Follina Exploited by State-Sponsored Hackers
A government-aligned attacker tried using a Microsoft vulnerability to attack U.S. and E.U. government targets.
Stay updated with breaking news from Microsoft Security Response. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
A government-aligned attacker tried using a Microsoft vulnerability to attack U.S. and E.U. government targets.
Threat actors already are exploiting vulnerability, dubbed ‘Follina’ and originally identified back in April, to target organizations in Russia and Tibet, researchers said.
While Microsoft may be quick to point out security vulnerabilities in other companies' products, its own software is far from infallible. A good example of this is the recently discovered 'Follina' security hole that affects Microsoft Office.
Threat actors could gain access to a user’s account by leveraging a new type of technique that involves pre-hijacking an account before it’s actually registered by the victim.
Microsoft will now offer higher rewards for high-impact flaws found in Microsoft 365, Dynamics 365 and Power Platform.