Category: bleepingcomputer
-
Microsoft: Exchange 2016 and 2019 reach end of support in 30 days
Microsoft: Exchange 2016 and 2019 reach end of support in 30 days Microsoft has reminded administrators again that Exchange 2016 and Exchange 2019 will reach the end of extended support next month and has provided guidance for decommissioning outdated servers. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims. […] Lawrence Abrams Go to bleepingcomputer
-
New VoidProxy phishing service targets Microsoft 365, Google accounts
New VoidProxy phishing service targets Microsoft 365, Google accounts A newly discovered phishing-as-a-service (PhaaS) platform, named VoidProxy, targets Microsoft 365 and Google accounts, including those protected by third-party single sign-on (SSO) providers such as Okta. […] Bill Toulas Go to bleepingcomputer
-
Microsoft reminds of Windows 10 support ending in 30 days
Microsoft reminds of Windows 10 support ending in 30 days On Friday, Microsoft reminded customers once again that Windows 10 will reach its end of support in 30 days, on October 14. […] Sergiu Gatlan Go to bleepingcomputer
-
‘WhiteCobra’ floods VSCode market with crypto-stealing extensions
‘WhiteCobra’ floods VSCode market with crypto-stealing extensions A threat actor named WhiteCobra has targeting VSCode, Cursor, and Windsurf users by planting 24 malicious extensions in the Visual Studio marketplace and the Open VSX registry. […] Bill Toulas Go to bleepingcomputer
-
New HybridPetya ransomware can bypass UEFI Secure Boot
New HybridPetya ransomware can bypass UEFI Secure Boot A recently discovered ransomware strain called HybridPetya can bypass the UEFI Secure Boot feature to install a malicious application on the EFI System Partition. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of actively exploited Dassault RCE vulnerability
CISA warns of actively exploited Dassault RCE vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers exploiting a critical remote code execution flaw in DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution from French company Dassault Systèmes. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 23H2 Home and Pro reach end of support in 60 days
Windows 11 23H2 Home and Pro reach end of support in 60 days Microsoft has reminded customers today that devices running Home and Pro editions of Windows 11 23H2 will stop receiving updates in November. […] Sergiu Gatlan Go to bleepingcomputer
-
Man gets over 4 years in prison for selling unreleased movies
Man gets over 4 years in prison for selling unreleased movies A Tennessee court has sentenced a Memphis man who worked for a DVD and Blu-ray manufacturing and distribution company to 57 months in prison for stealing and selling digital copies of unreleased movies. […] Sergiu Gatlan Go to bleepingcomputer
-
The first three things you’ll want during a cyberattack
The first three things you’ll want during a cyberattack When cyberattacks hit, every second counts. Survival depends on three essentials: clarity to see what’s happening, control to contain it, and a lifeline to recover fast. Learn from Acronis TRU how MSPs and IT teams can prepare now for the difference between recovery and catastrophe. […]…
-
Samsung patches actively exploited zero-day reported by WhatsApp
Samsung patches actively exploited zero-day reported by WhatsApp Samsung has patched a remote code execution vulnerability that was exploited in zero-day attacks targeting its Android devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Exchange Online outage affecting users worldwide
Microsoft fixes Exchange Online outage affecting users worldwide Microsoft says that it has mitigated an Exchange Online outage affecting customers worldwide, which blocked their access to emails and calendars. […] Sergiu Gatlan Go to bleepingcomputer
-
U.S. Senator accuses Microsoft of “gross cybersecurity negligence”
U.S. Senator accuses Microsoft of “gross cybersecurity negligence” U.S. Senator Ron Wyden has sent a letter to the Federal Trade Commission (FTC) requesting the agency to investigate Microsoft for failing to provide adequate security in its products, which led to ransomware attacks against healthcare organizations. […] Bill Toulas Go to bleepingcomputer
-
Apple warns customers targeted in recent spyware attacks
Apple warns customers targeted in recent spyware attacks Apple warned customers last week that their devices were targeted in a new series of spyware attacks, according to the French national Computer Emergency Response Team (CERT-FR). […] Sergiu Gatlan Go to bleepingcomputer
-
Panama Ministry of Economy discloses breach claimed by INC ransomware
