Security News

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
2025-01-02 12:53

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure. The flaws, discovered by Melbourne-based...

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
2024-12-31 05:42

The United States Treasury Department said it suffered a "major cybersecurity incident" that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents. ...

API security blind spots put businesses at risk
2024-12-24 04:00

Many customer-facing APIs remain unprotected, leaving businesses vulnerable to breaches. To address these threats, a comprehensive approach to API security, covering every stage of the lifecycle,...

Over 300K Prometheus Instances Exposed: Credentials and API Keys Leaking Online
2024-12-12 14:24

Cybersecurity researchers are warning that thousands of servers hosting the Prometheus monitoring and alerting toolkit are at risk of information leakage and exposure to denial-of-service (DoS) as...

Exposed APIs and issues in the world’s largest organizations
2024-12-12 04:30

In this Help Net Security video, Tristan Kalos, CEO of Escape, discusses the results of its 2024 State of API Exposure report. The study highlights significant API security gaps affecting Fortune...

Criminals open DocuSign's Envelope API to make BEC special delivery
2024-11-05 18:34

Why? Because that's where the money is Business email compromise scammers are trying to up their success rate by using a DocuSign API.…

DocuSign's Envelopes API abused to send realistic fake invoices
2024-11-04 20:18

Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute fake invoices that appear genuine, impersonating well-known brands like Norton and PayPal. [...]

Product showcase: Shift API security left with StackHawk
2024-10-30 13:00

With the proliferation of APIs, and the speed at which AI functionality is helping fuel innovation, a strategic approach for securing APIs is no longer a nice to have, it’s a criticality. Without...

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
2024-10-24 02:30

Attacks on unprotected servers reach 'critical level' An unknown attacker is abusing exposed Docker Remote API servers to deploy perfctl cryptomining malware on victims' systems, according to...

Cybercriminals Exploiting Docker API Servers for SRBMiner Crypto Mining Attacks
2024-10-22 14:00

Bad actors have been observed targeting Docker remote API servers to deploy the SRBMiner crypto miner on compromised instances, according to new findings from Trend Micro. "In this attack, the...