Cyber Defense Advisors

Month: November 2023

  • by
  • November 9, 2023

When Email Security Meets SaaS Security: Uncovering Risky Auto-Forwarding Rules

While intended for convenience and efficient communication, email auto-forwarding rules can inadvertently lead to the unauthorized dissemination of sensitive information to external entities, putting confidential data at risk of exposure to unauthorized parties. Wing Security (Wing), a SaaS security company, announced yesterday that their SaaS shadow IT discovery methods now include a solution that solves […]

Cyber News
  • by
  • November 9, 2023

MuddyC2Go: New C2 Framework Iranian Hackers Using Against Israel

Iranian nation-state actors have been observed using a previously undocumented command-and-control (C2) framework called MuddyC2Go as part of attacks targeting Israel. “The framework’s web component is written in the Go programming language,” Deep Instinct security researcher Simon Kenin said in a technical report published Wednesday. The tool has been attributed to MuddyWater, an Iranian state-sponsored […]

Cyber News
  • by
  • November 9, 2023

CISA Alerts: High-Severity SLP Vulnerability Now Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw in the Service Location Protocol (SLP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Tracked as CVE-2023-29552 (CVSS score: 7.5), the issue relates to a denial-of-service (DoS) vulnerability that could be weaponized to launch massive DoS amplification […]

Cyber News

Smashing Security podcast #347: Trolls, military data, and the hitman and her

A woman’s attempt to hire an assassin online backfires badly, it’s scary just how cheap it is to buy information about US military personnel, and trolls and tattoos don’t mix. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, […]

Cyber News, Cyber Threat Trends

Smashing Security podcast #347: Trolls, military data, and the hitman and her

A woman’s attempt to hire an assassin online backfires badly, it’s scary just how cheap it is to buy information about US military personnel, and trolls and tattoos don’t mix. All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, […]

Cyber News

Women sue plastic surgery after hack saw their naked photos posted online

Graham CLULEY November 08, 2023 Promo Protect all your devices, without slowing them down. Free 30-day trial Photos of naked patients and medical records have been posted online by extortionists who hacked a Las Vegas plastic surgery, driving victims to file a lawsuit claiming not enough care was taken to protect their private information. As […]

Cyber News

Microsoft Warns of Election Threats in 2024

To address these challenges, Microsoft is introducing several initiatives

Cyber News, Cyber Threat Trends
  • by
  • November 8, 2023

Identifying Group Policy attacks

A threat hunt looks at three attacker changes to a compromised Active Directory, and explains how to both understand and overcome them

Cyber News, Cyber Threat Trends
  • by
  • November 8, 2023

Scam Texts Are More Painful Than Getting a Root Canal

Sick and tired of scam messages? So are the 54% of Americans who said they’d rather get a root canal than fall for one of those scams.  That’s one of the striking findings we uncovered in our Global Scam Message Study. We surveyed more than 7,000 adults worldwide — including more than 1,000 in the […]

Cyber News, Cyber Threat Trends