Category: bleepingcomputer
-
OpenAI is going Meta route, as it considers memory-based ads on ChatGPT
OpenAI is going Meta route, as it considers memory-based ads on ChatGPT OpenAI is planning to introduce ads on ChatGPT, as it continues to struggle with revenue from paid users. […] Mayank Parmar Go to bleepingcomputer
-
Google confirms AI search will have ads, but they may look different
Google confirms AI search will have ads, but they may look different Google Ads are not going anywhere. Eventually, AI Search results on Google and likely other properties will have ads. […] Mayank Parmar Go to bleepingcomputer
-
Windows 11 Build 26220.7051 released with “Ask Copilot” feature
Windows 11 Build 26220.7051 released with “Ask Copilot” feature Windows 11 Build 26220.7051 is now rolling out to testers in the Windows Insider Program, and there are at least three new features, including Ask Copilot in the taskbar. […] Mayank Parmar Go to bleepingcomputer
-
China-linked hackers exploited Lanscope flaw as a zero-day in attacks
China-linked hackers exploited Lanscope flaw as a zero-day in attacks China-linked cyber-espionage actors tracked as ‘Bronze Butler’ (Tick) exploited a Motex Lanscope Endpoint Manager vulnerability as a zero-day to deploy an updated version of their Gokcpdoor malware. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 tests shared Bluetooth audio support, but only for AI PCs
Windows 11 tests shared Bluetooth audio support, but only for AI PCs If you have two headphones, speakers, earbuds, or any other Bluetooth hardware, you can now use both simultaneously on a Copilot+ PC. […] Mayank Parmar Go to bleepingcomputer
-
‘We got hacked’ emails threaten to leak University of Pennsylvania data
‘We got hacked’ emails threaten to leak University of Pennsylvania data The University of Pennsylvania suffered a cybersecurity incident on Friday, where students and alumni received a series of offensive emails from various University email addresses, claiming that data was stolen in a breach. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Edge gets scareware sensor for faster scam detection
Microsoft Edge gets scareware sensor for faster scam detection Microsoft is introducing a new scareware sensor for the Microsoft Edge web browser, which helps detect scam pages more quickly and ensures that Defender SmartScreen blocks them faster. […] Sergiu Gatlan Go to bleepingcomputer
-
Australia warns of BadCandy infections on unpatched Cisco devices
Australia warns of BadCandy infections on unpatched Cisco devices The Australian government is warning about ongoing cyberattacks against unpatched Cisco IOS XE devices in the country to infect routers with the BadCandy webshell. […] Bill Toulas Go to bleepingcomputer
-
Why password controls still matter in cybersecurity
Why password controls still matter in cybersecurity Passwords still matter — and weak policies leave the door wide open. Specops Software explains how longer passphrases, smarter banned-password lists, and adaptive rotation strategies can strengthen security without frustrating users. […] Sponsored by Specops Software Go to bleepingcomputer
-
Ukrainian extradited from Ireland on Conti ransomware charges
Ukrainian extradited from Ireland on Conti ransomware charges A Ukrainian national believed to be a member of the Conti ransomware operation has been extradited to the United States and faces charges that could get him 25 years in prison. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI confirms GPT-5 is now better at handling mental and emotional distress
OpenAI confirms GPT-5 is now better at handling mental and emotional distress OpenAI confirmed that it shipped an update on October 5, which allows GPT-5 to better handle sensitive conversations, especially when a user is experiencing emotional or mental distress. […] Mayank Parmar Go to bleepingcomputer
-
Massive surge of NFC relay malware steals Europeans’ credit cards
Massive surge of NFC relay malware steals Europeans’ credit cards Near-Field Communication (NFC) relay malware has grown massively popular in Eastern Europe, with researchers discovering over 760 malicious Android apps using the technique to steal people’s payment card information in the past few months. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers CISA has ordered federal agencies to patch a high-severity vulnerability in Broadcom’s VMware Aria Operations and VMware Tools software, exploited by Chinese hackers since October 2024. […] Sergiu Gatlan Go to bleepingcomputer
-