Panama Ministry of Economy discloses breach claimed by INC ransomware Panama’s Ministry of Economy and Finance (MEF) has disclosed that one of its computers may have been compromised in a cyberattack.. […] Bill Toulas Go to bleepingcomputer
-
DDoS defender targeted in 1.5 Bpps denial-of-service attack
DDoS defender targeted in 1.5 Bpps denial-of-service attack A DDoS mitigation service provider in Europe was targeted in a massive distributed denial-of-service attack that reached 1.5 billion packets per second. […] Bill Toulas Go to bleepingcomputer
-
Microsoft waives fees for Windows devs publishing to Microsoft Store
Microsoft waives fees for Windows devs publishing to Microsoft Store Microsoft announced that, starting today, individual Windows developers will no longer have to pay for publishing their applications on the Microsoft Store. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers left empty-handed after massive NPM supply-chain attack
Hackers left empty-handed after massive NPM supply-chain attack The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it. […] Bill Toulas Go to bleepingcomputer
-
Pixel 10 fights AI fakes with new Android photo verification tech
Pixel 10 fights AI fakes with new Android photo verification tech Google is integrating C2PA Content Credentials into the Pixel 10 camera and Google Photos, to help users distinguish between authentic, unaltered images and those generated or edited with artificial intelligence technology. […] Bill Toulas Go to bleepingcomputer
-
Cursor AI editor lets repos “autorun” malicious code on devices
Cursor AI editor lets repos “autorun” malicious code on devices A weakness in the Cursor code editor exposes developers to the risk of automatically executing tasks in a malicious repository as soon as it’s opened. […] Bill Toulas Go to bleepingcomputer
-
U.S. sanctions cyber scammers who stole billions from Americans
U.S. sanctions cyber scammers who stole billions from Americans The U.S. Department of the Treasury has sanctioned several large networks of cyber scam operations in Southeast Asia, which stole over $10 billion from Americans last year. […] Bill Toulas Go to bleepingcomputer
-
Hackers hide behind Tor in exposed Docker API breaches
Hackers hide behind Tor in exposed Docker API breaches A threat actor targeting exposed Docker APIs has updated its malicious tooling with more dangerous functionality that could lay the foundation for a complex botnet. […] Bill Toulas Go to bleepingcomputer
-
Windows 10 KB5065429 update includes 14 changes and fixes
Windows 10 KB5065429 update includes 14 changes and fixes Microsoft has released the KB5065429 cumulative update for Windows 10 22H2 and Windows 10 21H2, with fourteen fixes or changes, including fixes for unexpected UAC prompts and severe lag and stuttering issues with NDI streaming software. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days Today is Microsoft’s September 2025 Patch Tuesday, which includes security updates for 81 flaws, including two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5065426 & KB5065431 cumulative updates released
Windows 11 KB5065426 & KB5065431 cumulative updates released Microsoft has released Windows 11 KB5065426 and KB5065431 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
Plex tells users to reset passwords after new data breach
Plex tells users to reset passwords after new data breach Media streaming platform Plex is warning customers to reset passwords after suffering a data breach in which a hacker was able to steal customer authentication data from one of its databases. […] Lawrence Abrams Go to bleepingcomputer
-
Surge in networks scans targeting Cisco ASA devices raise concerns
Surge in networks scans targeting Cisco ASA devices raise concerns Large network scans have been targeting Cisco ASA devices, prompting warnings from cybersecurity researchers that it could indicate an upcoming flaw in the products. […] Bill Toulas Go to bleepingcomputer
-
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack A new supply chain attack on GitHub, dubbed ‘GhostAction,’ has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys. […] Bill Toulas Go to bleepingcomputer
-
Signal adds secure cloud backups to save and restore chats
Signal adds secure cloud backups to save and restore chats Signal has introduced a new opt-in feature that helps users create end-to-end encrypted backups of their chats, allowing them to restore messages even if their phones are damaged or lost. […] Sergiu Gatlan Go to bleepingcomputer
-
Lovesac confirms data breach after ransomware attack claims
Lovesac confirms data breach after ransomware attack claims American furniture brand Lovesac is warning that it suffered a data breach impacting an undisclosed number of individuals, stating their personal data was exposed in a cybersecurity incident. […] Bill Toulas Go to bleepingcomputer
