news.mlab.sh
Back to the feed
threat-intel

Serial Microsoft 0-day hunter drops yet another Defender exploit

HighCVSS 7.8
Summary

A persistent 0-day vulnerability is being exploited in on-prem Microsoft SharePoint, allowing attackers to bypass security measures. This follows previous failures to patch the issue, highlighting a significant ongoing risk for organizations relying on this software. The vulnerability is being actively leveraged by threat actors.

A persistent 0-day vulnerability is being exploited in on-prem Microsoft SharePoint, allowing attackers to bypass security measures. This follows previous failures to patch the issue, highlighting a significant ongoing risk for organizations relying on this software. The vulnerability is being actively leveraged by threat actors. The Register reports that attackers are posing as Signal support to launch phishing attacks, and the US has taken down Iranian propaganda sites. Microsoft has released a patch, but the vulnerability remains unaddressed for many users. Additionally, China is upgrading smartphone surveillance tools, and Ring is easing its anti-snooping stance. The cybersecurity firm Acronis has been acquired by EQT, representing a $3.5B+ valuation. Threat actors are also utilizing phishing attacks, mimicking Signal support to gain access to user accounts. The vulnerability is a significant concern for organizations using on-prem SharePoint, and the Register highlights that the US is taking down Iranian propaganda sites. The cybersecurity firm Acronis has been acquired by EQT, representing a $3.5B+ valuation. The vulnerability is a significant concern for organizations using on-prem SharePoint, and the Register highlights that the US is taking down Iranian propaganda sites.

Read the full article at The Register