Major telecom services provider Ribbon breached by state hackers
Major telecom services provider Ribbon breached by state hackers Ribbon Communications, a provider of telecommunications services to the U.S. government and telecom companies worldwide, revealed that nation-state hackers breached its IT network as early as December 2024. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
Malicious NPM packages fetch infostealer for Windows, Linux, macOS Ten malicious packages mimicking legitimate software projects in the npm registry download an information-stealing component that collects sensitive data from Windows, Linux, and macOS systems. […] Bill Toulas Go to bleepingcomputer
-
WordPress security plugin exposes private data to site subscribers
WordPress security plugin exposes private data to site subscribers The Anti-Malware Security and Brute-Force Firewall plugin for WordPress, installed on over 100,000 sites, has a vulnerability that allows subscribers to read any file on the server, potentially exposing private information. […] Bill Toulas Go to bleepingcomputer
-
Canada says hacktivists breached water and energy facilities
Canada says hacktivists breached water and energy facilities The Canadian Centre for Cyber Security warned today that hacktivists have breached critical infrastructure systems multiple times across the country, allowing them to modify industrial controls that could have led to dangerous conditions. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes Media Creation Tool broken on some Windows PCs
Microsoft fixes Media Creation Tool broken on some Windows PCs Microsoft has confirmed that the Windows 11 Media Creation Tool (MCT) is working again on Windows 10 22H2 and Windows 11 25H2 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: DNS outage impacts Azure and Microsoft 365 services
Microsoft: DNS outage impacts Azure and Microsoft 365 services Microsoft is suffering an ongoing DNS outage affecting customers worldwide, preventing them from logging into company networks and accessing Microsoft Azure and Microsoft 365 services. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5067036 update rolls out Administrator Protection feature
Windows 11 KB5067036 update rolls out Administrator Protection feature Microsoft has released the KB5067036 preview cumulative update for Windows 11 24H2 and 25H2, which begins the rollout of the Administrator Protection cybersecurity feature and an updated Start Menu. […] Lawrence Abrams Go to bleepingcomputer
-
Python rejects $1.5M grant from U.S. govt. fearing ethical compromise
Python rejects $1.5M grant from U.S. govt. fearing ethical compromise The Python Software Foundation (PSF) has withdrawn its $1.5 million grant proposal to the U.S. National Science Foundation (NSF) due to funding terms forcing a compromise on its commitment to diversity, equity, and inclusion.. […] Bill Toulas Go to bleepingcomputer
-
Advertising giant Dentsu reports data breach at subsidiary Merkle
Advertising giant Dentsu reports data breach at subsidiary Merkle Japanese advertising giant Dentsu has disclosed that its U.S.-based subsidiary Merkle suffered a cybersecurity incident that exposed staff and client data. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of two more actively exploited Dassault vulnerabilities
CISA warns of two more actively exploited Dassault vulnerabilities The Cybersecurity & Infrastructure Security Agency (CISA) warned today that attackers are actively exploiting two vulnerabilities in Dassault Systèmes’ DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution. […] Sergiu Gatlan Go to bleepingcomputer
-
Qilin ransomware abuses WSL to run Linux encryptors in Windows
Qilin ransomware abuses WSL to run Linux encryptors in Windows The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools. […] Lawrence Abrams Go to bleepingcomputer
-
Google disputes false claims of massive Gmail data breach
Google disputes false claims of massive Gmail data breach Google was once again forced to announce that it had not suffered a data breach after numerous news outlets published sensational stories about a fake breach that purportedly exposed 183 million accounts. […] Lawrence Abrams Go to bleepingcomputer
-
X: Re-enroll 2FA security keys by November 10 or get locked out
X: Re-enroll 2FA security keys by November 10 or get locked out X is warning that users must re-enroll their security keys or passkeys for two-factor authentication (2FA) before November 10 or they will be locked out of their accounts until they do so. […] Lawrence Abrams Go to bleepingcomputer
