenticator

Attackers are using Microsoft Teams chats from compromised Microsft 365 tenants as credential theft phishing lures

(Read more…)

The post Microsoft Teams used in phishing campaign to bypass multi-factor authentication appeared first on Malwarebytes Labs.

Read more