Hackers Abuse DocuSign API to Send Genuine Looking Invoices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have started leveraging DocuSign’s API to send fraudulent invoices that appear shockingly authentic. Unlike traditional phishing schemes that rely on poorly crafted emails and malicious links, these attacks use …

Multiple Vulnerabilities in HPE Aruba Access Points Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities have been identified in HPE Aruba Access Points, potentially allowing attackers to execute remote code and compromise systems. These vulnerabilities affect both Instant AOS-8 and AOS-10, with …

North Korean Hackers Employing New Tactic To Acquire Remote Jobs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers increasingly target remote workers by exploiting vulnerabilities arising from the shift to telecommuting. They use tactics like “voice phishing” (vishing) to gain access to corporate networks. They impersonate IT …

HookBot Malware’s Overlay Attacks To Impersonate As Popular Brands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Overlay attacks involve placing a tricky layer over legitimate applications on mobile devices like Android. This malicious overlay can mimic the interface of trusted apps, tricking users into entering sensitive …

Azure API Management Flaws Let Attackers Take Full Control APIM Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Binary Security have uncovered critical vulnerabilities in Microsoft’s Azure API Management (APIM) service that could allow attackers with basic Reader permissions to gain complete administrative control of …

CRON#TRAP Campaign Attacking Windows Machine With Weaponized Linux VMs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Weaponized Linux virtual machines are used for offensive cybersecurity purposes like “penetration testing” or “exploiting vulnerabilities.” These setups often use the tools and frameworks that are designed for ethical hacking. …

INTERPOL Takes Down 22,000 malicious IP addresses Used for Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

INTERPOL has dismantled over 22,000 malicious IP addresses and servers linked to various cyber threats. This operation, code-named Synergia II, ran from April 1 to August 31, 2024, and was a collaborative …