Category: bleepingcomputer
-
CyberStrikeAI tool adopted by hackers for AI-powered attacks
CyberStrikeAI tool adopted by hackers for AI-powered attacks Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet FortiGate firewalls. […] Lawrence Abrams Go to bleepingcomputer
-
Fake Google Security site uses PWA app to steal credentials, MFA codes
Fake Google Security site uses PWA app to steal credentials, MFA codes A phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker traffic through victims’ browsers. […] Ionut Ilascu Go to bleepingcomputer
-
Alabama man pleads guilty to hacking, extorting hundreds of women
Alabama man pleads guilty to hacking, extorting hundreds of women A 22-year-old Alabama man pleaded guilty to extortion, cyberstalking, and computer fraud charges after hijacking the social media accounts of hundreds of young women (including minors). […] Sergiu Gatlan Go to bleepingcomputer
-
ClawJacked attack let malicious websites hijack OpenClaw to steal data
ClawJacked attack let malicious websites hijack OpenClaw to steal data Security researchers have disclosed a high-severity vulnerability dubbed “ClawJacked” in the popular AI agent OpenClaw that allowed a malicious website to silently bruteforce access to a locally running instance and take control over it. […] Lawrence Abrams Go to bleepingcomputer
-
Samsung TVs to stop collecting Texans’ data without express consent
Samsung TVs to stop collecting Texans’ data without express consent Samsung and the State of Texas have reached a settlement agreement over the alleged unlawful collection of content-viewing information through its smart TVs […] Bill Toulas Go to bleepingcomputer
-
QuickLens Chrome extension steals crypto, shows ClickFix attack
QuickLens Chrome extension steals crypto, shows ClickFix attack A Chrome extension named “QuickLens – Search Screen with Google Lens” has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users. […] Lawrence Abrams Go to bleepingcomputer
-
$4.8M in crypto stolen after Korean tax agency exposes wallet seed
$4.8M in crypto stolen after Korean tax agency exposes wallet seed South Korea’s National Tax Service accidentally exposed the mnemonic recovery phrase of a seized cryptocurrency wallet in an official press release, allowing hackers to steal 6.4 billion won ($4.8M) worth in cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
Microsoft testing Windows 11 batch file security improvements
Microsoft testing Windows 11 batch file security improvements Microsoft is rolling out new Windows 11 Insider Preview builds that improve security and performance during batch file or CMD script execution. […] Sergiu Gatlan Go to bleepingcomputer
-
APT37 hackers use new malware to breach air-gapped networks
APT37 hackers use new malware to breach air-gapped networks North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance. […] Bill Toulas Go to bleepingcomputer
-
Europol-led crackdown on The Com hackers leads to 30 arrests
Europol-led crackdown on The Com hackers leads to 30 arrests A yearlong Europol-coordinated operation dubbed “Project Compass” has led to 30 arrests and 179 suspects being tied to “The Com,” an online cybercrime collective that targets children and teenagers. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA warns that RESURGE malware can be dormant on Ivanti devices
CISA warns that RESURGE malware can be dormant on Ivanti devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new details about RESURGE, a malicious implant used in zero-day attacks exploiting CVE-2025-0282 to breach Ivanti Connect Secure devices. […] Bill Toulas Go to bleepingcomputer
-
Third-Party Patching and the Business Footprint We All Share
Third-Party Patching and the Business Footprint We All Share Everyday tools like PDF readers, email clients, and archive utilities quietly define the real attack surface. Action1 explains how third-party software drift increases exploit risk and why consistent patching reduces exposure across endpoints. […] Sponsored by Action1 Go to bleepingcomputer
-
Previously harmless Google API keys now expose Gemini AI data
Previously harmless Google API keys now expose Gemini AI data Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data. […] Bill Toulas Go to bleepingcomputer
-
Trend Micro warns of critical Apex One code execution flaws
Trend Micro warns of critical Apex One code execution flaws Trend Micro has patched two critical Apex One vulnerabilities that allow attackers to gain remote code execution (RCE) on vulnerable Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
European DYI chain ManoMano data breach impacts 38 million customers
