+44 (0)203 88 020 88

Author name: secureteampstg

New Backdoor Linux Malware ‘Lightning Framework’

A new, previously undetected, Linux malware known as ‘Lightning Framework’ can be used as a backdoor to install rootkits in infected devices via Secure Shell (SSH). A report released by Intezer this week calls this malware “Swiss Army Knife-like” due to its wide range of capabilities, and ability to use techniques to avoid detection and

New Backdoor Linux Malware ‘Lightning Framework’ Read More »

Proof of Concept Released for MacOS Vulnerability

The Microsoft 365 Defender Research Team have released a security warning to macOS users about a vulnerability they have discovered in Apple’s App Sandbox. The vulnerability tracked as CVE-2022-26706 was first uncovered in October 2021, however a new Proof of Concept (PoC) has been released by Microsoft in two formats, one of which is describe

Proof of Concept Released for MacOS Vulnerability Read More »

Phishing Attacks That Can Bypass MFA

A large-scale phishing attack campaign has emerged using adversary-in-the-middle (AiTM) to steal credentials and circumvent multi-factor authentication (MFA) needs. Microsoft have released a security blog post regarding the use of these phishing attacks and the impersonation of Microsoft Azure Active Directory (Azure AD) login pages. This campaign has reportedly targeted over 10,000 organisations in the

Phishing Attacks That Can Bypass MFA Read More »

Publicly Disclosed Windows Vulnerability Patched

An actively exploited Windows Client Server Runtime Subsystem (CSRSS) vulnerability was one of 84 patched in this week’s Microsoft patch Tuesday. First discovered by the Microsoft Threat intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC), CVE-2022-22047 is tracked as a ‘High’ severity vulnerability, with a CVSS rating of 7.8/10. It affects devices running Windows

Publicly Disclosed Windows Vulnerability Patched Read More »

Chrome Update Patches Zero-Day Vulnerabilities

Google released updates this week for Android and desktop Chrome browser users. These updates address high criticality zero-day vulnerabilities including one which has been actively exploited. This is the fourth Chrome update so far this year to patch zero-day vulnerabilities, with previous key updates being released in February, March, and April. Users should make sure

Chrome Update Patches Zero-Day Vulnerabilities Read More »

Microsoft Patches Linux Cluster Bug

The Microsoft Security Response Centre released a blog post this week about a Service Fabric (SF) Linux Cluster vulnerability. This bug has been identified on both Linux and Windows operating systems, however Microsoft claims only Linux is vulnerable to attack. This vulnerability was published as CVE-2022-30137 by Microsoft earlier this month.  Azure Service Fabric is a distributed systems

Microsoft Patches Linux Cluster Bug Read More »

Scroll to Top