U.S. Charges Three Chinese Hackers for Hacking Siemens, Trimble & Moody

Haythem Elmir

The United States Justice Department has charged three Chinese nationals for allegedly hacking Moody’s Analytics economist, German electronics manufacturer Siemens, and GPS maker Trimble, and stealing gigabytes of sensitive data and trade secrets. According to an indictment unsealed Monday in federal court in Pittsburgh, Pennsylvania, the three men worked for […]

The Cobalt group is exploiting the CVE-2017-11882 Microsoft Office flaw in targeted attacks

Haythem Elmir

A few days after details about the CVE-2017-11882 Microsoft Office flaw were publicly disclosed, the firm Reversing Lab observed Cobalt group using it. A few days after details about the CVE-2017-11882 Microsoft Office vulnerability were publicly disclosed, security experts from firm Reversing Lab observed criminal gang using it in the wild. The gang is […]

Facebook Flaw Allowed Removal of Any Photo

Haythem Elmir

A researcher says he received a $10,000 bounty from Facebook after finding a critical vulnerability that could have been exploited to delete any photo from the social media network. In early November, Facebook announced a new feature for posting polls that include images and GIF animations. Iran-based security researcher and […]

SAML POST-INTRUSION ATTACK MIRRORS ‘GOLDEN TICKET’

Haythem Elmir

Researchers at CyberArk Labs have created a post-intrusion attack technique known as a Golden SAML that could allow an attacker to fake enterprise user identities and forge authentication to gain access to valuable cloud resources in a federation environment. “Using this post-exploit technique, attackers can become any user they want […]