European DYI chain ManoMano data breach impacts 38 million customers DIY store chain ManoMano is notifying customers of a data breach personal data, which was caused by hackers compromising a third-party service provider. […] Bill Toulas Go to bleepingcomputer
-
Critical Juniper Networks PTX flaw allows full router takeover
Critical Juniper Networks PTX flaw allows full router takeover A critical vulnerability in the Junos OS Evolved network operating system running on PTX Series routers from Juniper Networks could allow an unauthenticated attacker to execute code remotely with root privileges. […] Bill Toulas Go to bleepingcomputer
-
Olympique Marseille confirms ‘attempted’ cyberattack after data leak
Olympique Marseille confirms ‘attempted’ cyberattack after data leak French professional football club Olympique de Marseille has confirmed a cyberattack after a threat actor claimed on Monday that it breached the club’s systems earlier this month. […] Sergiu Gatlan Go to bleepingcomputer
-
Medical device maker UFP Technologies warns of data stolen in cyberattack
Medical device maker UFP Technologies warns of data stolen in cyberattack American manufacturer of medical devices, UFP Technologies, has disclosed that a cybersecurity incident has compromised its IT systems and data. […] Bill Toulas Go to bleepingcomputer
-
Fake Next.js job interview tests backdoor developer’s devices
Fake Next.js job interview tests backdoor developer’s devices The Microsoft Defender team has discovered a coordinated campaign targeting software developers through malicious repositories posing as legitimate Next.js projects and technical assessment materials, including recruiting coding tests. […] Bill Toulas Go to bleepingcomputer
-
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023 Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks. […] Lawrence Abrams Go to bleepingcomputer
-
Chinese cyberspies breached dozens of telecom firms, govt agencies
Chinese cyberspies breached dozens of telecom firms, govt agencies Google’s Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a global espionage campaign attributed to a suspected Chinese threat actor that used SaaS API calls to hide malicious traffic in attacks targeting telecom and government networks. […] Bill Toulas Go to bleepingcomputer
-
Marquis sues SonicWall over backup breach that led to ransomware attack
Marquis sues SonicWall over backup breach that led to ransomware attack Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. […] Bill Toulas Go to bleepingcomputer
-
Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker
Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker The former head of Trenchant, a specialized U.S. defense contractor unit, was sentenced Tuesday to more than seven years in federal prison for stealing and selling zero-day exploits to a Russian exploit broker whose clients include the Russian government. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool
Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool Microsoft has released the KB5077241 optional cumulative update for Windows 11, which comes with 29 changes, including improvements to BitLocker, a new network speed test tool, and native System Monitor (Sysmon) functionality. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing campaign targets freight and logistics orgs in the US, Europe
Phishing campaign targets freight and logistics orgs in the US, Europe A financially motivated threat group dubbed “Diesel Vortex” is stealing credentials from freight and logistics operators in the U.S. and Europe in phishing attacks using 52 domains. […] Bill Toulas Go to bleepingcomputer
-
Wynn Resorts confirms employee data breach after extortion threat
Wynn Resorts confirms employee data breach after extortion threat Wynn Resorts has confirmed that a hacker stole employee data from its systems after the company was listed on the ShinyHunters extortion gang’s data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
1Campaign platform helps malicious Google ads evade detection
1Campaign platform helps malicious Google ads evade detection A newly identified cybercrime service known as 1Campaign is enabling threat actors to run malicious Google Ads that remain online for extended periods while evading scrutiny from security researchers. […] Bill Toulas Go to bleepingcomputer
-
Android mental health apps with 14.7M installs filled with security flaws
Android mental health apps with 14.7M installs filled with security flaws Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information. […] Ionut Ilascu Go to bleepingcomputer
-
Spain arrests suspected hacktivists for DDoSing govt sites
