Category: bleepingcomputer
-
ChatGPT will soon record, transcribe, and summarize your meetings
ChatGPT will soon record, transcribe, and summarize your meetings OpenAI may be planning to challenge Microsoft Teams Copilot integration with a new “Record” feature in ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
Windows 10 KB5058379 update triggers BitLocker recovery on some devices
Windows 10 KB5058379 update triggers BitLocker recovery on some devices The Windows 10 KB5058379 cumulative update is triggering unexpected BitLocker recovery prompts on some devices afters it’s installed and the computer restarted. […] Lawrence Abrams Go to bleepingcomputer
-
Google fixes high severity Chrome flaw with public exploit
Google fixes high severity Chrome flaw with public exploit Google has released emergency security updates to patch a high-severity Chrome vulnerability that has a public exploit and can let attackers hijack accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to block admin-level browser launches for better security
Google Chrome to block admin-level browser launches for better security Google is rolling out a change to Chromium that “de-elevates” Google Chrome so it does not run as an administrator to increase security in Windows. […] Mayank Parmar Go to bleepingcomputer
-
Hackers behind UK retail attacks now targeting US companies
Hackers behind UK retail attacks now targeting US companies Google warned today that hackers using Scattered Spider tactics against retail chains in the United Kingdom have also started targeting retailers in the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gangs join ongoing SAP NetWeaver attacks
Ransomware gangs join ongoing SAP NetWeaver attacks Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers. […] Sergiu Gatlan Go to bleepingcomputer
-
Australian Human Rights Commission leaks docs to search engines
Australian Human Rights Commission leaks docs to search engines The Australian Human Rights Commission (AHRC) disclosed a data breach incident where private documents leaked online and were indexed by major search engines. […] Bill Toulas Go to bleepingcomputer
-
SAP patches second zero-day flaw exploited in recent attacks
SAP patches second zero-day flaw exploited in recent attacks SAP has released patches to address a second vulnerability exploited in recent attacks targeting SAP NetWeaver servers as a zero-day. […] Sergiu Gatlan Go to bleepingcomputer
-
North Korea ramps up cyberspying in Ukraine to assess war risk
North Korea ramps up cyberspying in Ukraine to assess war risk The state-backed North Korean threat group Konni (Opal Sleet, TA406) was observed targeting Ukrainian government entities in intelligence collection operations. […] Bill Toulas Go to bleepingcomputer
-
Twilio denies breach following leak of alleged Steam 2FA codes
Twilio denies breach following leak of alleged Steam 2FA codes Twilio has denied in a statement for BleepingComputer that it was breached after a threat actor claimed to be holding over 89 million Steam user records with one-time access codes. […] Bill Toulas Go to bleepingcomputer
-
Ivanti fixes EPMM zero-days chained in code execution attacks
Ivanti fixes EPMM zero-days chained in code execution attacks Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws Today is Microsoft’s May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
ASUS DriverHub flaw let malicious sites run commands with admin rights
ASUS DriverHub flaw let malicious sites run commands with admin rights The ASUS DriverHub driver management utility was vulnerable to a critical remote code execution flaw that allowed malicious sites to execute commands on devices with the software installed. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 upgrade block lifted after Safe Exam Browser fix
Windows 11 upgrade block lifted after Safe Exam Browser fix Microsoft has removed an upgrade block that prevented some Safe Exam Browser users from installing the Windows 11 2024 Update due to incompatibility issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers now testing ClickFix attacks against Linux targets
Hackers now testing ClickFix attacks against Linux targets A new campaign employing ClickFix attacks has been spotted targeting both Windows and Linux systems using instructions that make infections on either operating system possible. […] Bill Toulas Go to bleepingcomputer
-
Output Messenger flaw exploited as zero-day in espionage attacks
Output Messenger flaw exploited as zero-day in espionage attacks A Türkiye-backed cyberespionage group exploited a zero-day vulnerability to attack Output Messenger users linked to the Kurdish military in Iraq. […] Sergiu Gatlan Go to bleepingcomputer
-
Moldova arrests suspect linked to DoppelPaymer ransomware attacks
Moldova arrests suspect linked to DoppelPaymer ransomware attacks Moldovan authorities have detained a 45-year-old suspect linked to DoppelPaymer ransomware attacks targeting Dutch organizations in 2021. […] Sergiu Gatlan Go to bleepingcomputer
-
Bluetooth 6.1 enhances privacy with randomized RPA timing
