"Microsoft Sway Abused in Massive QR Code Phishing Campaign"

"Microsoft Sway Abused in Massive QR Code Phishing Campaign"

A massive QR code phishing campaign has exploited Microsoft Sway, a cloud-based tool used for creating online presentations, to host landing pages aimed at tricking Microsoft 365 users into providing their credentials. Netskope Threat Labs discovered the attacks in July 2024, after detecting a significant increase in attacks involving Microsoft Sway to host phishing pages that steal Microsoft 365 credentials. This wave of attacks strongly differs from the minimal activity reported in the first half of the year, suggesting the campaign's large scale.

Submitted by Gregory Rigby on

"Can Your Smartwatch Get Hacked? Study Shows What Information Is at Risk"

"Can Your Smartwatch Get Hacked? Study Shows What Information Is at Risk"

According to a new Charles Darwin University (CDU) study, smartwatches can provide hackers with a wealth of personal information to exploit. The researchers hacked various smart wearable devices priced between $25 and $150 to learn about the technology's vulnerabilities and what information can be accessed and exploited. These devices enable people to track their health, monitor their fitness, perform medical tests, and more, but they frequently use Bluetooth Low Energy (BLE) technology, thus sacrificing security for low energy consumption.

Submitted by Gregory Rigby on

"A Third of Organizations Suffer SaaS Data Breaches"

"A Third of Organizations Suffer SaaS Data Breaches"

According to AppOmni, about 31 percent of global organizations experienced a data breach in their Software-as-a-Service (SaaS) applications last year while attempting to gain visibility and control over their cloud environment. To compile its "State of SaaS Security 2024 Report", the security vendor surveyed 644 enterprises with 2,500 or more employees in the US, UK, France, Germany, Japan, and Australia. The five-point increase in the share of breached respondents this year can be attributed to a number of factors identified in the study.

Submitted by Gregory Rigby on

"FBI Flawed Data Handling Raises Security Concerns"

"FBI Flawed Data Handling Raises Security Concerns"

A recent audit conducted by the Department of Justice's (DoJ) Office of the Inspector General (OIG) discovered that the FBI is exposing sensitive and classified data because of "significant weaknesses" in its inventory management and disposal of electronic storage media.

Submitted by Adam Ekwall on

NSA’s Summer 2025 Internship Opportunities - APPLY SEPT 1- OCT 1

NSA’s Summer 2025 Internship Opportunities - APPLY SEPT 1- OCT 1

The Science of Security team is pleased to announce the opening of... 

NSA’s Summer 2025 internship opportunities   

Ads open: September 1- October 1 

Who may Apply: College students (starting in freshman year) 

Submitted by Amy Karns on

"Protecting Connected, Self-Driving Vehicles From Hackers"

"Protecting Connected, Self-Driving Vehicles From Hackers"

A study led by the University of Michigan found that emerging self-driving vehicle networks that collaborate and communicate with one another or with infrastructure to make decisions are vulnerable to data fabrication attacks. The Vehicle-to-Everything (V2X) network of collaboration and communication is still in development as many countries are still testing it on a small scale. Information sharing among vehicles allows hackers to introduce fake objects or remove real objects from perception data, potentially causing vehicles to brake hard or crash.

Submitted by Gregory Rigby on

"Hackers Use Rare Stealth Techniques to Down Asian Military, Gov't Orgs"

"Hackers Use Rare Stealth Techniques to Down Asian Military, Gov't Orgs"

An ongoing campaign infects high-level organizations in Southeat Asia using two stealth techniques. The first method called "GrimResource," lets attackers run arbitrary code in the Microsoft Management Console (MMC). The second method, "AppDomainManager Injection," uses malicious Dynamic Link Libraries (DLLs). According to NTT researchers, an attacker similar to China's "APT41" has been using these methods to drop Cobalt Strike onto the Information Technology (IT) systems of Taiwanese government agencies, the Philippine military, and energy organizations in Vietnam.

Submitted by Gregory Rigby on

"Google Warns of Exploited Chrome Vulnerability"

"Google Warns of Exploited Chrome Vulnerability"

Less than a week after releasing Chrome 128 to the stable channel, Google warns that another bug resolved with the update is being exploited in the wild.  The issue tracked as CVE-2024-7965 (CVSS score of 8.8) is described by Google as an inappropriate implementation in the V8 JavaScript engine that allows a remote attacker to exploit heap corruption via crafted HTML pages.  Google noted that if the victim visits a compromised or malicious web page, the vulnerability could allow the attacker to execute code or access sensitive information.

Submitted by Adam Ekwall on

"Patelco Credit Union Says Breach Impacts 726k After Ransomware Gang Auctions Data"

"Patelco Credit Union Says Breach Impacts 726k After Ransomware Gang Auctions Data"

California-based Patelco Credit Union has recently started informing customers and employees about a data breach after a ransomware group managed to steal information from databases containing personal information from its systems. Patelco is a member-owned, non-profit credit union serving Northern California, particularly the San Francisco Bay Area. The organization detected a ransomware attack involving unauthorized access to its databases on June 29. An investigation revealed that the hackers accessed its systems between May 23 and June 29.

Submitted by Adam Ekwall on

"Seattle-Tacoma Airport IT Systems Down Due to a Cyberattack"

"Seattle-Tacoma Airport IT Systems Down Due to a Cyberattack"

The Seattle-Tacoma International Airport has confirmed that a cyberattack is likely behind the ongoing IT systems outage that disrupted reservation check-in systems and delayed flights over the weekend.  In 2023, the airport served almost 51 million passengers. The airport is a major hub for Alaska Airlines and Delta Air Line, serving 91 domestic and 28 international destinations.

Submitted by Adam Ekwall on
Subscribe to