Spain arrests suspected hacktivists for DDoSing govt sites Spanish authorities have arrested four alleged members of a hacktivist group believed to have carried out cyberattacks targeting government ministries, political parties, and various public institutions. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says bug in classic Outlook hides the mouse pointer
Microsoft says bug in classic Outlook hides the mouse pointer Microsoft is investigating a known issue that causes the mouse pointer to disappear in the classic Outlook desktop email client for some users. […] Sergiu Gatlan Go to bleepingcomputer
-
Ad tech firm Optimizely confirms data breach after vishing attack
Ad tech firm Optimizely confirms data breach after vishing attack New York-based ad tech company Optimizely has notified an undisclosed number of customers of a data breach after threat actors compromised some of its systems in a voice phishing attack. […] Sergiu Gatlan Go to bleepingcomputer
-
When identity isn’t the weak link, access still is
When identity isn’t the weak link, access still is Stolen tokens and compromised devices let attackers reuse trust without breaking authentication. Specops Software explains why identity alone isn’t enough and how continuous device verification strengthens Zero Trust. […] Sponsored by Specops Software Go to bleepingcomputer
-
Arkanix Stealer pops up as short-lived AI info-stealer experiment
Arkanix Stealer pops up as short-lived AI info-stealer experiment An information-stealing malware operation named Arkanix Stealer, promoted on multiple dark web forums towards the end of 2025, was likely developed as an AI-assisted experiment. […] Bill Toulas Go to bleepingcomputer
-
Predator spyware hooks iOS SpringBoard to hide mic, camera activity
Predator spyware hooks iOS SpringBoard to hide mic, camera activity Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. […] Bill Toulas Go to bleepingcomputer
-
Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks
Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks Amazon is warning that a Russian-speaking hacker used multiple generative AI services as part of a campaign that breached more than 600 FortiGate firewalls across 55 countries in five weeks. […] Lawrence Abrams Go to bleepingcomputer
-
Japanese tech giant Advantest hit by ransomware attack
Japanese tech giant Advantest hit by ransomware attack Advantest Corporation disclosed that its corporate network has been targeted in a ransomware attack that may have affected customer or employee data. […] Bill Toulas Go to bleepingcomputer
-
CISA: BeyondTrust RCE flaw now exploited in ransomware attacks
CISA: BeyondTrust RCE flaw now exploited in ransomware attacks Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns. […] Bill Toulas Go to bleepingcomputer
-
Data breach at French bank registry impacts 1.2 million accounts
Data breach at French bank registry impacts 1.2 million accounts The French Ministry of Finance has published an announcement informing of a cybersecurity incident that has impacted 1.2 million accounts. […] Bill Toulas Go to bleepingcomputer
-
Why the shift left dream has become a nightmare for security and developers
Why the shift left dream has become a nightmare for security and developers The “shift left” approach has increased pressure on developers, as speed demands override security checks in modern CI pipelines. Qualys explains how analyzing 34,000 public container images revealed 7.3% were malicious and why security must be enforced at the infrastructure layer by…
-
PayPal discloses data breach that exposed user info for 6 months
PayPal discloses data breach that exposed user info for 6 months PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukrainian gets 5 years for helping North Koreans infiltrate US firms
Ukrainian gets 5 years for helping North Koreans infiltrate US firms A Ukrainian national was sentenced to five years in prison for providing North Korean IT workers with stolen identities that helped them infiltrate U.S. companies. […] Sergiu Gatlan Go to bleepingcomputer
-
PromptSpy is the first known Android malware to use generative AI at runtime
PromptSpy is the first known Android malware to use generative AI at runtime Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google’s Gemini model to adapt its persistence across different devices. […] Lawrence Abrams Go to bleepingcomputer
-
Flaw in Grandstream VoIP phones allows stealthy eavesdropping
Flaw in Grandstream VoIP phones allows stealthy eavesdropping A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications. […] Bill Toulas Go to bleepingcomputer
-
