Device code phishing uses Microsoft's real auth pages. The stock exchange exfiltration used Dropbox and OneDrive as C2. SendGrid and Amazon SES carry the phishing payload.
Every attack this week succeeded because trusted infrastructure was used correctly.
French government's secure messaging system Tchap was breached, what does this say about the vulnerability of supposedly secure systems, can any system be truly secure?
#infosec#cybersecurity#messagingsecurity
Source: French government’s secure messaging system breached
Stolen API keys are sold on the dark web for as little as $5, giving attackers a foothold for supply-chain attacks. Can your business afford to ignore this risk
#cybersecurity#supplychainrisk#darkweb
Source: Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
73,000 French govt employees had their Tchap messenger accounts breached, leaving sensitive info exposed. How vulnerable is your company's messaging platform?
Protect your inbox: soemailsecurity.com, can you afford to wait?
#emailsecurity#cybersecurity#dataprotection
Maine's breach portal was recently exploited to publish fake data breach disclosures, with false claims being made public before verification, can we trust public breach portals to verify info before posting
#cybersecurity#datasecurity#breachnotification
Tenet Security discovered Agentjacking, which tricks AI coding agents into running malicious code via fake error reports on Sentry, what's the real risk to developer machines here
#cybersecurity#AIsecurity#Agentjacking
Novo Nordisk just admitted a breach of clinical trials data, putting sensitive patient info at risk. 700 million people worldwide have diabetes, can we really trust companies to keep our health data safe? Protect your inbox: soemailsecurity.com#cybersecurity#datasecurity