Iranian Seedworm hackers target organizations worldwide via Microsoft Teams
The attacker posed as an external IT support worker using a fake Microsoft 365 domain designed to appear legitimate.
The attacker posed as an external IT support worker using a fake Microsoft 365 domain designed to appear legitimate.
Tyler Buchanan and his co-conspirators targeted at least a dozen companies and stole at least $8 million from victims across the US.
More recent incidents show a shift toward social engineering and alternative entry points.
Attackers are exploiting a known vulnerability (CVE-2024-3721) affecting TBK DVR-4104 and DVR-4216 devices.
In brief: Microsoft and Adobe fix zero-days, the Russian Grinex crypto exchange hacked for 1 billion rubles, and more.
CERT-UA believes the attacks may also target individuals connected to Ukraine’s Defense Forces
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.
In addition to the SharePoint zero-day, Microsoft also patched a publicly disclosed privilege-escalation flaw.
There are no other public reports so far confirming active exploitation of CVE-2020-9715, CVE-2023-36424, or CVE-2025-60710 besides CISA’s KEV list.
Researchers found that 54 of the extensions specifically target Google account data using OAuth2, while 45 include a hidden backdoor.
Showing elements 121 - 130