Mass spamming starts with no MFA and credential stuffing

Microsoft has been monitoring and seeing an increase in attacks using malicious OAuth applications, installed on compromise cloud servers that then facilitate mass spamming from Exchange Online servers. Malicious OAuth applications abuse cloud email services to spread spam – Microsoft Security Blog The attack started with the threat actor launching …

Are you SQL servers secure? What, you do not know if you use SQL servers!

Many office and web based applications, both commercial and bespoke use SQL servers of varying flavours – you or your cyber security consultant should know if your organisation is dependent on a Microsoft SQL server and what actions have been taken to protect it. Here is the threat, ransomware targeting …

Microsoft Teams is keeping security tokens in plain text… and more UPDATED 23 September 2022

The original post was published on 16 September 2022 This is a real problem, no software or system should keep any security token in plain text, any time during operation. The user base for Microsoft Teams is in excess of 270 million users – we are part of that number …

Every major event will attract cyber criminals. What is your organisation doing on Monday 19 September?

The Queen

The death of Her Majesty Queen Elizabeth II and the associated ceremonies and period of national mourning will be no exception: Potential phishing activity update – NCSC.GOV.UK The National Cyber Security Centre has issued a warning that the potential for malicious phishing, social engineering and scam cyber-attacks is very high …