Tag: office
-
Microsoft Defender for Office 365 to Block Email Bombing Attacks
First seen on thesecurityblogger.com Jump to article: www.thesecurityblogger.com/microsoft-defender-for-office-365-to-block-email-bombing-attacks/
-
UK fines 23andMe for ‘profoundly damaging’ breach exposing genetics data
The UK Information Commissioner’s Office (ICO) has fined genetic testing provider 23andMe £2.31 million ($3.12 million) over ‘serious security failings’ that led to a ‘profoundly damaging’ data breach in 2023. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/uk-fines-23andme-for-profoundly-damaging-breach-exposing-genetics-data/
-
DNA testing firm 23andMe fined £2.3m by UK regulator for 2023 data hack
Information stolen from US company included details of 150,000 British residents including family treesThe genetic testing company 23andMe has been fined more than £2.3m for failing to protect the personal information of more than 150,000 UK residents after a large-scale cyberattack in 2023.Family trees, health reports, names and postcodes were among the sensitive data hacked…
-
Microsoft Office 2016-Nutzer mit Copilot zwangsbeglückt
Die Woche ist mir erneut ein ein Fall untergekommen, wo Copilot, trotz gesetzter GPOs zum Deaktivieren, in Office 2016 auftaucht. Nachdem Sicherheitsforscher auf die erste Zero-Click-Schwachstelle in der KI-Anwendung Copilot gestoßen sind, greife ich das Thema nochmals hier im Blog auf. … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/14/microsoft-office-2016-nutzer-mit-copilot-zwangsbeglueckt/
-
Government offices in North Carolina, Georgia disrupted by cyberattacks
The city government of Thomasville, North Carolina, and a court district in eastern Georgia are responding to recent intrusions into their networks. First seen on therecord.media Jump to article: therecord.media/thomasville-nc-government-ogeechee-ga-district-cyberattacks
-
Cyberangriff auf eine Staatsanwaltschaft in Georgia, USA
Ogeechee Judicial Circuit District Attorney’s Office targeted in cyber attack, operations limited First seen on griceconnect.com Jump to article: www.griceconnect.com/local-news/ogeechee-judicial-circuit-district-attorneys-office-targeted-in-cyber-attack-operations-limited-10793672
-
Apple encryption row: Does law enforcement need to use Technical Capability Notices?
History shows that law enforcement can bring successful prosecutions without the need for the Home Office to introduce ‘backdoors’ into end-to-end encryption First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366625826/Apple-encryption-row-Does-law-enforcement-need-to-use-Technical-Capability-Notices
-
EchoLeak: Erste AI 0-Click-Sicherheitslücke in Microsoft Copilot
Sicherheitsforscher sind auf die erste Zero-Click-Schwachstelle in einer KI-Anwendung gestoßen. Wenig überraschend für mich betrifft dies Microsoft 365 Copilot. Angreifer könnten Microsoft 365 Copilot über diese, als EchoLeak bezeichnete, Schwachstelle zu einer Datenexfiltration zwingen. Microsoft “stülpt” ja allen Office-Anwendern den … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/13/echoleak-erste-ai-0-click-sicherheitsluecke-in-microsoft-copilot/
-
WhatsApp Backs Apple Over Encryption Fight With UK
WhatsApp CEO Says UK Request Sets Dangerous Precedent. Instant messaging app WhatsApp is seeking to join Apple’s legal battle with the U.K. government over end-to-end encryption. Apple is challenging a Home Office order requiring the device maker to provide law enforcement with unencrypted copies of customer data. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/whatsapp-backs-apple-over-encryption-fight-uk-a-28685
-
CSO Awards 2025 showcase world-class security strategies
A+E Global Media Marine Corps Community Services Accenture Marvell Adobe Mastercard Aflac Munich Re Ally Financial National Cybersecurity Alliance AmeriHealth Caritas Naval Information Warfare Center Pacific Amtrak New Jersey Institute of Technology Arizona Department of Child Safety Northern Nevada HOPES Augusta University NRC Health Avanade OHLA USA Avery Dennison Penn Medicine Avnet, Inc. Precisely Baptist…
-
New Cybersecurity Executive Order: What You Need To Know
Tags: ai, cisa, cloud, communications, compliance, computing, control, cyber, cybersecurity, data, defense, detection, encryption, exploit, fedramp, framework, government, identity, incident response, infrastructure, Internet, iot, network, office, privacy, programming, resilience, risk, service, software, supply-chain, technology, threat, update, vulnerability, vulnerability-management, zero-trustA new cybersecurity Executive Order aims to modernize federal cybersecurity with key provisions for post-quantum encryption, AI risk and secure software development. On June 6, 2025, the White House released a new Executive Order (EO) aimed at modernizing the nation’s cybersecurity posture. As cyber threats continue to evolve in scale and sophistication, the EO reinforces…
-
Outlook Vulnerability Allows Remote Execution of Arbitrary Code by Attackers
Microsoft confirmed a critical security vulnerability (CVE-2025-47176) in Microsoft Office Outlook, enabling attackers to execute arbitrary code. Despite the “Remote Code Execution” title, the attack vector is local, requiring attackers to run code from a user’s own machine. However, the potential impact remains high for organizations, as successful exploitation can compromise the confidentiality, integrity, and…
-
Government using national security as ‘smokescreen’ in Apple encryption row