Bluetooth 6.1 enhances privacy with randomized RPA timing The Bluetooth Special Interest Group (SIG) has announced Bluetooth Core Specification 6.1, bringing important improvements to the popular wireless communication protocol. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT is finally adding Download as PDF for Deep Research
ChatGPT is finally adding Download as PDF for Deep Research ChatGPT’s Deep Research, which allows you to conduct multi-step research for complex tasks, is finally getting an option to save the report as a PDF. […] Mayank Parmar Go to bleepingcomputer
-
iClicker site hack targeted students with malware via fake CAPTCHA
iClicker site hack targeted students with malware via fake CAPTCHA The website of iClicker, a popular student engagement platform, was compromised in a ClickFix attack that used a fake CAPTCHA prompt to trick students and instructors into installing malware on their devices. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Teams will soon block screen capture during meetings
Microsoft Teams will soon block screen capture during meetings Microsoft is working on adding a new Teams feature that will prevent users from capturing screenshots of sensitive information shared during meetings. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake AI video generators drop new Noodlophile infostealer malware
Fake AI video generators drop new Noodlophile infostealer malware Fake AI-powered video generation tools are being used to distribute a new information-stealing malware family called ‘Noodlophile,’ under the guise of generated media content. […] Bill Toulas Go to bleepingcomputer
-
Ascension says recent data breach affects over 430,000 patients
Ascension says recent data breach affects over 430,000 patients Ascension, one of the largest private healthcare systems in the United States, has revealed that the personal and healthcare information of over 430,000 patients was exposed in a data breach disclosed last month. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to use on-device AI to detect tech support scams
Google Chrome to use on-device AI to detect tech support scams Google is implementing a new Chrome security feature that uses the built-in ‘Gemini Nano’ large-language model (LLM) to detect and block tech support scams while browsing the web. […] Bill Toulas Go to bleepingcomputer
-
Police dismantles botnet selling hacked routers as residential proxies
Police dismantles botnet selling hacked routers as residential proxies Law enforcement authorities have dismantled a botnet that infected thousands of routers over the last 20 years to build two networks of residential proxies known as Anyproxy and 5socks. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers behind attacks targeting SAP NetWeaver servers
Chinese hackers behind attacks targeting SAP NetWeaver servers Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor. […] Sergiu Gatlan Go to bleepingcomputer
-
Germany takes down eXch cryptocurrency exchange, seizes servers
Germany takes down eXch cryptocurrency exchange, seizes servers The Federal police in Germany (BKA) seized the server infrastructure and shut down the ‘eXch’ cryptocurrency exchange platform for alleged money laundering cybercrime proceeds. […] Bill Toulas Go to bleepingcomputer
-
FBI: End-of-life routers hacked for cybercrime proxy networks
FBI: End-of-life routers hacked for cybercrime proxy networks The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks. […] Bill Toulas Go to bleepingcomputer
-
Cisco fixes max severity IOS XE flaw letting attackers hijack devices
Cisco fixes max severity IOS XE flaw letting attackers hijack devices Cisco has fixed a maximum severity flaw in IOS XE Software for Wireless LAN Controllers by a hard-coded JSON Web Token (JWT) that allows an unauthenticated remote attacker to take over devices. […] Bill Toulas Go to bleepingcomputer
-
Education giant Pearson hit by cyberattack exposing customer data
Education giant Pearson hit by cyberattack exposing customer data Education giant Pearson suffered a cyberattack, allowing threat actors to steal corporate data and customer information, BleepingComputer has learned. […] Lawrence Abrams Go to bleepingcomputer
-
Supply chain attack hits npm package with 45,000 weekly downloads
Supply chain attack hits npm package with 45,000 weekly downloads An npm package named ‘rand-user-agent’ has been compromised in a supply chain attack to inject obfuscated code that activates a remote access trojan (RAT) on the user’s system. […] Bill Toulas Go to bleepingcomputer
-
Malicious PyPi package hides RAT malware, targets Discord devs since 2022
Malicious PyPi package hides RAT malware, targets Discord devs since 2022 A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three years. […] Sergiu Gatlan Go to bleepingcomputer
-
LockBit ransomware gang hacked, victim negotiations exposed
LockBit ransomware gang hacked, victim negotiations exposed The LockBit ransomware gang has suffered a data breach after its dark web affiliate panels were defaced and replaced with a message linking to a MySQL database dump. […] Lawrence Abrams Go to bleepingcomputer
