Cyber criminals Exploit DocuSign API for Mass Distribution of Fake Invoices

In an alarming trend, cyber criminals have found new ways to exploit the DocuSign API to deliver fraudulent invoices that appear authentic. Unlike conventional phishing attacks that rely on suspicious-looking emails or malicious links, these schemes leverage legitimate DocuSign accounts and official templates, allowing cyber criminals to send fake invoices that users and security systems […]
Android zero-day vulnerabilities were used in targeted attacks – now fixed by Google

In the current threat landscape, mobile devices have become prime targets for cyber criminals, with a particular focus on Android vulnerabilities. Given Google’s recent security update addressing two critical Android zero-day vulnerabilities, businesses are advised to ensure that both personal and work-related Android devices used by employees are regularly backed up and updated. Implementing these […]
Outsourcing Your IT Support and Services

For small and medium-sized businesses, outsourcing IT support to a Managed Services Provider (MSP) like Neuways delivers enterprise-level benefits at a fraction of the cost of an in-house IT team. So, why partner with a trusted MSP like Neuways? Here’s what we bring to the table: The Benefits of Managed IT Support with Neuways Cost […]
Google: 70% of exploited flaws disclosed in 2023 were zero-days

In 2023, Google Mandiant reported a sharp rise in cybercriminals being able to exploit zero-day vulnerabilities, underscoring a significant shift in threat actor capabilities. According to Mandiant and Bleeping Computer, 70% of the 138 actively exploited vulnerabilities this year were zero-day flaws, meaning they were exploited before vendors could patch them. This trend demonstrates an […]
Beyond Out-of-the-Box: Safeguarding Microsoft’s Ecosystem

Imagine you’re setting up a new office. You want software that can get your team up and running quickly, with tools everyone knows how to use, a platform that “just works.” Enter Microsoft—Outlook for email, SharePoint for sharing files, Teams for communication, and Microsoft 365 to tie it all together in one neat package. It’s […]
Social Engineering Methods Continue to Evolve!

Cyber security experts have uncovered a concerning trend in Black Basta’s social engineering methods and tactics in an alarming new investigation. The cyber criminal gang leverages Microsoft Teams and malicious QR codes to penetrate systems with highly targeted social engineering techniques. Here’s an in-depth look at their evolving strategies and how your organisation can defend […]
Boost Your Security Posture with Objective-Based Penetration Testing

Organisations need confidence that their defences effectively maximise the value of security investments. But how can you prove this to customers, partners, and regulators? We break down the Neuways Cyber Security services, which allow us to protect your businesses from cyber threats. Objective-based penetration testing, or “pen testing,” is a crucial tool that reveals vulnerabilities […]
Unknown Threat Actors Exploit Roundcube Webmail Vulnerability in Phishing Campaign

Cyber criminals continue to find new ways to exploit vulnerabilities in commonly used software. Recently, a flaw in Roundcube Webmail (CVE-2024-37383) was leveraged in a phishing campaign, potentially compromising user credentials. Though the email vulnerability has been patched, the attack serves as a reminder of the importance of timely updates and proactive cyber security measures. […]
Gryphon Healthcare and Tri-City Medical Center Disclose Significant Data Breaches Affecting Over 500,000 Individuals

Two major healthcare organisations, Gryphon Healthcare and Tri-City Medical Centre, recently revealed significant data breaches, collectively affecting more than 500,000 individuals. These breaches highlight the ongoing risks to sensitive patient data and the critical need for robust cyber security measures within the healthcare industry, where cyber criminals often target personal and medical information. Gryphon Healthcare’s […]
Global threat to businesses as a foreign intelligence cyber campaign exploits established vulnerabilities

Businesses are being called to bolster their cyber defences and follow the latest guidance issued by the UK’s National Cyber Security Centre (NCSC) and US agencies. This urgent advisory addresses a cyber campaign exploiting established software vulnerabilities. In the article below, we advise what the vulnerabilities are and explain in detail about how patch management […]