Microsoft Trusted Signing Service Abused to Code-sign Malware

Microsoft's Trusted Signing service is exploited by cybercriminals to code-sign malware using short-lived three-day certificates. These signed executables can bypass security filters. Criminals prefer this method due to easier access compared to Extended Validation certificates. Microsoft monitors and revokes misuse of their signing service, citing active threat intelligence measures.

https://www.bleepingcomputer.com/news/security/microsoft-trusted-signing-service-abused-to-code-sign-malware/

Arrests in Tap-to-Pay Scheme Powered by Phishing

Chinese nationals arrested for tap-to-pay fraud using mobile wallets linked to phishing scams. They bought gift cards with stolen credit card info, traveling across states. Authorities recovered over $23,000 in gift cards. Scammers utilize a custom Android app for transactions, leveraging stolen data acquired through sophisticated phishing techniques. This highlights vulnerabilities in mobile wallet security and the evolving tactics of cybercriminals.

https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/

Impact, Root Cause of GitHub Actions Supply Chain Hack Revealed

Recent details reveal the root cause and impact of the GitHub Actions supply chain hack. The attack compromised the ‘tj-actions/changed-files' action, affecting over 23,000 repositories, allowing attackers to execute a script that could leak CI/CD secrets. Initial investigations identified the compromise of the ‘reviewdog/action-setup' action as the root cause, which inadvertently provided an attacker access to a personal access token. The attack initially targeted Coinbase but expanded to a broader scope, potentially affecting about 160,000 dependencies. However, only 218 repositories leaked sensitive information, primarily short-lived tokens. GitHub confirmed no evidence of system compromise and encouraged users to review actions before usage.

https://www.securityweek.com/impact-root-cause-of-github-actions-supply-chain-hack-revealed/

FBI Warning For All iPhone, Android Users—Hang Up Now, Use This Code

FBI warns iPhone and Android users about AI-powered deepfake scams. Users should hang up on suspicious calls and create a secret code for verification with close family to combat voice cloning threats. Social media poses risks as it provides voice samples for cybercriminals. Ongoing AI attacks are reshaping crime, making scams increasingly sophisticated and difficult to detect.

https://www.forbes.com/sites/daveywinder/2025/03/22/fbi-warns-iphone-and-android-users-hang-up-now-use-this-code/

Cybersecurity in FinTech Applications: Protecting Financial Data and Preventing Fraud

Cybersecurity is crucial in the rapidly growing FinTech sector for safeguarding financial data and combating fraud. As FinTechs innovate, they face significant cybersecurity threats, evidenced by costly data breaches. This article by Vasilii Domnikov outlines solutions for enhancing security, including data encryption, multi-factor authentication, and strategies like tokenization and machine learning for fraud detection. It emphasizes the necessity for compliance with regulations and adapting to evolving cyber threats to maintain consumer trust and ensure operational integrity in financial services.

https://hackernoon.com/cybersecurity-in-fintech-applications-protecting-financial-data-and-preventing-fraud

Microsoft Isn’t Fixing 8-year-old Zero Day Used for Spying

Microsoft is ignoring an 8-year-old Windows exploit involving .LNK shortcut files used for surveillance, treating it as a low-priority issue despite its effectiveness in espionage. Trend Micro discovered the flaw, which allows attackers to hide malicious commands, affecting mainly state-sponsored actors from countries like North Korea and Russia. Microsoft claims it's a user-interface issue rather than a security threat, suggesting a possible fix in future updates but no immediate action.

https://www.theregister.com/2025/03/18/microsoft_trend_flaw/

GitHub Action Supply Chain Attack: Reviewdog/action-setup

GitHub Action supply chain attack: reviewdog/action-setup detected. Attack compromised tj-actions/changed-files, leaking secrets. Wiz Research links attack to reviewdog/action-setup@v1, suggesting ongoing risks. Compromised Personal Access Token allowed modifications. Secrets visible in CI logs; public repositories exposed secrets, while private ones potentially retained internal risks. Immediate action recommended: stop using affected actions, rotate leaked secrets, and audit workflows. Use specific commit hashes for security. Wiz offers detection tools for compromised actions and incident monitoring.

https://www.wiz.io/blog/new-github-action-supply-chain-attack-reviewdog-action-setup