-
PowerSchool hacker now extorting individual school districts
PowerSchool hacker now extorting individual school districts PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student and teacher data if a ransom is not paid. […] Lawrence Abrams Go to bleepingcomputer
-
CoGUI phishing platform sent 580 million emails to steal credentials
CoGUI phishing platform sent 580 million emails to steal credentials A new phishing kit named ‘CoGUI’ sent over 580 million emails to targets between January and April 2025, aiming to steal account credentials and payment data. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit OttoKit WordPress plugin flaw to add admin accounts
Hackers exploit OttoKit WordPress plugin flaw to add admin accounts Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. […] Bill Toulas Go to bleepingcomputer
-
Play ransomware exploited Windows logging flaw in zero-day attacks
Play ransomware exploited Windows logging flaw in zero-day attacks The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: April updates cause Windows Server auth issues
Microsoft: April updates cause Windows Server auth issues Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. […] Sergiu Gatlan Go to bleepingcomputer
-
Apache Parquet exploit tool detect servers vulnerable to critical flaw
Apache Parquet exploit tool detect servers vulnerable to critical flaw A proof-of-concept exploit tool has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy to find vulnerable servers. […] Bill Toulas Go to bleepingcomputer
-
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. […] Bill Toulas Go to bleepingcomputer
-
UK Legal Aid Agency investigates cybersecurity incident
UK Legal Aid Agency investigates cybersecurity incident The Legal Aid Agency (LAA), an executive agency of the UK’s Ministry of Justice that oversees billions in legal funding, warned law firms of a security incident and said the attackers might have accessed financial information. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Langflow RCE flaw exploited to hack AI app servers
Critical Langflow RCE flaw exploited to hack AI app servers The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible. […] Bill Toulas Go to bleepingcomputer
-
Linux wiper malware hidden in malicious Go modules on GitHub
Linux wiper malware hidden in malicious Go modules on GitHub A supply-chain attack targets Linux servers with disk-wiping malware hidden in Golang modules published on GitHub. […] Ionut Ilascu Go to bleepingcomputer
-
Microsoft pushes fix for Windows 11 update 0x80240069 errors
Microsoft pushes fix for Windows 11 update 0x80240069 errors Microsoft has fixed a known issue preventing Windows 11 24H2 feature updates from being delivered via Windows Server Update Services (WSUS) after installing the April 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Luna Moth extortion hackers pose as IT help desks to breach US firms
Luna Moth extortion hackers pose as IT help desks to breach US firms The data-theft extortion group known as Luna Moth, aka Silent Ransom Group, has ramped up callback phishing campaigns in attacks on legal and financial institutions in the United States. […] Bill Toulas Go to bleepingcomputer
-
New “Bring Your Own Installer” EDR bypass used in ransomware attack
New “Bring Your Own Installer” EDR bypass used in ransomware attack A new “Bring Your Own Installer” EDR bypass technique is exploited in attacks to bypass SentinelOne’s tamper protection feature, allowing threat actors to disable endpoint detection and response (EDR) agents to install the Babuk ransomware. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft finds default Kubernetes Helm charts can expose data
Microsoft finds default Kubernetes Helm charts can expose data Microsoft warns about the security risks posed by default configurations in Kubernetes deployments, particularly those using out-of-the-box Helm charts, which could publicly expose sensitive data. […] Bill Toulas Go to bleepingcomputer
-
OpenAI document explains when to use each ChatGPT model
OpenAI document explains when to use each ChatGPT model OpenAI admitted that it can be confusing for users to choose between all the different models, but the company has quietly published a document that makes it easier to understand ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
StealC malware enhanced with stealth upgrades and data theft tools
StealC malware enhanced with stealth upgrades and data theft tools The creators of StealC, a widely-used information stealer and malware downloader, have released its second major version, bringing multiple stealth and data theft enhancements. […] Bill Toulas Go to bleepingcomputer
-
Google NotebookLM is now using Gemini 2.5 Flash
Google NotebookLM is now using Gemini 2.5 Flash Google NotebookLM, which is a research and note-taking AI tool, is getting upgraded to Gemini 2.5 Flash. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft ends Authenticator password autofill, moves users to Edge