-
Ransomware profits drop as victims stop paying hackers
Ransomware profits drop as victims stop paying hackers The number of victims paying ransomware threat actors has reached a new low, with just 23% of the breached companies giving in to attackers’ demands. […] Bill Toulas Go to bleepingcomputer
-
Windows will soon prompt for memory scans after BSOD crashes
Windows will soon prompt for memory scans after BSOD crashes Microsoft has started testing a new feature that prompts Windows 11 users to run a memory scan when logging in after a blue screen of death (BSOD). […] Sergiu Gatlan Go to bleepingcomputer
-
QNAP warns of critical ASP.NET flaw in its Windows backup software
QNAP warns of critical ASP.NET flaw in its Windows backup software QNAP warned customers to patch a critical ASP.NET Core vulnerability that also impacts the company’s NetBak PC Agent, a Windows utility for backing& up data to a QNAP network-attached storage (NAS) device. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers steal Discord accounts with RedTiger-based infostealer
Hackers steal Discord accounts with RedTiger-based infostealer Attackers are using the open-source red-team tool RedTiger to build an infostealer that collects Discord account data and payment information. […] Bill Toulas Go to bleepingcomputer
-
New CoPhish attack steals OAuth tokens via Copilot Studio agents
New CoPhish attack steals OAuth tokens via Copilot Studio agents A new phishing technique dubbed ‘CoPhish’ weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains. […] Bill Toulas Go to bleepingcomputer
-
Hackers launch mass attacks exploiting outdated WordPress plugins
Hackers launch mass attacks exploiting outdated WordPress plugins A widespread exploitation campaign is targeting WordPress websites with GutenKit and Hunk Companion plugins vulnerable to critical-severity, old security issues that can be used to achieve remote code execution (RCE). […] Bill Toulas Go to bleepingcomputer
-
Critical WSUS flaw in Windows Server now exploited in attacks
Critical WSUS flaw in Windows Server now exploited in attacks Attackers are now exploiting a critical-severity Windows Server Update Service (WSUS) vulnerability, which already has publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Amazon: This week’s AWS outage caused by major DNS failure
Amazon: This week’s AWS outage caused by major DNS failure Amazon says a major DNS failure was behind a massive AWS (Amazon Web Services) outage that took down many websites and online services on Monday. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake LastPass death claims used to breach password vaults
Fake LastPass death claims used to breach password vaults LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process. […] Bill Toulas Go to bleepingcomputer
-
How to reduce costs with self-service password resets
How to reduce costs with self-service password resets Password resets account for nearly 40% of IT help desk calls, costing orgs time and money. Specops Software’s uReset lets users securely reset passwords with flexible MFA options like Duo, Okta, and Yubikey while enforcing identity verification to stop misuse. […] Sponsored by Specops Software Go to…
-
Windows Server emergency patches fix WSUS bug with PoC exploit
Windows Server emergency patches fix WSUS bug with PoC exploit Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities. […] Sergiu Gatlan Go to bleepingcomputer
-
Toys “R” Us Canada warns customers’ info leaked in data breach
Toys “R” Us Canada warns customers’ info leaked in data breach Toys “R” Us Canada has sent notices of a data breach to customers informing them of a security incident where threat actors leaked customer records they had previously stolen from its systems. […] Bill Toulas Go to bleepingcomputer
-
HP pulls update that broke Microsoft Entra ID auth on some AI PCs
HP pulls update that broke Microsoft Entra ID auth on some AI PCs HP has pulled an HP OneAgent software update for Windows 11 that mistakenly deleted Microsoft certificates required for some organizations to log in to Microsoft Entra ID, effectively disconnecting them from their company’s cloud environments. […] Lawrence Abrams Go to bleepingcomputer
-
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar Today, Microsoft introduced Mico, a new and more personal avatar for the AI-powered Copilot digital assistant, which the company describes as human-centered. […] Sergiu Gatlan Go to bleepingcomputer
-
Iranian hackers targeted over 100 govt orgs with Phoenix backdoor
