|
NEW RESOURCES Cornell Chronicle: ‘Wall-to-wall' map of NYC trees could help cool cities worldwide. "Researchers have created an interactive map identifying 1.8 million individual trees in New York City, with a new […]
| RELATED ARTICLES | | |
|
NEW RESOURCES Dartmouth College: New Website Investigates Eugenics in 20th-Century U.S.. "An innovative new website, Eugenic States: A Contextual Archive, uses digital storytelling to preserve and illuminate a disturbing and largely unknown […]
| RELATED ARTICLES | | |
|
NEW RESOURCES Azernews: National Library launches e-database in honor of Khagani Shirvani. "An electronic information database dedicated to prominent Azerbaijani poet Afzaladdin Khagani Shirvani has been presented to users at the Azerbaijan […]
|
|
AI PROBLEMS Reuters: Amazon, Walmart AI detect ‘made in USA' fraud but do not flag it, study says. "Amazon and Walmart AI shopping assistants can often detect ?when "Made in USA" product […]
| RELATED ARTICLES | | |
|
Traveling enterprise employees beware: Think twice before you log onto that oh-so-convenient public Wi-Fi.
Since at least June, threat actors have been compromising "captive" Wi-Fi gateways and other portal appliances at hotels, conference centers, and similar shared venues to hijack users' Microsoft 365 accounts, according to the ReliaQuest Threat Research team.
Once a threat actor controls a gateway, they can silently redirect a user's traffic to their own infrastructure and steal their Microsoft 365 credentials without ever touching the user's device, compromising endpoints, or sending phishing links or malicious attachments.
"The most dangerous element is that it operates at the network gateway, which sits beneath most of the trust assumptions users and devices make," ReliaQuest told CSO Online. "It's not necessarily an enterprise breach level event on its own, but it's a very real risk to individual accounts."
Exploiting a ‘fundamental trust'
Domain Name System (DNS) poisoning, in which false data is injected to redirect regular web traffic to fraudulent domains, has previously been observed on small office routers, but attackers are now expanding the technique to higher-level targets, the ReliaQuest researchers explained in a blog post.
Attackers l
|
|