Secure test accounts and avoiding password reuse are crucial to prevent hacking incidents.
Google's Pixel phones experienced a critical bug related to storage permission, raising questions about Google's control over the platform.
Deep dives
Microsoft and HPE Hacked Due to Test Account Negligence
Microsoft and HPE fell victim to hacking due to negligence surrounding test accounts. In Microsoft's case, a dormant test account with admin privileges was left vulnerable, leading to a breach. The individuals responsible for the mistake were likely no longer with the company, as turnover is common in large enterprises like Microsoft. HPE, on the other hand, was compromised by a password spray attack, which granted access to a test account. The attackers used distributed residential proxy infrastructure to reduce malicious activity detection. These incidents highlight the importance of secure test accounts and the need to avoid reusing passwords.
Pixel Phones Affected by Critical Bug
Google's Pixel phones were affected by a critical bug related to storage permission. The bug, which seems to be a reoccurring issue, caused problems for users, including being locked out of their phones. The bug is related to multiple profiles set up on Android devices. Google Play system updates were responsible for the bug this time. These updates, happening in the background without requiring a reboot, often carry core functionality of Android. This move has led to speculation about Google's intention to exert more control over the platform and the increased reliance on proprietary Google Play services.
Innovative Malware Campaign Exploits URL Encoding
A sophisticated malware campaign used innovative techniques involving URL encoding to hide malicious payloads. The campaign targeted high-value individuals and organizations. The attack consisted of multiple stages, beginning with malware-loaded USB drives left in parking lots. On infected systems, the malware fetched a URL from a seemingly harmless image URL, which included base64-encoded HTTP GET variables. These variables contained instructions for fetching the actual malicious payload. The campaign showcased the growing complexity and evasive techniques employed by advanced threat actors.
Consider Upgrading Hardware Ahead of Windows 10 End Date
Windows 10 users should consider upgrading their hardware ahead of its end date in October 2025. While the prices may not skyrocket in the final months, it's advisable to plan and upgrade in advance. The performance gains of newer processors, even lower-tier ones, can significantly outperform older sixth or seventh generation CPUs. Waiting until closer to the end date may result in a rush for certain hardware, such as refurbished corporate machines. Therefore, upgrading now can ensure a smoother transition and maximize the benefits of improved hardware performance.
Microsoft’s rudimentary error that allowed an attacker access to its executives’ emails, Pixel phones have another serious storage bug, hidden malware payload found at Ars Technica, and when to upgrade your hardware for Windows 11.