🔓 VULNERABILITIES & CVEs
- Zoom warns of critical account takeover vulnerability — BleepingComputer
Zoom disclosed a critical vulnerability in its Windows desktop client and SDK that allows unauthenticated attackers to hijack user accounts. Immediate patching is advised to prevent active exploitation. No CVE ID published yet, but this impacts all Windows Zoom desktop versions prior to the forthcoming update.
🕵️ THREAT RESEARCH & DEEP DIVES
- Security researchers find stalkers abusing Chrome’s sync feature — CyberScoop
Researchers at Certo Software reveal that Google Chrome’s sync feature, intended for user convenience, is being exploited by stalkers to monitor victims’ online activity covertly. This abuse highlights a novel privacy risk vector that defenders should monitor, especially in environments with sensitive user data.
📰 LESSER-KNOWN / UNDER-REPORTED
- Identity Attacks Overtake Exploits as Top Ransomware Cause — Dark Reading
Email-based identity attacks surpassed software exploits as the leading root cause of ransomware incidents last year. Alarmingly, MFA was present in 97% of these credential-based compromises but failed to stop attackers, signaling a need for enhanced identity security controls beyond MFA.