Tech

Exchange/Outlook autodiscover bug exposed 100,000+ email passwords

Enlarge / If you own the right domain, you can intercept hundreds of thousands of innocent third parties’ email credentials, just by operating a standard webserver. (credit: Guardicore) Security researcher Amit Serper of Guardicore discovered a severe flaw in Microsoft’s autodiscover—the protocol which allows automagical configuration of an email account with only the address and […]

Tech

Microsoft Outlook shows real person’s contact info for IDN phishing emails

Enlarge (credit: Drew Angerer | Getty Images ) If you receive an email from someone@arstechnіca. com , is it really from someone at Ars? Most definitely not—the domain in that email address will be not the same arstechnica. com that you know. The ‘і’ character in there is usually from the Cyrillic script and not […]