< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybersecurity Alert: Critical vulnerabilities found in Microsoft, SAP, and Visa systems

A series of critical cybersecurity vulnerabilities and sophisticated spyware campaigns have been identified. Researchers demonstrated that expired contactless Visa cards could be used for payments by manipulating NFC exchanges through man-in-the-middle attacks.

Major technology providers have reported high-severity flaws. Microsoft issued an alert for a CVSS 10.0 vulnerability in its Entra ID cloud service, noting that the flaw is being exploited. SAP Commerce Cloud also faces a critical vulnerability with a score of 10, which is seeing initial exploitation attempts. Additionally, Cisco has released security updates for its Crosswork and Secure Workload platforms to address several vulnerabilities, some reaching a CVSS score of 10.0.

Separately, Apple has been issuing notifications to users regarding potential compromises by sophisticated spyware such as Pegasus, Predator, and Graphite. These attacks target high-profile individuals, including journalists, lawyers, and politicians. Notifications indicate that at least one iCloud-linked device may have been targeted, though there is often a delay of several months between the compromise attempt and the alert.

Entities

Apple · Cisco · Microsoft · SAP · Visa