Microsoft ends Authenticator password autofill, moves users to Edge Microsoft has announced that it will discontinue the password storage and autofill feature in the Authenticator app starting in July and will complete the deprecation in August 2025. […] Bill Toulas Go to bleepingcomputer
-
Co-op confirms data theft after DragonForce ransomware claims attack
Co-op confirms data theft after DragonForce ransomware claims attack The Co-op cyberattack is far worse than initially reported, with the company now confirming that data was stolen for a significant number of current and past customers. […] Lawrence Abrams Go to bleepingcomputer
-
Magento supply chain attack compromises hundreds of e-stores
Magento supply chain attack compromises hundreds of e-stores A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational. […] Bill Toulas Go to bleepingcomputer
-
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks A 36-year-old Yemeni national, who is believed to be the developer and primary operator of ‘Black Kingdom’ ransomware, has been indicted by the United States for conducting 1,500 attacks on Microsoft Exchange servers. […] Bill Toulas Go to bleepingcomputer
-
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call The United Kingdom’s National Cyber Security Centre warned that ongoing cyberattacks impacting multiple UK retail chains should be taken as a “wake-up call.” […] Sergiu Gatlan Go to bleepingcomputer
-
TikTok fined €530 million for sending European user data to China
TikTok fined €530 million for sending European user data to China The Irish Data Protection Commission (DPC) has fined TikTok €530 million (over $601 million) for illegally transferring the personal data of users in the European Economic Area (EEA) to China, violating the European Union’s GDPR data protection regulations. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft makes all new accounts passwordless by default
Microsoft makes all new accounts passwordless by default Microsoft has announced that all new Microsoft accounts will be “passwordless by default” to secure them against password attacks such as phishing, brute force, and credential stuffing. […] Sergiu Gatlan Go to bleepingcomputer
-
Hacker ‘NullBulge’ pleads guilty to stealing Disney’s Slack data
Hacker ‘NullBulge’ pleads guilty to stealing Disney’s Slack data A California man who used the alias “NullBulge” has pleaded guilty to illegally accessing Disney’s internal Slack channels and stealing over 1.1 terabytes of internal company data. […] Lawrence Abrams Go to bleepingcomputer
-
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks Russia-aligned hacktivists persistently target key public and private organizations in the Netherlands with distributed denial of service (DDoS) attacks, causing access problems and service disruptions. […] Bill Toulas Go to bleepingcomputer
-
Ukrainian extradited to US for Nefilim ransomware attacks
Ukrainian extradited to US for Nefilim ransomware attacks A Ukrainian national has been extradited from Spain to the United States to face charges over allegedly conducting Nefilim ransomware attacks against companies. […] Lawrence Abrams Go to bleepingcomputer
-
Harrods the next UK retailer targeted in a cyberattack
Harrods the next UK retailer targeted in a cyberattack London’s iconic department store, Harrods, has confirmed it was targeted in a cyberattack, becoming the third major UK retailer to report cyberattacks in a week following incidents at M&S and the Co-op. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers abuse IPv6 networking feature to hijack software updates
Hackers abuse IPv6 networking feature to hijack software updates A China-aligned APT threat actor named “TheWizards” abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress plugin disguised as a security tool injects backdoor
WordPress plugin disguised as a security tool injects backdoor A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it. […] Bill Toulas Go to bleepingcomputer
-
WhatsApp unveils ‘Private Processing’ for cloud-based AI features
WhatsApp unveils ‘Private Processing’ for cloud-based AI features WhatsApp has announced the introduction of ‘Private Processing,’ a new technology that enables users to utilize advanced AI features by offloading tasks to privacy-preserving cloud servers. […] Bill Toulas Go to bleepingcomputer
-
SonicWall: SMA100 VPN vulnerabilities now exploited in attacks
SonicWall: SMA100 VPN vulnerabilities now exploited in attacks Cybersecurity company SonicWall has warned customers that several vulnerabilities impacting its Secure Mobile Access (SMA) appliances are now being actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Commvault says recent breach didn’t impact customer backup data
Commvault says recent breach didn’t impact customer backup data Commvault, a leading provider of data protection solutions, says a nation-state threat actor who breached its Azure environment didn’t gain access to customer backup data. […] Sergiu Gatlan Go to bleepingcomputer
