Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no CVE. The firm says it reported the flaw to Argo CD’s maintainers in
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges
Peter Stokes, 19, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, where a judge ordered him held in custody.
Finnish police
Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings
Microsoft’s new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings.
The post Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings appeared first on SecurityWeek.
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.
These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others.
DHS confirms hackers breached HSIN info-sharing platform
VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer
The activity has been codenamed VEIL#DROP by Securonix. It’s suspected that the initial payloads are distributed either via spear-phishing or a drive-by compromise, which occurs when an unsuspecting user lands on
Webinar: Why traditional email security is no longer enough
Hackers target Microsoft 365 accounts with 81 million login attempts
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain or Portugal, and hides its real payload inside an image.
The goal is the usual one: steal banking logins and take
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
The ColdFusion updates “resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and security feature bypass,” Adobe said in an alert released Tuesday.
The vulnerabilities are listed