-
Google to make it easier to access AI Mode as default
Google to make it easier to access AI Mode as default Google plans to make it easier for users to access AI mode by allowing them to set it as the default, replacing the traditional blue links. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT makes Projects feature free, adds a toggle to split chat
ChatGPT makes Projects feature free, adds a toggle to split chat ChatGPT’s Projects feature is now feature and second new feature allows you to create new conversations from existing conversations. […] Mayank Parmar Go to bleepingcomputer
-
iCloud Calendar abused to send phishing emails from Apple’s servers
iCloud Calendar abused to send phishing emails from Apple’s servers iCloud Calendar invites are being abused to send callback phishing emails disguised as purchase notifications directly from Apple’s email servers, making them more likely to bypass spam filters to land in targets’ inboxes. […] Lawrence Abrams Go to bleepingcomputer
-
Czech cyber agency warns against Chinese tech in critical infrastructure
Czech cyber agency warns against Chinese tech in critical infrastructure The Czech Republic’s National Cyber and Information Security Agency (NUKIB) is instructing critical infrastructure organizations in the country to avoid using Chinese technology or transferring user data to servers located in China. […] Bill Toulas Go to bleepingcomputer
-
VirusTotal finds hidden malware phishing campaign in SVG files
VirusTotal finds hidden malware phishing campaign in SVG files VirusTotal has discovered a phishing campaign hidden in SVG files that create convincing portals impersonating Colombia’s judicial system that deliver malware. […] Lawrence Abrams Go to bleepingcomputer
-
AI-powered malware hit 2,180 GitHub accounts in “s1ngularity” attack
AI-powered malware hit 2,180 GitHub accounts in “s1ngularity” attack Investigations into the Nx “s1ngularity” NPM supply chain attack have unveiled a massive fallout, with thousands of account tokens and repository secrets leaked. […] Bill Toulas Go to bleepingcomputer
-
Microsoft now enforces MFA on Azure Portal sign-ins for all tenants
Microsoft now enforces MFA on Azure Portal sign-ins for all tenants Microsoft says it has been enforcing multifactor authentication (MFA) for Azure Portal sign-ins across all tenants since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
EU fines Google $3.5 billion for anti-competitive ad practices
EU fines Google $3.5 billion for anti-competitive ad practices The European Commission has fined Google €2.95 billion ($3.5 billion) for abusing its dominance in the digital advertising technology market and favoring its adtech services over those of its competitors. […] Sergiu Gatlan Go to bleepingcomputer
-
Financial services firm Wealthsimple discloses data breach
Financial services firm Wealthsimple discloses data breach Wealthsimple, a leading Canadian online investment management service, has disclosed a data breach after attackers stole the personal data of an undisclosed number of customers in a recent incident. […] Sergiu Gatlan Go to bleepingcomputer
-
Max severity Argo CD API flaw leaks repository credentials
Max severity Argo CD API flaw leaks repository credentials An Argo CD vulnerability allows API tokens with even low project-level get permissions to access API endpoints and retrieve all repository credentials associated with the project. […] Bill Toulas Go to bleepingcomputer
-
Microsoft gives US students a free year of Microsoft 365 Personal
Microsoft gives US students a free year of Microsoft 365 Personal Microsoft announced that starting this Thursday, all college students in the United States can get a free year of Microsoft 365 Personal. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploited Sitecore zero-day flaw to deploy backdoors
Hackers exploited Sitecore zero-day flaw to deploy backdoors Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance malware. […] Bill Toulas Go to bleepingcomputer
-
Texas sues PowerSchool over breach exposing 62M students, 880k Texans
Texas sues PowerSchool over breach exposing 62M students, 880k Texans Texas Attorney General Ken Paxton has filed a lawsuit against education software company PowerSchool, which suffered a massive data breach in December that exposed the personal information of 62 million students, including over 880,000 Texans. […] Sergiu Gatlan Go to bleepingcomputer
-
Chess.com discloses recent data breach via file transfer app
Chess.com discloses recent data breach via file transfer app Chess.com has disclosed a data breach after threat actors gained unauthorized access to a third-party file transfer application used by the platform. […] Bill Toulas Go to bleepingcomputer