-
Grinex exchange suspected rebrand of sanctioned Garantex crypto firm
Grinex exchange suspected rebrand of sanctioned Garantex crypto firm A new cryptocurrency exchange named Grinex is believed to be a rebrand of Garantex, a Russian cryptocurrency exchange whose domains were seized by the U.S. authorities and an admin arrested. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Windows Server hotpatching to require subscription
Microsoft: Windows Server hotpatching to require subscription Microsoft has announced it will require paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers ramp up scans for leaked Git tokens and secrets
Hackers ramp up scans for leaked Git tokens and secrets Threat actors are intensifying internet-wide scanning for Git configuration files that can reveal sensitive secrets and authentication tokens used to compromise cloud services and source code repositories. […] Bill Toulas Go to bleepingcomputer
-
France ties Russian APT28 hackers to 12 cyberattacks on French orgs
France ties Russian APT28 hackers to 12 cyberattacks on French orgs Today, the French foreign ministry blamed the APT28 hacking group linked to Russia’s military intelligence service (GRU) for targeting or breaching a dozen French entities over the last four years. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks A set of security vulnerabilities in Apple’s AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code execution. […] Sergiu Gatlan Go to bleepingcomputer
-
Marks & Spencer breach linked to Scattered Spider ransomware attack
Marks & Spencer breach linked to Scattered Spider ransomware attack Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as “Scattered Spider” BleepingComputer has learned from multiple sources. […] Lawrence Abrams Go to bleepingcomputer
-
Hitachi Vantara takes servers offline after Akira ransomware attack
Hitachi Vantara takes servers offline after Akira ransomware attack Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. […] Sergiu Gatlan Go to bleepingcomputer
-
VeriSource now says February data breach impacts 4 million people
VeriSource now says February data breach impacts 4 million people Employee benefits administration firm VeriSource Services is warning that a data breach exposed the personal information of four million people. […] Bill Toulas Go to bleepingcomputer
-
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux warns of update failures after losing repo signing key
Kali Linux warns of update failures after losing repo signing key Offensive Security warned Kali Linux users to manually install a new Kali repository signing key to avoid experiencing update failures. […] Sergiu Gatlan Go to bleepingcomputer
-
Coinbase fixes 2FA log error making people think they were hacked
Coinbase fixes 2FA log error making people think they were hacked Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
Brave’s Cookiecrumbler tool taps community to help block cookie notices
Brave’s Cookiecrumbler tool taps community to help block cookie notices Brave has open-sourceed a new tool called “Cookiecrumbler,” which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won’t break site functionality. […] Bill Toulas Go to bleepingcomputer
-
DragonForce expands ransomware model with white-label branding scheme
DragonForce expands ransomware model with white-label branding scheme The ransomware scene is re-organizing, with one gang known as DragonForce working to gather other operations under a cartel-like structure. […] Ionut Ilascu Go to bleepingcomputer
-
WooCommerce admins targeted by fake security patches that hijack sites
WooCommerce admins targeted by fake security patches that hijack sites A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a “critical patch” that adds a WordPress backdoor to the site. […] Bill Toulas Go to bleepingcomputer
-
Windows 11’s Recall AI is now rolling out on Copilot+ PCs
Windows 11’s Recall AI is now rolling out on Copilot+ PCs Microsoft has confirmed that Windows Recall is rolling out to everyone with Windows 11 KB5055627 on Copilot+ PCs. […] Mayank Parmar Go to bleepingcomputer
-
Windows 11 KB5055627 update released with 30 new changes, fixes
Windows 11 KB5055627 update released with 30 new changes, fixes Microsoft has released the KB5055627 preview cumulative update for Windows 11 24H2 with many new features gradually rolling out, and some new bug fixes for everyone. […] Lawrence Abrams Go to bleepingcomputer
-
Craft CMS RCE exploit chain used in zero-day attacks to steal data
Craft CMS RCE exploit chain used in zero-day attacks to steal data Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense. […] Lawrence Abrams Go to bleepingcomputer
-
Marks & Spencer pauses online orders after cyberattack
Marks & Spencer pauses online orders after cyberattack British retailer giant Marks & Spencer (M&S) has suspended online orders while working to recover from a recently disclosed cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Mobile provider MTN says cyberattack compromised customer data
