Microsoft Teams 上的虚假 IT 支持电话推送 EtherRAT 恶意软件
威胁行为者正在滥用 Microsoft Teams 语音通话,冒充企业 IT 支持人员,诱骗员工安装 EtherRAT 恶意软件,从而让攻击者获得对企业网络的初始访问权限。据 Palo Alto Networks 的 Unit 42 报告,该活动结合了钓鱼邮件、Microsoft Teams 语音通话、合法的远程管理工具以及一个基于 Node.js 的恶意软件加载器,以入侵受害者的计算机。根据 U...
A critical security flaw has been discovered in the fast-mcp-telegram package that could allow remote attackers to access sensitive Telegram session data and perform unauthorized actions. The vulnerability, tracked as CVE-2026-52830 , affects all versions up to 0.19.0 and has been fixed in version 0.19.1. The issue stems from improper validation of HTTP Bearer tokens used for […]
The post Fast-mcp-telegram Vulnerability Allow Attackers to Access Sensitive Files appeared first on Cyber Security News.