HOLLOWGRAPH MALWARE HIJACKS MICROSOFT 365 FOR C2
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
A newly discovered malware component called HollowGraph exploits Microsoft 365 calendar features to communicate with attackers. The malware uses compromised mailboxes as a covert command-and-control channel.
■ MORE FROM THE SECURITY DESK
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect to breach corporate networks. Arctic Wolf disclosed the active exploitation campaign.
Meta's Ray-Ban smartglasses can record video without obvious indicators, raising child safety concerns. The company places responsibility on users to avoid 'actively exploiting' the technology rather than implementing technical safeguards.
Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.
The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.