Google Owner Alphabet to Buy Cybersecurity Startup Wiz for $32B

Google's parent company, Alphabet, plans to acquire cybersecurity startup Wiz for $32 billion, marking its largest acquisition. This move is part of Google's strategy to boost its cloud computing capabilities amid rising competition from Microsoft and Amazon. If approved by regulators, Wiz will enhance Google Cloud's security tools, which are crucial for handling increasing demand for AI-driven data centers. Despite the deal's potential benefits, concerns about antitrust implications loom, with the acquisition expected to face scrutiny before its anticipated closure in 2026.

https://apnews.com/article/google-alphabet-wiz-32-billion-e50fb41b9a84a1056a116f963e6efed0

BitM Up! Session Stealing in Seconds Using the Browser-in-the-Middle Technique

TLDR: BitM attacks rapidly compromise web application sessions, bypassing MFA through social engineering. Adversaries target session tokens via tools like Evilginx2. Mandiant's Delusion tool enhances BitM efficiency, enabling session stealing with minimal prior knowledge of target authentication methods. Strong defenses, including hardware-based MFA and client certificates, are crucial to thwarting such threats. Organizations should adopt layered security measures to protect sensitive data from BitM exploits.

https://cloud.google.com/blog/topics/threat-intelligence/session-stealing-browser-in-the-middle/

GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 Repositories

GitHub Action tj-actions/changed-files was compromised, exposing CI/CD secrets in over 23,000 repositories. Attackers altered its code, allowing sensitive information such as AWS keys and GitHub PATs to be printed in build logs. The incident, assigned CVE-2025-30066 (CVSS 8.6), highlights supply chain risks in CI/CD environments. Users should update to the latest version (46.0.1) and review workflows from March 14-15 for any unexpected outputs. GitHub has revoked the compromised PAT and implemented stricter access controls to prevent future attacks.

https://thehackernews.com/2025/03/github-action-compromise-puts-cicd.html

Jailbreaking Is (mostly) Simpler Than You Think

Microsoft's blog discusses a straightforward jailbreak method, Context Compliance Attack (CCA), effective against many AI systems. CCA manipulates AI by exploiting reliance on client-supplied conversation history, allowing for context manipulation with minimal effort. Models maintaining conversation state, like Copilot and ChatGPT, are safe from this attack. Microsoft suggests enhancements like cryptographic signatures and server-side history to bolster AI safety. The implications of CCA stress the need for comprehensive security considerations in AI system designs, encouraging discussions on further mitigation strategies.

https://msrc.microsoft.com/blog/2025/03/jailbreaking-is-mostly-simpler-than-you-think/

Remote Access Infra Remains Riskiest Corp. Attack Surface

Remote access infrastructure poses significant risks for corporations, with exposed login panels for VPNs and remote access systems increasing vulnerability to ransomware attacks. Analysis shows many companies have poorly secured login credentials, often leading to data breaches and making it harder to obtain cyber insurance. Recommendations for securing remote access include keeping network equipment updated, implementing strong multifactor authentication (MFA), and adopting a zero-trust security model.

https://www.darkreading.com/cyber-risk/remote-access-infra-remains-riskiest-corp-attack-surface

You Have 7 Days To Act Following Gmail Lockout Hack Attacks, Google Says

Google warns Gmail users to act within 7 days if locked out due to hacks. Quick recovery is essential, especially after an attacker changes login credentials. Users should ensure a recovery phone number and email are linked to their accounts for regaining access. Google advises implementing stronger security measures like two-factor authentication (2FA) to prevent future breaches.

https://www.forbes.com/sites/daveywinder/2025/03/16/you-have-7-days-to-act-following-gmail-lockout-hack-attack-google-says/

Google’s ‘consent-less’ Android Tracking Probed by Academics

Google's Android tracking has been criticized by researchers for using identifiers to track users without consent. Research by Doug Leith from Trinity College Dublin highlights that data collection occurs before users open any apps, primarily through pre-installed services like Google Play. Key identifiers, such as the “DSID” cookie and Android ID, are created during the startup process and track users even after they log out, with no opt-out option available. Leith's findings suggest possible violations of data protection laws, which Google disputes, emphasizing a commitment to user privacy. Users have expressed frustration, especially regarding a recent system feature that scans images without consent.

https://www.theregister.com/2025/03/04/google_android/

Scroll to Top