Companies in Germany are facing a new wave of cyberattacks. The State Criminal Police Office of North Rhine-Westphalia has issued a warning. Cybercriminals are targeting Microsoft 365, particularly email and document management, as a way to launch their attacks.
“Unknown perpetrators take over email accounts and then send messages on behalf of the affected companies. These emails contain dangerous attachments or links. The emails look genuine because they do not contain any language errors, but often contain real previous conversations. As soon as a recipient clicks on the links, the IT system can be immediately attacked and data loss or theft as well as other attacks, such as phishing attacks, can occur” the press release reads.
By infosecbulletin
/ Sunday , April 20 2025
You copy a password from your manager, thinking it's safe. Meanwhile, your phone is saving it in plain text. Samsung...
Read More
By infosecbulletin
/ Saturday , April 19 2025
A data leak involving 8 million UK healthcare worker records, including IDs and financial information, was caused by a misconfigured...
Read More
By infosecbulletin
/ Saturday , April 19 2025
GitHub has released security updates for GitHub Enterprise Server to fix several vulnerabilities, including a high-severity flaw that could allow...
Read More
By infosecbulletin
/ Friday , April 18 2025
Hackers can exploit a vulnerability in Asus routers to execute unauthorized functions. This serious issue, rated 9.2 out of 10,...
Read More
By infosecbulletin
/ Friday , April 18 2025
According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
By infosecbulletin
/ Friday , April 18 2025
A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
By infosecbulletin
/ Thursday , April 17 2025
Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
According to the press release “many companies are currently affected by cyber attacks on Office 365 (email and document management). These attacks also pose a risk to companies connected to the corporate network as well as to their customers and communication partners.”
The police say that cybercriminals often update their dangerous attachments, which may not always be detected by existing virus scanners. The press release does not specify the techniques or procedures used by hackers or provide detailed countermeasures.
Microsoft has updated its guidelines on how users can identify if their email account has been hacked and what they should do about it. Signs of a compromised account may include frequent password changes, missing or deleted emails, unexpected email forwarding, and inability to send emails.
Source: Press release of the State Criminal Police Office of North Rhine-Westphalia (LKA NRW), Cybernews