New ‘ALBeast’ Vulnerability Exposes Weakness in AWS Application Load Balancer

August 22, 2024 at 11:18AM Israeli cybersecurity company Miggo has discovered a vulnerability named “ALBeast” impacting up to 15,000 Amazon Web Services’ (AWS) Application Load Balancer (ALB) users. The issue allows attackers to bypass authentication controls, potentially compromising exposed cloud applications. Amazon has updated its authentication documentation and recommends implementing additional security measures to mitigate … Read more

Disney, Nike, IBM Signatures Anchor 3M Fake Emails a Day

August 2, 2024 at 11:46AM The EchoSpoofing campaign sent millions of fake emails, exploiting a vulnerability in Proofpoint’s email protection service and Microsoft 365. By using a misconfiguration flaw, the attackers impersonated blue chip companies like Disney and Coca-Cola, exploiting the trust between Microsoft 365 and Proofpoint to send fraudulent emails. Proofpoint implemented a fix, … Read more

20 Million Trusted Domains Vulnerable to Email Hosting Exploits

July 18, 2024 at 02:23PM Three novel attack techniques chaining vulnerabilities found in email-hosting platforms allow spoofing of emails from over 20 million trusted organization domains. Researchers at PayPal discovered flaws that bypass SPF, DKIM, and DMARC protocols, affecting large email service providers. They plan to disclose these vulnerabilities in an upcoming conference. The attacks … Read more