Cyber Threat Alert: Hackers Exploiting SimpleHelp RMM Vulnerabilities

Cyber criminals exploit recently patched vulnerabilities in SimpleHelp Remote Monitoring and Management (RMM) software to gain initial network access. These flaws, CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, allow attackers to upload and download files on compromised devices and escalate privileges to administrative levels. Ongoing Attacks Targeting SimpleHelp Servers Research from Arctic Wolf indicates an ongoing campaign targeting […]
WhatsApp accounts compromised by Cyber Criminals

WhatsApp accounts compromised by Cyber Criminals: The latest Whatsapp Phishing attack highlights the growing sophistication of phishing campaigns, particularly those targeting organisations with a high volume of sensitive data or a role in international affairs. Star Blizzard’s WhatsApp phishing tactic demonstrates technical ingenuity and a deep understanding of human behaviour, exploiting trust in familiar platforms […]
7 Types of Social Engineering Attacks: Insights for Businesses

In the wake of cyber attacks targeting casino giants MGM and Caesars, social engineering remains one of the most effective techniques cyber criminals employ. In these incidents, threat actors used a phone-based impersonation tactic, known as vishing, to manipulate an outsourced IT help desk into providing critical access, which paved the way for ransomware attacks […]
Blue Yonder Ransomware Attack Demonstrates the Vital Role of Cyber Resilience and Business Continuity

The recent ransomware attack targeting Blue Yonder, a global supply chain management software provider, has sent ripples across the industries that rely on its platform, including retail and logistics. Starbucks, one of the affected companies, confirmed that the attack disrupted its scheduling and time-tracking systems. While the company has reverted to manual processes to ensure […]
Why You Should Use Multi-Factor Authentication on VPNs

As a cyber security provider, we urge organisations to immediately protect themselves from SafePay, a newly identified ransomware operator with advanced capabilities. SafePay has been actively targeting organisations across industries, exploiting weaknesses in VPNs to infiltrate networks and deploy ransomware at alarming speed. It is so important that your business is able to protect its […]
Cyber criminals Exploit DocuSign API for Mass Distribution of Fake Invoices

In an alarming trend, cyber criminals have found new ways to exploit the DocuSign API to deliver fraudulent invoices that appear authentic. Unlike conventional phishing attacks that rely on suspicious-looking emails or malicious links, these schemes leverage legitimate DocuSign accounts and official templates, allowing cyber criminals to send fake invoices that users and security systems […]
Beyond Out-of-the-Box: Safeguarding Microsoft’s Ecosystem

Imagine you’re setting up a new office. You want software that can get your team up and running quickly, with tools everyone knows how to use, a platform that “just works.” Enter Microsoft—Outlook for email, SharePoint for sharing files, Teams for communication, and Microsoft 365 to tie it all together in one neat package. It’s […]
Social Engineering Methods Continue to Evolve!

Cyber security experts have uncovered a concerning trend in Black Basta’s social engineering methods and tactics in an alarming new investigation. The cyber criminal gang leverages Microsoft Teams and malicious QR codes to penetrate systems with highly targeted social engineering techniques. Here’s an in-depth look at their evolving strategies and how your organisation can defend […]
Unknown Threat Actors Exploit Roundcube Webmail Vulnerability in Phishing Campaign

Cyber criminals continue to find new ways to exploit vulnerabilities in commonly used software. Recently, a flaw in Roundcube Webmail (CVE-2024-37383) was leveraged in a phishing campaign, potentially compromising user credentials. Though the email vulnerability has been patched, the attack serves as a reminder of the importance of timely updates and proactive cyber security measures. […]
Global threat to businesses as a foreign intelligence cyber campaign exploits established vulnerabilities

Businesses are being called to bolster their cyber defences and follow the latest guidance issued by the UK’s National Cyber Security Centre (NCSC) and US agencies. This urgent advisory addresses a cyber campaign exploiting established software vulnerabilities. In the article below, we advise what the vulnerabilities are and explain in detail about how patch management […]