-
Update Microsoft SharePoint ASAP | Kaspersky official blog
Attackers are actively exploiting vulnerabilities CVE-2025-53770 and CVE-2025-53771 to gain control of Microsoft SharePoint servers. Unknown malefactors are actively attacking companies that use SharePoint Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. By exploiting a chain of two vulnerabilities – CVE-2025-53770 (CVSS rating – 9.8) and CVE-2025-53771 (CVSS rating – 6.3), attackers are…
-
Securing Against Phishing Beyond Email
Phishing is no longer just an email problem. Reports state that 40% of phishing campaigns now span channels beyond email, hitting collaboration tools like Slack and Teams, plus SMS, and social media platforms. Voice phishing (“vishing”) in particular is on the rise: 30% of surveyed organizations reported at least one instance of attackers using spoofed…
-
Why Financial Websites Should Treat Web Application Firewalls Like Insurance
Most financial sites don’t think twice about WAFs until a bot army drains their API or a misstep leaks trading data. That’s when panic sets in and puts the target service in the eye of a perfect storm. That’s why WAFs aren’t optional anymore; they’re your digital insurance policy. This piece will break down real-world…
-
HR guidelines phishing email | Kaspersky official blog
A malicious actor employing spear-phishing techniques to mass-mail fake HR guidelines. We’ve been seeing attempts at using spear-phishing tricks on a mass scale for quite a while now. These efforts are typically limited to slightly better than usual email styling that mimics a specific company, faking a corporate sender via ghost spoofing, and personalizing the…
-
Aligning Software Security Practices with the EU CRA Requirements
As the European Cyber Resilience Act (CRA)’s enforcement date approaches (October 2026), cybersecurity requirements on manufacturers, developers, and service providers responsible for software and hardware connected to the internet will need to start thinking – if they haven’t already -about what they need to do to comply. It may seem like a long time off,…
-
OT Security in Ports: Lessons from the Coast Guard’s Latest Warning
The cranes that move goods in and out of America’s busiest ports (some of the most essential components of our national logistics chain) are under growing scrutiny. In a newly issued MARSEC Directive 105-5, the U.S. Coast Guard has raised red flags about the cybersecurity risks that come with ship-to-shore (STS) cranes manufactured in China.…
-
What is Wi-Fi sensing, and how does it detect human motion in the home? | Kaspersky official blog
All about Wi-Fi sensing: how it works, pluses, minuses, settings. Wi-Fi can be used to track people’s (and pets’) movements in the home — from the tiniest gestures, such as hand waves. This application of Wi-Fi is nothing new in theory, but only recently has it been put on a commercial footing. The technology is…
-
The hidden risks of browser extensions – and how to stay safe
Not all browser add-ons are handy helpers – some may contain far more than you have bargained for Not all browser add-ons are handy helpers – some may contain far more than you have bargained for Go to Source
-
SharePoint under fire: ToolShell attacks hit organizations worldwide
The ToolShell bugs are being exploited by cybercriminals and APT groups alike, with the US on the receiving end of 13 percent of all attacks The ToolShell bugs are being exploited by cybercriminals and APT groups alike, with the US on the receiving end of 13 percent of all attacks Go to Source
-
ToolShell: An all-you-can-eat buffet for threat actors
ESET Research has been monitoring attacks involving the recently discovered ToolShell zero-day vulnerabilities ESET Research has been monitoring attacks involving the recently discovered ToolShell zero-day vulnerabilities Go to Source