Mobile provider MTN says cyberattack compromised customer data African mobile giant MTN Group announced that a cybersecurity incident has compromised the personal information of some of its subscribers in certain countries. […] Bill Toulas Go to bleepingcomputer
-
FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches
FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches The FBI has asked the public for information on Chinese Salt Typhoon hackers behind widespread breaches of telecommunications providers in the United States and worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft announces fix for CPU spikes when typing in Outlook
Microsoft announces fix for CPU spikes when typing in Outlook Microsoft says it will soon fix a known issue causing CPU spikes when typing messages in recent versions of its classic Outlook email client. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts
Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts Russian threat actors have been abusing legitimate OAuth 2.0 authentication workflows to hijack Microsoft 365 accounts of employees of organizations related to Ukraine and human rights. […] Bill Toulas Go to bleepingcomputer
-
Lazarus hackers breach six companies in watering hole attacks
Lazarus hackers breach six companies in watering hole attacks In a recent espionage campaign, the infamous North Korean threat group Lazarus targeted multiple organizations in the software, IT, finance, and telecommunications sectors in South Korea. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes machine learning bug flagging Adobe emails as spam
Microsoft fixes machine learning bug flagging Adobe emails as spam Microsoft says it mitigated a known issue in one of its machine learning (ML) models that mistakenly flagged Adobe emails in Exchange Online as spam. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian army targeted by new Android malware hidden in mapping app
Russian army targeted by new Android malware hidden in mapping app A new Android malware has been discovered hidden inside trojanized versions of the Alpine Quest mapping app, which is reportedly used by Russian soldiers as part of war zone operational planning. […] Bill Toulas Go to bleepingcomputer
-
WhatsApp’s new Advanced Chat Privacy protects sensitive messages
WhatsApp’s new Advanced Chat Privacy protects sensitive messages WhatsApp has introduced a new Advanced Chat Privacy feature to protect sensitive information exchanged in private chats and group conversations. […] Sergiu Gatlan Go to bleepingcomputer
-
Blue Shield of California leaked health data of 4.7 million members to Google
Blue Shield of California leaked health data of 4.7 million members to Google Blue Shield of California disclosed it suffered a data breach after exposing protected health information of 4.7 million members to Google’s analytics and advertisement platforms. […] Bill Toulas Go to bleepingcomputer
-
FBI: US lost record $16.6 billion to cybercrime in 2024
FBI: US lost record $16.6 billion to cybercrime in 2024 The FBI says cybercriminals have stolen a record $16,6 billion in 2024, marking an increase in losses of over 33% compared to the previous year. […] Sergiu Gatlan Go to bleepingcomputer
-
ASUS releases fix for AMI bug that lets hackers brick servers
ASUS releases fix for AMI bug that lets hackers brick servers ASUS has released security updates to address CVE-2024-54085, a maximum severity flaw that could allow attackers to hijack and potentially brick servers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes Remote Desktop freezes caused by Windows updates
Microsoft fixes Remote Desktop freezes caused by Windows updates Microsoft has resolved a known issue causing Remote Desktop sessions to freeze on Windows Server 2025 and Windows 11 24H2 devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows Server 2025 blue screen, install issues
Microsoft fixes Windows Server 2025 blue screen, install issues Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count. […] Sergiu Gatlan Go to bleepingcomputer
-
Marks & Spencer confirms a cyberattack as customers face delayed orders
Marks & Spencer confirms a cyberattack as customers face delayed orders Marks & Spencer (M&S) has disclosed that it is responding to a cyberattack over the past few days that has impacted operations, including its Click and Collect service. […] Lawrence Abrams Go to bleepingcomputer
-
Active! Mail RCE flaw exploited in attacks on Japanese orgs
Active! Mail RCE flaw exploited in attacks on Japanese orgs An Active! Mail zero-day remote code execution vulnerability is actively exploited in attacks on large organizations in Japan. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Zoom remote control feature for crypto-theft attacks
Hackers abuse Zoom remote control feature for crypto-theft attacks A hacking group dubbed ‘Elusive Comet’ targets cryptocurrency users in social engineering attacks that exploit Zoom’s remote control feature to trick users into granting them access to their machines. […] Bill Toulas Go to bleepingcomputer