-
New TP-Link zero-day surfaces as CISA warns other flaws are exploited
New TP-Link zero-day surfaces as CISA warns other flaws are exploited TP-Link has confirmed the existence of an unpatched zero-day vulnerability impacting multiple router models, as CISA warns that other router flaws have been exploited in attacks. […] Bill Toulas Go to bleepingcomputer
-
France slaps Google with €325M fine for violating cookie regulations
France slaps Google with €325M fine for violating cookie regulations The French data protection authority has fined Google €325 million ($378 million) for violating cookie regulations and displaying ads between Gmail users’ emails without their consent. […] Sergiu Gatlan Go to bleepingcomputer
-
Threat actors abuse X’s Grok AI to spread malicious links
Threat actors abuse X’s Grok AI to spread malicious links Threat actors are using Grok, X’s built-in AI assistant, to bypass link posting restrictions that the platform introduced to reduce malicious advertising. […] Bill Toulas Go to bleepingcomputer
-
US offers $10 million bounty for info on Russian FSB hackers
US offers $10 million bounty for info on Russian FSB hackers The U.S. Department of State is offering a reward of up to $10 million for information on three Russian Federal Security Service (FSB) officers involved in cyberattacks targeting U.S. critical infrastructure organizations on behalf of the Russian government. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws
Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws Hackers are increasingly using a new AI-powered offensive security framework called HexStrike-AI in real attacks to exploit newly disclosed n-day flaws. […] Bill Toulas Go to bleepingcomputer
-
US sues robot toy maker for exposing children’s data to Chinese devs
US sues robot toy maker for exposing children’s data to Chinese devs The U.S. Department of Justice has sued toy maker Apitor Technology for allegedly allowing a Chinese third party to collect children’s geolocation data without their knowledge and parental consent. […] Sergiu Gatlan Go to bleepingcomputer
-
Police disrupts Streameast, largest pirated sports streaming network
Police disrupts Streameast, largest pirated sports streaming network The Alliance for Creativity and Entertainment (ACE) and Egyptian authorities have shut down Streameast, the world’s largest illegal live sports streaming network, and arrested two people allegedly associated with the operation. […] Bill Toulas Go to bleepingcomputer
-
Hackers breach fintech firm in attempted $130M bank heist
Hackers breach fintech firm in attempted $130M bank heist Hackers tried to steal $130 million from Evertec’s Brazilian subsidiary Sinqia S.A.after gaining unauthorized access to its environment on the central bank’s real-time payment system (Pix). […] Bill Toulas Go to bleepingcomputer
-
Cloudflare hit by data breach in Salesloft Drift supply chain attack
Cloudflare hit by data breach in Salesloft Drift supply chain attack Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps Internet infrastructure company Cloudflare said it recently blocked the largest recorded volumetric distributed denial-of-service (DDoS) attack, which peaked at 11.5 terabits per second (Tbps). […] Sergiu Gatlan Go to bleepingcomputer
-
No, Google did not warn 2.5 billion Gmail users to reset passwords
No, Google did not warn 2.5 billion Gmail users to reset passwords Google has disputed a widely reported story about the company warning all Gmail users to reset their passwords due to a recent data breach that also affected some Workspace accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Jaguar Land Rover says cyberattack ‘severely disrupted’ production
Jaguar Land Rover says cyberattack ‘severely disrupted’ production Jaguar Land Rover (JLR) announced that a cyberattack forced the company to shut down certain systems as part of the mitigation effort. […] Bill Toulas Go to bleepingcomputer
-
Zscaler data breach exposes customer info after Salesloft Drift compromise
Zscaler data breach exposes customer info after Salesloft Drift compromise Cybersecurity company Zscaler warns it suffered a data breach after threat actors gained access to its Salesforce instance and stole customer information, including the contents of support cases. […] Lawrence Abrams Go to bleepingcomputer
-
Amazon disrupts Russian APT29 hackers targeting Microsoft 365
Amazon disrupts Russian APT29 hackers targeting Microsoft 365 Researchers have disrupted an operation attributed to Russian state-sponsored threat group Midnight Blizzard, who sought access to Microsoft 365 accounts and data. […] Bill Toulas Go to bleepingcomputer
