Application, API attack prevalence spikes
SiliconAngle reports that cyberattacks aimed at applications and application programming interfaces have increased by 137% in 2022, resulting in the highest number of attacks on record.
Stay updated with breaking news from Server Side Request Forgery. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
SiliconAngle reports that cyberattacks aimed at applications and application programming interfaces have increased by 137% in 2022, resulting in the highest number of attacks on record.
CISA’s Untitled Goose Tool aims to support network defenders with finding and detecting malicious activity in Microsoft Azure, Active Directory, and Microsoft 365 environments.
The vulnerable services include Azure API Management, Azure Functions, Azure Machine Learning, and Azure Digitals, according to a blog post Tuesday by Orca Security. Among them, two vulnerabilities involving Azure Functions and Azure Digital Twins did not require authentication, meaning that an attacker could exploit them even without an Azure account.
Two of the vulnerabilities — in Azure Functions and Azure Digital Twins — required no account authentication for an attacker to exploit them.
Microsoft updated the mitigation measures security teams should undertake for recently disclosed Exchange vulnerabilities that can lead to remote code execution after it was reported that previous measure can easily be bypassed.