Vectra: Microsoft Teams stores authentication tokens in unencrypted plaintext mode; Microsoft has no plans for a fix, since an exploit requires network access (Steve Dent/Engadget)

Steve Dent / Engadget:
Vectra: Microsoft Teams stores authentication tokens in unencrypted plaintext mode; Microsoft has no plans for a fix, since an exploit requires network access  —  Microsoft downplayed the flaw saying it ‘does not meet our bar for immediate servicing.’  —  Microsoft Teams stores authentication tokens …

Related Articles

Anker admits its eufy security cameras’ live view feature on its web portal “has a security flaw”, but fails to address why anyone can view unencrypted streams (Sean Hollister/The Verge)

Sean Hollister / The Verge:
Anker admits its eufy security cameras’ live view feature on its web portal “has a security flaw”, but fails to address why anyone can view unencrypted streams  —  On the last episode of “Will Anker ever tell us what’s actually going on with its security cameras rather than lying …

Google’s Project Zero reported five security flaws in devices with Mali GPUs in the summer, but Samsung, Xiaomi, Google, and others are yet to release patches (Kris Holt/Engadget)

Kris Holt / Engadget:
Google’s Project Zero reported five security flaws in devices with Mali GPUs in the summer, but Samsung, Xiaomi, Google, and others are yet to release patches  —  Google has disclosed several security flaws for phones that have Mali GPUs, such as those with Exynos chipsets.

Sony reports Q2 gaming revenue rose 12% YoY to $4.92B and ships 3.3M PS5 units, flat YoY, bringing total sales to 25M; software sales fell to 62.5M units (Steve Dent/Engadget)

Steve Dent / Engadget:
Sony reports Q2 gaming revenue rose 12% YoY to $4.92B and ships 3.3M PS5 units, flat YoY, bringing total sales to 25M; software sales fell to 62.5M units  —  In its latest earnings drop, Sony said it sold 3.3 million PlayStation 5s this quarter, matching exactly what it did last year …

The FBI and CISA say an Iranian-backed threat group hacked a US Federal Civilian Executive Branch and deployed XMRig cryptomining malware via the Log4Shell flaw (Sergiu Gatlan/BleepingComputer)

Sergiu Gatlan / BleepingComputer:
The FBI and CISA say an Iranian-backed threat group hacked a US Federal Civilian Executive Branch and deployed XMRig cryptomining malware via the Log4Shell flaw  —  The FBI and CISA revealed in a joint advisory published today that an unnamed Iranian-backed threat group hacked …