Multiple Document Management XSS Flaw Let Attackers Access Sensitive Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Rapid7 uncovered a number of vulnerabilities with on-premises installations of open-source and freemium Document Management System (DMS) services from four different vendors: LogicalDOC, Mayan, ONLYOFFICE, and OpenKM. The eight vulnerabilities, …

Hackers Increasingly Use Microsoft OneNote to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OneNote documents are increasingly being used by threat actors to send malware to unsuspecting end users via email, according to Proofpoint researchers. It infects victims with remote access malware that can …

Hackers Backdoor Windows Device Using Cobalt Strike Alternative ‘Sliver’

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Using Sunlogin flaws, a new hacking campaign has been detected by security analysts at AhnLab Security Emergency Response Center (ASEC) that takes advantage of Windows BYOVD attacks to disable security …

EV Charge Points Hijack – Multiple Vulnerabilities Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, two new security weaknesses have been discovered in several electric vehicle (EV) charging systems. These weaknesses have raised concerns as they could be exploited by malicious actors to remotely …

PixPirate Android Malware Stealing Banking Passwords From Browsers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the introduction of Pix, an instant payment platform developed and managed by the monetary authority of Brazil, the Central Bank of Brazil (BCB), which enables the quick execution of payments and …

Hackers Use Google Ads to Install Malware that Evades Antivirus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cluster of virtualized.NET malware loaders that were disseminated via malvertising attacks was discovered by SentinelLabs. The loaders, known as MalVirt, leverage the Windows Process Explorer driver for process termination …