2778 stories
·
0 followers

Microsoft Teams now lets admins block external bots from meetings

1 Share
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete

New malware targets Microsoft Teams users by posing as your company's IT helpdesk

1 Share
  • Expel researchers warn of SynkLoader backdoor spread via fake IT help desk Teams messages
  • Malware modules include PhishLocker (fake login screen harvesting OS passwords) and Interactive Shell for remote control
  • Defenses: distrust unsolicited Teams DMs, verify with IT before installing apps, and train staff against social engineering

For roughly a month now, cybercriminals have been targeting organizations with a new backdoor malware called SynkLoader.

According to security researchers Expel, the attack starts with social engineering. Victims would get a Microsoft Teams message from a person claiming to be from the company’s IT help desk. They would tell the victim their computer is having an issue, and that they need to install a “PowerShell Cleaner”. This fake program is nothing more than a malicious framework, hosted on Microsoft Azure to increase its trustworthiness.

The malware itself comes with a number of different modules, giving the attacker a range of features, from harvesting system information, to creating a reverse proxy. Two particularly worrying modules are called PhishLocker and Interactive Shell. The former creates a convincing, yet fake, Windows lock screen, which can harvest the user’s OS login password.

This is not SickKids' first attack

BleepingComputer argues that with this password the attackers could “access corporate environments from the infected device, bypassing IP allow-list restrictions”. Those with a sharper eye might spot the ruse, as a simple Alt + Tab shows that the login screen is nothing more than a “full-screen borderless GUI application”.

The other module - Interactive Shell, allows threat actors to remotely execute PowerShell commands and receive the output, which essentially grants them full control over the infected device.

The full list of Indicators of Compromise (IoC) can be found on this link. To defend against these types of attacks, target companies should instruct their employees not to trust unsolicited Teams messages at face value, and not to install any applications without double-checking (calling) with their IT department first.

Alongside phone calls, Microsoft Teams is one of the most-used channels for initial contact and compromise. Also, employees remain the weakest link in every company’s cybersecurity chain, unwillingly granting attackers access or sharing login credentials.

Via BleepingComputer



Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete

Iranian Cyberattack Shuts Down UK Power Generator

1 Share

A power plant was shut down for four days in July due to an Iranian-linked cyberattack



Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete

Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet

1 Share
  • Hackers exploited trusted software updates to deliver malware directly into car head units
  • Kaspersky says this is the first campaign tailored specifically for vehicle head units
  • The malware can run silently without showing drivers any visible interface

Car head units are now being drawn into a growing wave of Android malware campaigns built for connected vehicle systems, experts have warned.

A newly discovered malware campaign is infecting these head units directly, systems that combine multimedia functions with, in some models, vehicle control.

According to Kaspersky, this campaign marks the first documented case of malware built specifically for this type of infection chain.

Compromised update channels deliver malware straight into vehicles

Researchers believe the activity can likely be traced back to the MoYu Group, a threat actor closely tied to the well-known BadBox botnet, which spread through the legitimate update mechanisms built directly into the firmware of Android-based head units manufactured by DoFun.

The infection chain originates from TWCore, a legitimate system app that is normally responsible for collecting analytics and updating head unit software remotely.

Attackers hijacked this trusted update channel using a specialized dropper called JarService to deliver previously unknown malware directly onto a range of affected devices.

Once successfully installed, the malware operated quietly as a regular background application without ever displaying any visible user interface.

Kaspersky identified nine distinct remote commands built into the malware, capable of displaying unwanted ads and executing various forms of ad fraud.

The malware also actively collected sensitive device information, including display resolution, device model, Wi-Fi network identifier, and the device's MAC address.

Investigators found clear technical links between this campaign and prior attacks launched against TV set-top boxes tied to the same broader threat group.

The research team claims that the botnet's administration panel shares embedded URLs with residential proxy service websites PXYEDGE and ProxyForU.

BadBox itself operates as a large, sprawling network of hijacked Android devices, including streaming boxes, phones, and tablets that arrive pre-infected from the factory.

Kaspersky has already formally notified the vendor about this ongoing abuse of its legitimate software distribution channel and update infrastructure.

According to statements from DoFun, the underlying issue has since been resolved across most affected devices currently deployed in the field.

Head units present a growing and largely unprotected attack surface

Car head units can arrive factory-installed directly from the manufacturer or get added later to older vehicles as aftermarket upgrades.

Manufacturers frequently rely heavily on the Android operating system because it simplifies interface customization and essential system integration work considerably.

This widespread industry reliance means most standard Android applications, along with most existing Android malware, can potentially run on these devices.

Head units rarely store sensitive personal data directly on board, which on the surface might suggest only limited appeal to attackers.

However, they typically include active SIM card slots and maintain constant internet connectivity for navigation services and routine software updates.

That particular combination of persistent connectivity and comparatively weak security oversight makes these systems a genuinely attractive prospect for attackers going forward.

The overall scale of this particular campaign remains genuinely unclear, and whether other head unit manufacturers face similar exposure is not yet known.

Google logo on a black background next to text reading 'Click to follow TechRadar'



Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete

CISA Warns of Exploited Oracle WebLogic Vulnerability

1 Share

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

The post CISA Warns of Exploited Oracle WebLogic Vulnerability appeared first on SecurityWeek.

Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete

Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff

1 Share

AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.

The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek.

Read the whole story
NerdsToGo
16 hours ago
reply
Share this story
Delete
Next Page of Stories