Iranian hackers targeted over 100 govt orgs with Phoenix backdoor State-sponsored Iranian hacker group MuddyWater has targeted more than 100 government entities in attacks that deployed version 4 of the Phoenix backdoor. […] Bill Toulas Go to bleepingcomputer
-
Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000
Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000 Security researchers collected $792,750 in cash after exploiting 56 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploiting critical “SessionReaper” flaw in Adobe Magento
Hackers exploiting critical “SessionReaper” flaw in Adobe Magento Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. […] Bill Toulas Go to bleepingcomputer
-
TARmageddon flaw in abandoned Rust library enables RCE attacks
TARmageddon flaw in abandoned Rust library enables RCE attacks A high-severity vulnerability in the now-abandoned async-tar Rust library and its forks can be exploited to gain remote code execution on systems running unpatched software. […] Sergiu Gatlan Go to bleepingcomputer
-
Meta launches new anti-scam tools for WhatsApp and Messenger
Meta launches new anti-scam tools for WhatsApp and Messenger Meta has announced new tools to help WhatsApp and Messenger users protect themselves from potential scams and secure their accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Vidar Stealer 2.0 adds multi-threaded data theft, better evasion
Vidar Stealer 2.0 adds multi-threaded data theft, better evasion The operators of Vidar Stealer, one of the most successful malware-as-a-service (MaaS) operations of the past decade, have released a new major version to reflect massive improvements in the malware. […] Bill Toulas Go to bleepingcomputer
-
TP-Link warns of critical command injection flaw in Omada gateways
TP-Link warns of critical command injection flaw in Omada gateways TP-Link has made firmware updates available for a broad range of Omada gateway models to address four vulnerabilities, among which a critical pre-auth OS command injection. […] Bill Toulas Go to bleepingcomputer
-
CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw
CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw CISA has confirmed that an Oracle E-Business Suite flaw tracked as CVE-2025-61884 is being exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog. […] Lawrence Abrams Go to bleepingcomputer
-
Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities The latest releases of Cursor and Windsurf integrated development environments are vulnerable to more than 94 known and patched security issues in the Chromium browser and the V8 JavaScript engine. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit 34 zero-days on first day of Pwn2Own Ireland
Hackers exploit 34 zero-days on first day of Pwn2Own Ireland On the first day of Pwn2Own Ireland 2025, security researchers exploited 34 unique zero-days and collected $522,500 in cash awards. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5070773 emergency update fixes Windows Recovery issues
Windows 11 KB5070773 emergency update fixes Windows Recovery issues Microsoft has released an emergency update to fix the Windows Recovery Environment (WinRE), which became unusable on systems with USB mice and keyboards after installing the October 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: October updates break USB input in Windows Recovery
Microsoft: October updates break USB input in Windows Recovery Microsoft has confirmed that this month’s security updates disable USB mice and keyboards in the Windows Recovery Environment (WinRE), making it unusable. […] Sergiu Gatlan Go to bleepingcomputer
-
DNS0.EU private DNS service shuts down over sustainability issues
DNS0.EU private DNS service shuts down over sustainability issues The DNS0.EU non-profit public DNS service focused on European users announced its immediate shut down due to time and resource constraints. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Muji halts online sales after ransomware attack on supplier
Retail giant Muji halts online sales after ransomware attack on supplier Japanese retail company Muji has taken offline its store due to a logistics outage caused by a ransomware attack at its delivery partner, Askul. […] Bill Toulas Go to bleepingcomputer
-
Over 75,000 WatchGuard security devices vulnerable to critical RCE
Over 75,000 WatchGuard security devices vulnerable to critical RCE Nearly 76,000 WatchGuard Firebox network security appliances are exposed on the public web and still vulnerable to a critical issue (CVE-2025-9242) that could allow a remote attacker to execute code without authentication. […] Bill Toulas Go to bleepingcomputer
