Microsoft warns about phishing campaign using open redirects – Malwarebytes Labs

Microsoft warns about phishing campaign using open redirects – Malwarebytes Labs

Microsoft warned about a massive credential phishing campaign using open redirects. Here’s how you can recognize these phishing mails. The Microsoft 365 Defender Threat Intelligence Team posted an article stating that they have been tracking a widespread credential phishing campaign using open redirector links. Open redirects have been part of the phisher’s arsenal for a…

QNAP works on patches for OpenSSL bugs impacting its NAS devices

QNAP works on patches for OpenSSL bugs impacting its NAS devices

Network-attached storage (NAS) maker QNAP is investigating and working on security updates to address remote code execution (RCE) and denial-of-service (DoS) vulnerabilities patched by OpenSSL last week. The security flaws tracked as CVE-2021-3711 and CVE-2021-3712, impact QNAP NAS device running QTS, QuTS hero, QuTScloud, and HBS 3 Hybrid Backup Sync (a backup and disaster recovery…

UNHCR ‘cautiously optimistic’ over working with Taliban

UNHCR ‘cautiously optimistic’ over working with Taliban

Filippo Grandi, the United Nations High Commissioner for Refugees, says there has been some “positive” contact with the Taliban. He told BBC World News the UNHCR had been dealing with the Taliban at both provincial and ground level. “I remember the interactions 25 years ago. If I compare those interactions with those that are happening…

CISA Expands ‘Bad Practices’ List With Single-Factor Authentication

CISA Expands ‘Bad Practices’ List With Single-Factor Authentication

The United States Cybersecurity and Infrastructure Security Agency (CISA) this week added single-factor authentication to its list of bad practices. “Single-factor authentication is a common low-security method of authentication. It only requires matching one factor—such as a password—to a username to gain access to a system,” CISA says. While the agency mainly refers to “the…

‘ProxyToken’ Exchange Server Vulnerability Leads to Email Compromise

‘ProxyToken’ Exchange Server Vulnerability Leads to Email Compromise

A vulnerability that Microsoft patched in Exchange Server earlier this year can allow attackers to set forwarding rules on target accounts and gain access to incoming emails. Tracked as CVE-2021-33766 and referred to as ProxyToken, the vulnerability has a severity rating of medium (CVSS score of 6.5). The security hole was identified by Le Xuan…