-
Brokewell Android malware delivered through fake TradingView ads
Brokewell Android malware delivered through fake TradingView ads Cybercriminals are abusing Meta’s advertising platforms with fake offers of a free TradingView Premium app that spreads the Brokewell malware for Android. […] Ionut Ilascu Go to bleepingcomputer
-
OpenAI releases big upgrade for ChatGPT Codex for agentic coding
OpenAI releases big upgrade for ChatGPT Codex for agentic coding OpenAI has announced a big update for Codex, which is the company’s agentic coding tool. […] Mayank Parmar Go to bleepingcomputer
-
Anthropic is testing GPT Codex-like Claude Code web app
Anthropic is testing GPT Codex-like Claude Code web app Anthropic is planning to bring the famous Claude Code to the web, and it might be similar to ChatGPT Codex, but you’ll need GitHub to get started. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI is testing “Thinking effort” for ChatGPT
OpenAI is testing “Thinking effort” for ChatGPT OpenAI is working on a new feature called the Thinking effort picker for ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
TamperedChef infostealer delivered through fraudulent PDF Editor
TamperedChef infostealer delivered through fraudulent PDF Editor Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef. […] Ionut Ilascu Go to bleepingcomputer
-
Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager
Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager Microsoft has released the KB5064081 preview cumulative update for Windows 11 24H2, which includes thirty-six new features or changes, with many gradually rolling out. These updates include new Recall features and a new way of displaying CPU usage in Task Manager. […] Lawrence…
-
Microsoft fixes bug behind Windows certificate enrollment errors
Microsoft fixes bug behind Windows certificate enrollment errors Microsoft has resolved a known issue causing false CertificateServicesClient (CertEnroll) error messages after installing the July 2025 preview and subsequent Windows 11 24H2 updates. […] Sergiu Gatlan Go to bleepingcomputer
-
WhatsApp patches vulnerability exploited in zero-day attacks
WhatsApp patches vulnerability exploited in zero-day attacks WhatsApp has patched a security vulnerability in its iOS and macOS messaging clients that was exploited in targeted zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to enforce MFA for Azure resource management in October
Microsoft to enforce MFA for Azure resource management in October Starting in October, Microsoft will enforce multi-factor authentication (MFA) for all Azure resource management actions to protect Azure clients from unauthorized access attempts. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says recent Windows update didn’t kill your SSD
Microsoft says recent Windows update didn’t kill your SSD Microsoft has found no link between the August 2025 KB5063878 security update and customer reports of failure and data corruption issues affecting solid-state drives (SSDs) and hard disk drives (HDDs). […] Sergiu Gatlan Go to bleepingcomputer
-
Google warns Salesloft breach impacted some Workspace accounts
Google warns Salesloft breach impacted some Workspace accounts Google reports that the Salesloft Drift breach is larger than initially thought, warning that attackers also used stolen OAuth tokens to access Google Workspace email accounts in addition to Salesforce data. […] Lawrence Abrams Go to bleepingcomputer
-
US targets North Korean IT worker army with new sanctions
US targets North Korean IT worker army with new sanctions The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned two individuals and two companies associated with North Korean IT worker schemes that operate at the expense of American organizations. […] Bill Toulas Go to bleepingcomputer
-
Google shares workarounds for auth failures on ChromeOS devices
Google shares workarounds for auth failures on ChromeOS devices Google is working to resolve authentication failures preventing users from signing into their Clever and ClassLink accounts on some ChromeOS devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Malware devs abuse Anthropic’s Claude AI to build ransomware
Malware devs abuse Anthropic’s Claude AI to build ransomware Anthropic’s Claude Code large language model has been abused by threat actors who used it in data extortion campaigns and to develop ransomware packages. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Word will save your files to the cloud by default
Microsoft Word will save your files to the cloud by default Microsoft says that Word for Windows will soon enable autosave and automatically save all new documents to the cloud by default. […] Sergiu Gatlan Go to bleepingcomputer