-
CISA: High-severity Windows SMB flaw now exploited in attacks
CISA: High-severity Windows SMB flaw now exploited in attacks CISA says threat actors are now actively exploiting a high-severity Windows SMB privilege escalation vulnerability that can let them gain SYSTEM privileges on unpatched systems. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI confirms GPT-6 is not shipping in 2025
OpenAI confirms GPT-6 is not shipping in 2025 OpenAI is not planning to ship GPT-6 this year, but that doesn’t necessarily mean the company will not release new models. […] Mayank Parmar Go to bleepingcomputer
-
Google ads for fake Homebrew, LogMeIn sites push infostealers
Google ads for fake Homebrew, LogMeIn sites push infostealers A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey. […] Bill Toulas Go to bleepingcomputer
-
ConnectWise fixes Automate bug allowing AiTM update attacks
ConnectWise fixes Automate bug allowing AiTM update attacks ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. […] Bill Toulas Go to bleepingcomputer
-
American Airlines subsidiary Envoy confirms Oracle data theft attack
American Airlines subsidiary Envoy confirms Oracle data theft attack Envoy Air, a regional airline carrier owned by American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft lifts more safeguard holds blocking Windows 11 updates
Microsoft lifts more safeguard holds blocking Windows 11 updates Microsoft has removed two more compatibility holds preventing customers from installing Windows 11 24H2 via Windows Update. […] Sergiu Gatlan Go to bleepingcomputer
-
Europol dismantles SIM box operation renting numbers for cybercrime
Europol dismantles SIM box operation renting numbers for cybercrime European law enforcement in an operation codenamed ‘SIMCARTEL’ has dismantled an illegal SIM-box service that enabled more than 3,200 fraud cases and caused at least 4.5 million euros in losses. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes highest-severity ASP.NET Core flaw ever
Microsoft fixes highest-severity ASP.NET Core flaw ever Earlier this week, Microsoft patched a vulnerability that was flagged with the “highest ever” severity rating received by an ASP.NET Core security flaw. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections Microsoft’s October Windows 11 updates have broken the “localhost” functionality, making applications that connect back to 127.0.0.1 over HTTP/2 no longer function properly. […] Lawrence Abrams Go to bleepingcomputer
-
Auction giant Sotheby’s says data breach exposed financial information
Auction giant Sotheby’s says data breach exposed financial information Major international auction house Sotheby’s is notifying individuals of a data breach incident on its systems where threat actors stole sensitive information, including financial details. […] Bill Toulas Go to bleepingcomputer
-
Have I Been Pwned: Prosper data breach impacts 17.6 million accounts
Have I Been Pwned: Prosper data breach impacts 17.6 million accounts Hackers stole the personal information of over 17.6 million people after breaching the systems of financial services company Prosper. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in older, unprotected Cisco networking devices to deploy a Linux rootkit and gain persistent access. […] Bill Toulas Go to bleepingcomputer
-
Microsoft disrupts ransomware attacks targeting Teams users
Microsoft disrupts ransomware attacks targeting Teams users Microsoft has disrupted a wave of Rhysida ransomware attacks in early October by revoking over 200 certificates used to sign malicious Teams installers. […] Sergiu Gatlan Go to bleepingcomputer
-
YouTube is down worldwide with playback error
YouTube is down worldwide with playback error YouTube is currently facing a global outage, with users reporting playback errors on both the website and mobile apps. […] Mayank Parmar Go to bleepingcomputer
-
Capita to pay £14 million for data breach impacting 6.6 million people
Capita to pay £14 million for data breach impacting 6.6 million people The Information Commissioner’s Office (ICO) in the UK has fined Capita, a provider of data-driven business process services, £14 million ($18.7 million) for a data breach incident in 2023 that exposed the personal information of 6.6 million people. […] Bill Toulas Go to bleepingcomputer
-
PowerSchool hacker gets sentenced to four years in prison
