Abusing
-
Blog
Carding tool abusing WooCommerce API downloaded 34K times on PyPI
A newly discovered malicious PyPi package named ‘disgrasya’ that abuses legitimate WooCommerce stores for validating stolen credit cards has been downloaded over 34,000 times from the open-source package platform. The script specifically targeted WooCommerce stores using the CyberSource payment gateway to validate cards, which is a key step for carding actors who need to evaluate thousands of stolen cards from dark web dumps…
Read More » -
Blog
Microsoft files suit against threat actors abusing AI services
Microsoft has filed a lawsuit against 10 foreign threat actors, accusing the group of stealing API keys for its Azure OpenAI service and using it to run a hacking as a service operation. According to the complaint, filed in December 2024, Microsoft discovered the customer API keys were being used to generate illicit content in late July that year. After…
Read More » -
Blog
Microsoft Exchange adds warning to emails abusing spoofing flaw
Microsoft has disclosed a high-severity Exchange Server vulnerability that allows attackers to forge legitimate senders on incoming emails and make malicious messages a lot more effective. The security flaw (CVE-2024-49040) impacts Exchange Server 2016 and 2019, and was discovered by Solidlab security researcher Vsevolod Kokorin, who reported it to Microsoft earlier this year. “The problem is that SMTP servers parse…
Read More » -
Blog
Google Abusing Dominant Position in Ad Tech Sector, Says U.K. Government
The U.K.’s Competition and Markets Authority has provisionally ruled that Google’s dominance in the ad tech market is detrimental to competitors — and could fine the tech giant up to 10% of its global annual turnover as a result. Since at least 2015, the company has allegedly been operating its tools for ad space buyers and sellers, such as Google…
Read More »