-
Storm-0501 hackers shift to ransomware attacks in the cloud
Storm-0501 hackers shift to ransomware attacks in the cloud Microsoft warns that a threat actor tracked as Storm-0501 has evolved its operations, shifting away from encrypting devices with ransomware to focusing on cloud-based encryption, data theft, and extortion. […] Lawrence Abrams Go to bleepingcomputer
-
Experimental PromptLock ransomware uses AI to encrypt, steal data
Experimental PromptLock ransomware uses AI to encrypt, steal data Threat researchers discovered the first AI-powered ransomware, called PromptLock, that uses Lua scripts to steal and encrypt data on Windows, macOS, and Linux systems. […] Bill Toulas Go to bleepingcomputer
-
FreePBX servers hacked via zero-day, emergency fix released
FreePBX servers hacked via zero-day, emergency fix released The Sangoma FreePBX Security Team is warning about an actively exploited FreePBX zero-day vulnerability that impacts systems with the Administrator Control Panel (ACP) is exposed to the internet. […] Lawrence Abrams Go to bleepingcomputer
-
IT system supplier cyberattack impacts 200 municipalities in Sweden
IT system supplier cyberattack impacts 200 municipalities in Sweden A cyberattack on Miljödata, an IT systems supplier for roughly 80% of Sweden’s municipal systems, has caused accessibility problems in more than 200 regions of the country. […] Bill Toulas Go to bleepingcomputer
-
Global Salt Typhoon hacking campaigns linked to Chinese tech firms
Global Salt Typhoon hacking campaigns linked to Chinese tech firms The U.S. National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC), and partners from over a dozen countries have linked the Salt Typhoon global hacking campaigns to three China-based technology firms. […] Lawrence Abrams Go to bleepingcomputer
-
Google to verify all Android devs to block malware on Google Play
Google to verify all Android devs to block malware on Google Play Google is introducing a new defense for Android called ‘Developer Verification’ to block malware installations from sideloaded apps sourced from outside the official Google Play app store. […] Bill Toulas Go to bleepingcomputer
-
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks Citrix fixed three NetScaler ADC and NetScaler Gateway flaws today, including a critical remote code execution flaw tracked as CVE-2025-7775 that was actively exploited in attacks as a zero-day vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
Silk Typhoon hackers hijack network captive portals in diplomat attacks
Silk Typhoon hackers hijack network captive portals in diplomat attacks State-sponsored hackers linked to the Mustang Panda activity cluster targeted diplomats by hijacking web traffic to redirect to a malware serving website. […] Bill Toulas Go to bleepingcomputer
-
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. The ShinyHunters extortion group claims responsibility for these additional Salesforce attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Nevada closes state offices as cyberattack disrupts IT systems
Nevada closes state offices as cyberattack disrupts IT systems Nevada remains two days into a cyberattack that began early Sunday, disrupting government websites, phone systems, and online platforms, and forcing all state offices to close on Monday. […] Lawrence Abrams Go to bleepingcomputer
-
Surge in coordinated scans targets Microsoft RDP auth servers
Surge in coordinated scans targets Microsoft RDP auth servers Internet intelligence firm GreyNoise reports that it has recorded a significant spike in scanning activity consisting of nearly 1,971 IP addresses probing Microsoft Remote Desktop Web Access and RDP Web Client authentication portals in unison, suggesting a coordinated reconnaissance campaign. […] Lawrence Abrams Go to bleepingcomputer
-
New AI attack hides data-theft prompts in downscaled images
New AI attack hides data-theft prompts in downscaled images Researchers have developed a novel attack that steals user data by injecting malicious prompts in images processed by AI systems before delivering them to a large language model. […] Bill Toulas Go to bleepingcomputer
-
Farmers Insurance data breach impacts 1.1M people after Salesforce attack
Farmers Insurance data breach impacts 1.1M people after Salesforce attack U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with BleepingComputer learning that the data was stolen in the widespread Salesforce attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Auchan retailer data breach impacts hundreds of thousands of customers
