ConsentFix v3 Targets Azure
ConsentFix v3 attacks automate OAuth abuse against Microsoft Azure, using social engineering and phishing to obtain tokens and hijack accounts despite multi-factor authentication.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
ConsentFix v3 attacks automate OAuth abuse against Microsoft Azure, using social engineering and phishing to obtain tokens and hijack accounts despite multi-factor authentication.
A 19-year-old Scattered Spider hacking group member has been arrested, and a critical vulnerability has been discovered in an outdated NSA mapping tool, posing a risk to industrial networks.
Two former cybersecurity professionals, Ryan Goldberg and Kevin Martin, were sentenced to four years in prison for committing ransomware attacks in 2023.
Cisco has released an open source tool, Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models.
Microsoft has fixed a bug causing Remote Desktop security warnings to display incorrectly on devices with multiple monitors and different display scaling settings.
US government and allies publish guidance on safely deploying autonomous artificial intelligence systems, warning of insufficient safeguards in critical infrastructure and defense sectors.
The Senate Judiciary Committee has advanced a bill that would bar artificial intelligence companies from letting children use AI companions, citing concerns over child safety and exploitation.
Illinois Representative Delia Ramirez has been appointed as the top Democrat on the House Homeland Security Committee's Cybersecurity and Infrastructure Protection Subcommittee, replacing Eric Swalwell following his resignation from Congress.
CISA has issued separate advisories for vulnerabilities in Zero Motorcycles electric bikes and Yadea T5 scooters that could allow attackers to upload malicious firmware or steal vehicles outright.