Senior conservative MP David Davis says the Home Office should disclose how many secret orders it has issued against telecoms and internet companies to Parliament First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366625724/Government-using-national-security-as-smokescreen-in-Apple-encryption-row
-
Multiple Microsoft Office Vulnerabilities Enable Remote Code Execution by Attackers
Microsoft has disclosed four critical remote code execution (RCE) vulnerabilities in its Office suite as part of the June 2025 Patch Tuesday updates, posing significant risks to organizations and individuals who depend on the widely used productivity software. The vulnerabilities, tracked as CVE-2025-47162, CVE-2025-47953, CVE-2025-47164, and CVE-2025-47167, each received a CVSS v3.1 base score of…
-
Ohne Nutzerinteraktion: Microsoft Office anfällig für Schadcode-Attacken
Wer Microsoft Office verwendet, sollte dringend die Juni-Updates einspielen. Angreifer können ohne Zutun des Nutzers Schadcode zur Ausführung bringen. First seen on golem.de Jump to article: www.golem.de/news/ohne-nutzerinteraktion-microsoft-office-anfaellig-fuer-schadcode-attacken-2506-197030.html
-
June 2025 Patch Tuesday: Microsoft Fixes 66 Bugs, Including Active 0-Day
June 2025 Patch Tuesday fixes 66 bugs, including a zero-day in WebDAV. Update Windows, Office, and more now to block active threats. First seen on hackread.com Jump to article: hackread.com/june-2025-patch-tuesday-microsoft-bugs-active-0-day/
-
Microsoft Security Update Summary (10. Juni 2025)
Microsoft hat am 10. Juni 2025 Sicherheitsupdates für Windows-Clients und -Server, für Office sowie für weitere Produkte veröffentlicht. Die Sicherheitsupdates beseitigen 65 Schwachstellen (CVEs), zwei davon wurden als 0-day klassifiziert. Eine Schwachstelle wurde bereits angegriffen. Nachfolgend findet sich … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/10/microsoft-security-update-summary-10-juni-2025/
-
Smarte Verteidigung für Zweigstellen: Check Point bringt neue Branch Office Firewalls mit KI
Diese neue Firewall-Generation ist optimiert für SD-WAN-Umgebungen und sorgt für eine reibungslose Nutzung von Cloud-Diensten und Anwendungen ein echtes Plus für Unternehmen mit verteilten Teams. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/smarte-verteidigung-fuer-zweigstellen-check-point-bringt-neue-branch-office-firewalls-mit-ki/a41093/
-
Organised Crime Gang Steals £47 Million from UK Tax Office in Phishing Scam
An organised crime gang has stolen £47 million ($64 million) from the UK’s tax office by hacking into over 100,000 customer accounts and fraudulently claiming government payments. His Majesty’s Revenue and Customs (HMRC) confirmed the breach but assured taxpayers that no individuals lost money. According to HMRC, criminals used stolen personal data, likely obtained through…
-
HHS Names New Director for HIPAA Enforcement Agency
Paula Stannard Has Deep HHS Regulatory and Legal Roots. The U.S. Department of Health and Human Services has named Paula Stannard to lead its HIPAA enforcement agency – the Office for Civil Rights. Stannard was a legal counsel at HHS under two previous Republican presidential administrations. She also has state and private sector legal experience.…
-
UK’s error-prone eVisa system is ‘anxiety-inducing’
Tags: officePeople experiencing technical errors with the Home Office’s electronic visa system explain the psychological toll of not being able to reliably prove their immigration status in the face of a hostile and unresponsive bureaucracy First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366625359/UKs-error-prone-eVisa-system-is-anxiety-inducing
-
U.S. Authorities Shut Down Major Dark Web Marketplace with 117,000 Users
In a blow to the cybercrime underworld, the U.S. Attorney’s Office for the Eastern District of Virginia announced the seizure of approximately 145 domains, spanning both darknet and traditional internet spaces, associated with the notorious BidenCash marketplace. This coordinated operation, executed with support from the U.S. Secret Service, FBI, Dutch National High Tech Crime Unit,…
-
Law enforcement seized the carding marketplace BidenCash
U.S. and Dutch authorities took down 145 domains tied to the BidenCash cybercrime marketplace in a coordinated law enforcement operation. The US DoJ announced the seizure of approximately 145 darknet and clear web domains, and cryptocurrency funds associated with the BidenCash marketplace. >>The U.S. Attorney’s Office for the Eastern District of Virginia announced today the…
-
Multiple High-Risk Vulnerabilities in Microsoft Products
According to the latest advisory by Cert-In, 78 vulnerabilities have been discovered across a broad range of Microsoft products, including Windows, Azure, MS Office, Developer Tools, Microsoft Apps, System Center, Dynamics, and even legacy products receiving Extended Security Updates (ESU). These flaws pose serious security threats, as they can be exploited by attackers to gain……
-
Germany doxxes Conti ransomware and TrickBot ring leader
The Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) claims that Stern, the leader of the Trickbot and Conti cybercrime gangs, is a 36-year-old Russian named Vitaly Nikolaevich Kovalev. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/germany-doxxes-conti-ransomware-and-trickbot-ring-leader/
-
US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator
The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major crypto losses through fraud infrastructure. The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Philippines-based company Funnull Technology Inc. and its admin Liu Lizhi for enabling romance scams, causing $200M in U.S. victim losses. A romance scam…

