
Recent cybersecurity incidents have raised alarms regarding vulnerabilities in Microsoft’s multi-factor authentication (MFA) and a significant supply-chain attack. Researchers have identified a critical flaw in Microsoft’s MFA system, referred to as 'AuthQuake,' which allows attackers to bypass the security feature by guessing six-digit codes. This vulnerability potentially affects 400 million Microsoft users. Concurrently, a yearlong supply-chain attack has compromised over 390,000 WordPress credentials, targeting both malicious and benevolent security personnel. The attack was facilitated through a malicious GitHub repository that masqueraded as a benign publishing tool. Additionally, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities in Cleo file transfer tools to its Known Exploited Vulnerabilities catalog, highlighting the risks posed by unpatched systems. These developments underscore ongoing challenges in cybersecurity, with experts warning of the potential for increased exploitation of these vulnerabilities.



Unpatched vulnerabilities are not just risks — they’re magnets for #ransomware, exposing organizations to more severe outcomes and longer recovery times, according to @Sophos. #cybersecurity #infosec #ITsecurity https://t.co/xYgl6gfSWz
By me @Forbes: If you don't mind using Chrome Canary on your Android, this is long overdue IMNHO. #infosec https://t.co/NHeehVNTEi
For the last few days we are scanning & sharing IPs of Cleo Harmony/VLTrader/LexiCom CVE-2024-50623/CVE-2024-55956 vulnerable file transfer instances. These RCE vulnerabilities are being exploited in the wild. We see around 930 vulnerable in our daily scans. Majority in US. https://t.co/VLBTO8ILR8