+ Microsoft issues patches for "ToolShell" vulnerable SharePoint Servers; Threat actors found distributing malware via DNS; and more
Can't view this message? Click here to view it online.
iTnews

WEEKLY SECURITY WRAP

Tuesday July 22, 2025

  Security  

"PoisonSeed" attack does not bypass hardware MFA

Confirmed as an MFA downgrade attack.

By Juha Saarinen

 

Latest Security News


Microsoft issues patches for "ToolShell" vulnerable SharePoint Servers
  Security  

Microsoft issues patches for "ToolShell" vulnerable SharePoint Servers

For versions 2019 and subscription only.

By Juha Saarinen

 
Threat actors found distributing malware via DNS
  Security  

Threat actors found distributing malware via DNS

Check those TXT records.

By Juha Saarinen

 
Qantas obtains court order to prevent third-party access to stolen data
  Security  

Qantas obtains court order to prevent third-party access to stolen data

Following data breach.

By Staff Writer

 
AI models with systemic risks given pointers on how to comply with EU AI rules
  Security  

AI models with systemic risks given pointers on how to comply with EU AI rules

Law will apply to these models from August 2.

By Foo Yun Chee

 
 
 
 
US National Guard unit 'extensively' hacked by Salt Typhoon in 2024
  Security  

US National Guard unit 'extensively' hacked by Salt Typhoon in 2024

According to Department of Homeland Security memo.

By Staff Writer

 
Hong Kong investigates Louis Vuitton data leak affecting 419,000 customers
  Security  

Hong Kong investigates Louis Vuitton data leak affecting 419,000 customers

Leaked information includes names and passport details.

By Staff Writer

 
Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage
  Networking  

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

It was BGP but not a route hijack.

By Juha Saarinen

 
NoName057(16) cybercrime group targeted in global operation
  Security  

NoName057(16) cybercrime group targeted in global operation

Accused of DDoS attacks on critical infrastructure and companies.

By Giulia Segreti and Thomas Escritt

 
Google's Big Sleep security AI agent foils bug exploitation
  Security  

Google's Big Sleep security AI agent foils bug exploitation

AI applied in more vulnerability detection scenarios.

By Juha Saarinen

 
Ex-intelligence officer jailed for stealing bitcoin from Silk Road 2.0 operator
  Security  

Ex-intelligence officer jailed for stealing bitcoin from Silk Road 2.0 operator

Gets five-and-a-half years.

By Staff Writer

 
 
 
 

Featured whitepaper


 
 

MOST POPULAR


Qantas obtains court order to prevent third-party access to stolen data
  Security  

Qantas obtains court order to prevent third-party access to stolen data

By Staff Writer

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage
  Networking  

Cloudflare makes changes to avoid repeat of 1.1.1.1 DNS outage

By Juha Saarinen

CBA using facial recognition logins to verify disputed payments
  Financial Services  

CBA using facial recognition logins to verify disputed payments

By Ry Crozier

ACSC alerts to exploited MS SharePoint remote code execution flaw
  Security  

ACSC alerts to exploited MS SharePoint remote code execution flaw

By Juha Saarinen

Researchers demo AI-crippling GPUHammer attack
  Security  

Researchers demo AI-crippling GPUHammer attack

By Juha Saarinen

 
 
unsubscribe