PowerSchool hacker gets sentenced to four years in prison 19-year-old college student Matthew D. Lane, from Worcester, Massachusetts, was sentenced to 4 years in prison for orchestrating a cyberattack on PowerSchool in December 2024 that resulted in a massive data breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake LastPass, Bitwarden breach alerts lead to PC hijacks
Fake LastPass, Bitwarden breach alerts lead to PC hijacks An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager. […] Bill Toulas Go to bleepingcomputer
-
F5 releases BIG-IP patches for stolen security vulnerabilities
F5 releases BIG-IP patches for stolen security vulnerabilities Cybersecurity company F5 has released security updates to address BIG-IP vulnerabilities stolen in a breach detected on August 9, 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
Malicious crypto-stealing VSCode extensions resurface on OpenVSX A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft’s Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and plant backdoors. […] Bill Toulas Go to bleepingcomputer
-
Final Windows 10 Patch Tuesday update rolls out as support ends
Final Windows 10 Patch Tuesday update rolls out as support ends In what marks the end of an era, Microsoft has released the Windows 10 KB5066791 cumulative update, the final free update for the operating system as it reaches the end of its support lifecycle. […] Lawrence Abrams Go to bleepingcomputer
-
New Android Pixnapping attack steals MFA codes pixel-by-pixel
New Android Pixnapping attack steals MFA codes pixel-by-pixel A new side-channel attack called Pixnapping enables a malicious Android app with no permissions to extract sensitive data by stealing pixels displayed by applications or websites, and reconstructing them to derive the content. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Exchange 2016 and 2019 have reached end of support
Microsoft: Exchange 2016 and 2019 have reached end of support Microsoft has reminded that Exchange Server 2016 and 2019 reached the end of support and advised IT administrators to upgrade servers to Exchange Server SE or migrate to Exchange Online. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws Today is Microsoft’s October 2025 Patch Tuesday, which includes security updates for 172 flaws, including six zero-day vulnerabilities. Get patching! […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft restricts IE mode access in Edge after zero-day attacks
Microsoft restricts IE mode access in Edge after zero-day attacks Microsoft is restricting access to Internet Explorer mode in Edge browser after learning that hackers are leveraging zero-day exploits in the Chakra JavaScript engine for access to target devices. […] Bill Toulas Go to bleepingcomputer
-
SimonMed says 1.2 million patients impacted in January data breach
SimonMed says 1.2 million patients impacted in January data breach U.S. medical imaging provider SimonMed Imaging is notifying more than 1.2 million individuals of a data breach that exposed their sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Massive multi-country botnet targets RDP services in the US
Massive multi-country botnet targets RDP services in the US A large-scale botnet is targeting Remote Desktop Protocol (RDP) services in the United States from more than 100,000 IP addresses. […] Bill Toulas Go to bleepingcomputer
-
SonicWall VPN accounts breached using stolen creds in widespread attacks
SonicWall VPN accounts breached using stolen creds in widespread attacks Researchers warn that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, valid credentials. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates outage affecting Microsoft 365 apps
Microsoft investigates outage affecting Microsoft 365 apps Microsoft is investigating an ongoing incident that is preventing some customers from accessing Microsoft 365 applications. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake ‘Inflation Refund’ texts target New Yorkers in new scam
Fake ‘Inflation Refund’ texts target New Yorkers in new scam An ongoing smishing campaign is targeting New Yorkers with text messages posing as the Department of Taxation and Finance, claiming to offer “Inflation Refunds” in an attempt to steal victims’ personal and financial data. […] Lawrence Abrams Go to bleepingcomputer
-
Spain dismantles “GXC Team” cybercrime syndicate, arrests leader
Spain dismantles “GXC Team” cybercrime syndicate, arrests leader Spanish Guardia Civil have dismantled the “GXC Team” cybercrime syndicate and arrested its alleged leader, a 25-year-old Brazilian known as “GoogleXcoder.” […] Bill Toulas Go to bleepingcomputer