Auchan retailer data breach impacts hundreds of thousands of customers French retailer Auchan is informing that some sensitive data associated with loyalty accounts of several hundred thousand of its customers was exposed in a cyberattack. […] Bill Toulas Go to bleepingcomputer
-
Malicious Android apps with 19M installs removed from Google Play
Malicious Android apps with 19M installs removed from Google Play Seventy-seven malicious Android apps containing different types of malware were found on Google Play after being downloaded more than 19 million times. […] Bill Toulas Go to bleepingcomputer
-
Murky Panda hackers exploit cloud trust to hack downstream customers
Murky Panda hackers exploit cloud trust to hack downstream customers A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers. […] Lawrence Abrams Go to bleepingcomputer
-
APT36 hackers abuse Linux .desktop files to install malware in new attacks
APT36 hackers abuse Linux .desktop files to install malware in new attacks The Pakistani APT36 cyberspies are using Linux .desktop files to load malware in new attacks against government and defense entities in India. […] Bill Toulas Go to bleepingcomputer
-
Fake Mac fixes trick users into installing new Shamos infostealer
Fake Mac fixes trick users into installing new Shamos infostealer A new infostealer malware targeting Mac devices, called ‘Shamos,’ is targeting Mac devices in ClickFix attacks that impersonate troubleshooting guides and fixes. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: August Windows updates cause severe streaming issues
Microsoft: August Windows updates cause severe streaming issues Microsoft has confirmed that the August 2025 security updates are causing severe lag and stuttering issues with NDI streaming software on some Windows 10 and Windows 11 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Massive anti-cybercrime operation leads to over 1,200 arrests in Africa
Massive anti-cybercrime operation leads to over 1,200 arrests in Africa Law enforcement authorities in Africa have arrested over 1,200 suspects as part of ‘Operation Serengeti 2.0,’ an INTERPOL-led international crackdown targeting cross-border cybercriminal gangs. […] Sergiu Gatlan Go to bleepingcomputer
-
DaVita says ransomware gang stole data of nearly 2.7 million people
DaVita says ransomware gang stole data of nearly 2.7 million people Kidney dialysis firm DaVita has confirmed that a ransomware gang that breached its network stole the personal and health information of nearly 2.7 million individuals. […] Sergiu Gatlan Go to bleepingcomputer
-
Dev gets 4 years for creating kill switch on ex-employer’s systems
Dev gets 4 years for creating kill switch on ex-employer’s systems A software developer has been sentenced to four years in prison for sabotaging his ex-employer’s Windows network with custom malware and a kill switch that locked out employees when his account was disabled. […] Lawrence Abrams Go to bleepingcomputer
-
Colt confirms customer data stolen as Warlock ransomware auctions files
Colt confirms customer data stolen as Warlock ransomware auctions files UK-based telecommunications company Colt Technology Services confirms that customer documentation was stolen as Warlock ransomware gang auctions files. […] Lawrence Abrams Go to bleepingcomputer
-
Europol confirms $50,000 Qilin ransomware reward is fake
Europol confirms $50,000 Qilin ransomware reward is fake Europol has confirmed that a Telegram channel impersonating the agency and offering a $50,000 reward for information on two Qilin ransomware administrators is fake. The impostor later admitted it was created to troll researchers and journalists. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft asks customers for feedback on reported SSD failures
Microsoft asks customers for feedback on reported SSD failures Microsoft is seeking further information from customers who reported failure and data corruption issues affecting their solid-state drives (SSDs) and hard disk drives (HDDs) after installing the August 2025 security update. […] Sergiu Gatlan Go to bleepingcomputer
-
Scattered Spider hacker gets sentenced to 10 years in prison
Scattered Spider hacker gets sentenced to 10 years in prison Noah Michael Urban, a key member of the Scattered Spider cybercrime collective, was sentenced to 10 years in prison on Wednesday after pleading guilty to charges of wire fraud and conspiracy in April. […] Sergiu Gatlan Go to bleepingcomputer
-
Orange Belgium discloses data breach impacting 850,000 customers
Orange Belgium discloses data breach impacting 850,000 customers Orange Belgium, a subsidiary of telecommunications giant Orange Group, disclosed on Wednesday that attackers who breached its systems in July have stolen the data of approximately 850,000 customers. […] Sergiu Gatlan Go to bleepingcomputer