EPISODE · Apr 11, 2025 · 44 MIN
Blumira Briefings, Ep. 3: Halo Fixes, NIST Changes, and Tax Phishing Prevention Tips!
from Blumira Briefings · host Blumira
🔔 Time for another edition of Blumira Briefings, bringing you the week’s headlines with the extra context you need! 🔔What We Cover This Week:📊 Top trending threats, risks, and suspects detected across our platform - including risky Azure sign-ins and Screen Connect anomalies💻 Halo ITSM vulnerability that allowed pre-auth SQL injection - and how quick vendor responses can demonstrate good security practices 📱 Android's critical April security update fixing over 60 flaws, including an 0day and plenty of privilege escalation bugs🔍 NIST's new "deferred" status for older vulnerabilities (and why legacy CVEs still matter)⚠️ Malicious VS Code extensions used in cryptomining campaigns - find out why attackers keep using this vector🎣 Tax-themed phishing campaigns deploying BruteRatel, Raccoon and AHKBot malware through sophisticated attack chainsPlus, Expert Insights On:How to evaluate vendor security incident responsesBYOD considerations for mobile device securityWhy old CVEs remain relevantMitigating the risks of developer tools like VS CodeHow threat actors leverage emotional current events like tax season for effective phishingDon't miss out on more practical advice for securing your organization -- hit subscribe for your weekly security download. 💪🔗 LINKS:CVE Trends Tool: https://intel.intruder.ioMSPGeek: https://mspgeek.org/ MSPs R Us: https://discord.com/invite/mspexchange📰 SOURCES:Halo ITSM Vulnerability: https://www.securityweek.com/halo-itsm-vulnerability-exposed-organizations-to-remote-hacking/Android Security Update: https://www.bleepingcomputer.com/news/security/google-fixes-android-zero-days-exploited-in-attacks-60-other-flaws/NIST Deferred Status: https://www.darkreading.com/vulnerabilities-threats/nist-deferred-status-dated-vulnerabilitiesVS Code Extensions Campaign: https://www.infosecurity-magazine.com/news/microsoft-vs-code-cryptojacking/Tax Season Phishing: https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/CHAPTERS0:00 - Introduction1:12 - Weekly Trends7:30 - Halo ITSM vulnerability13:30 - Android's critical April security update18:59 - NIST's new "deferred" status for older vulnerabilities26:15 - Malicious VS Code extensions32:31 - Tax-themed phishing campaigns44:15 - Outro
Embed this episode
What this episode covers
🔔 Time for another edition of Blumira Briefings, bringing you the week’s headlines with the extra context you need! 🔔 What We Cover This Week: 📊 Top trending threats, risks, and suspects detected across our platform - including risky Azure sign-ins and Screen Connect anomalies 💻 Halo ITSM vulnerability that allowed pre-auth SQL injection - and how quick vendor responses can demonstrate good security practices 📱 Android's critical April security update fixing over 60 flaws, including a...
NOW PLAYING
Blumira Briefings, Ep. 3: Halo Fixes, NIST Changes, and Tax Phishing Prevention Tips!
No transcript for this episode yet
Similar Episodes
No similar episodes found.