-
Windows 11 23H2 Home and Pro reach end of support in 30 days
Windows 11 23H2 Home and Pro reach end of support in 30 days Microsoft has reminded customers again today that systems running Home and Pro editions of Windows 11 23H2 will stop receiving security updates next month. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploiting zero-day in Gladinet file sharing software
Hackers exploiting zero-day in Gladinet file sharing software Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication. […] Bill Toulas Go to bleepingcomputer
-
Cybersecurity For Dummies, 3rd Edition eBook FREE for a Limited Time
Cybersecurity For Dummies, 3rd Edition eBook FREE for a Limited Time In today’s hyper-connected world, cyber threats are more sophisticated and frequent than ever – ransomware, data breaches, and social engineering scams, targeting everyone from individuals to Fortune 500 companies. Right now, you can grab “Cybersecurity For Dummies, 3rd Edition” – a $29.99 value –…
-
Google Chrome to revoke notification access for inactive sites
Google Chrome to revoke notification access for inactive sites Google is updating the Chrome web browser to automatically revoke notification permissions for websites that haven’t been visited recently, to reduce alert overload. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple now offers $2 million for zero-click RCE vulnerabilities
Apple now offers $2 million for zero-click RCE vulnerabilities Apple is announcing a major expansion and redesign of its bug bounty program, doubling maximum payouts, adding new research categories, and introducing a more transparent reward structure. […] Bill Toulas Go to bleepingcomputer
-
FBI takes down BreachForums portal used for Salesforce extortion
FBI takes down BreachForums portal used for Salesforce extortion The FBI has seized last night all domains for the BreachForums hacking forum operated by the ShinyHunters group mostly as a portal for leaking corporate data stolen in attacks from ransomware and extortion gangs. […] Bill Toulas Go to bleepingcomputer
-
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube A new Android spyware called ClayRat is luring potential victims by posing as popular apps and services like WhatsApp, Google Photos, TikTok, and YouTube. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Hackers target universities in “payroll pirate” attacks
Microsoft: Hackers target universities in “payroll pirate” attacks A cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in “pirate payroll” attacks since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers now use Velociraptor DFIR tool in ransomware attacks
Hackers now use Velociraptor DFIR tool in ransomware attacks Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender mistakenly flags SQL Server as end-of-life
Microsoft Defender mistakenly flags SQL Server as end-of-life Microsoft is working to resolve a known issue that causes its Defender for Endpoint enterprise endpoint security platform to incorrectly tag SQL Server software as end-of-life. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers claim Discord breach exposed data of 5.5 million users
Hackers claim Discord breach exposed data of 5.5 million users Discord says they will not be negotiating with threat actors who claim to have stolen the data of 5.5 million unique users from the company’s Zendesk support system instance, including government IDs and partial payment information for some people. […] Lawrence Abrams Go to bleepingcomputer
-
New FileFix attack uses cache smuggling to evade security software
New FileFix attack uses cache smuggling to evade security software A new variant of the FileFix social engineering attack uses cache smuggling to secretly download a malicious ZIP archive onto a victim’s system and bypassing security software. […] Lawrence Abrams Go to bleepingcomputer
-
Qilin ransomware claims Asahi brewery attack, leaks data
Qilin ransomware claims Asahi brewery attack, leaks data The Qilin ransomware group has claimed responsibility for the attack at Japanese beer maker Asahi, adding the company to its extortion page on the dark web yesterday. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 outage blocks access to Teams, Exchange Online
Microsoft 365 outage blocks access to Teams, Exchange Online Microsoft is working to resolve an ongoing outage preventing users from accessing Microsoft 365 services, including Microsoft Teams, Exchange Online, and the admin center. […] Sergiu Gatlan Go to bleepingcomputer