Google blocked over 1.75 million Play Store app submissions in 2025
Google blocked over 1.75 million Play Store app submissions in 2025 Google says that through 2025, it blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data and rejected over 1.75 million apps from being published on Google Play due to policy violations. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Dell flaw within 3 days
CISA orders feds to patch actively exploited Dell flaw within 3 days The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems within three days against a maximum-severity Dell vulnerability that has been under active exploitation since mid-2024. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking. […] Bill Toulas Go to bleepingcomputer
-
AI platforms can be abused for stealthy malware communication
AI platforms can be abused for stealthy malware communication AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabilities can be abused to intermediate command-and-control (C2) activity. […] Bill Toulas Go to bleepingcomputer
-
Telegram channels expose rapid weaponization of SmarterMail flaws
Telegram channels expose rapid weaponization of SmarterMail flaws Underground Telegram channels shared SmarterMail exploit PoCs and stolen admin credentials within days of disclosure. Flare explains how monitoring these communities reveals rapid weaponization of CVE-2026-24423 and CVE-2026-23760 tied to ransomware activity. […] Sponsored by Flare Go to bleepingcomputer
-
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages Microsoft says an Exchange Online issue that mistakenly quarantined legitimate emails last week was triggered by faulty heuristic detection rules designed to block credential phishing campaigns. […] Sergiu Gatlan Go to bleepingcomputer
-
Data breach at fintech firm Figure affects nearly 1 million accounts
Data breach at fintech firm Figure affects nearly 1 million accounts Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company. […] Sergiu Gatlan Go to bleepingcomputer
-
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches. […] Bill Toulas Go to bleepingcomputer
-
Flaws in popular VSCode extensions expose developers to attacks
Flaws in popular VSCode extensions expose developers to attacks Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely. […] Bill Toulas Go to bleepingcomputer
-
Chinese hackers exploiting Dell zero-day flaw since mid-2024
Chinese hackers exploiting Dell zero-day flaw since mid-2024 A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024. […] Sergiu Gatlan Go to bleepingcomputer
-
Notepad++ boosts update security with ‘double-lock’ mechanism
Notepad++ boosts update security with ‘double-lock’ mechanism Notepad++ has adopted a “double-lock” design for its update mechanism to address recently exploited security gaps that resulted in a supply-chain compromise. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams outage affects users in United States, Europe
Microsoft Teams outage affects users in United States, Europe Microsoft is working to resolve an ongoing outage affecting Microsoft Teams users, causing delays and preventing some from accessing the service. […] Sergiu Gatlan Go to bleepingcomputer
-
Ireland now also investigating X over Grok-made sexual images
Ireland now also investigating X over Grok-made sexual images Ireland’s Data Protection Commission (DPC), the country’s data protection authority, has opened a formal investigation into X over the use of the platform’s Grok artificial intelligence tool to generate non-consensual sexual images of real people, including children. […] Sergiu Gatlan Go to bleepingcomputer
-
Washington Hotel in Japan discloses ransomware infection incident
Washington Hotel in Japan discloses ransomware infection incident The Washington Hotel brand in Japan has announced that that its servers were compromised in a ransomware attack, exposing various business data. […] Bill Toulas Go to bleepingcomputer
-
Eurail says stolen traveler data now up for sale on dark web
Eurail says stolen traveler data now up for sale on dark web Eurail B.V., the operator that provides access to 250,000 kilometers of European railways, confirmed that data stolen in a breach earlier this year is being offered for sale on the dark web. […] Bill Toulas Go to bleepingcomputer
-
Man arrested for demanding reward after accidental police data leak
Man arrested for demanding reward after accidental police data leak Dutch authorities arrested a 40-year-old man after he downloaded confidential documents that had been mistakenly shared by the police and refused to delete them unless he received “something in return.” […] Sergiu Gatlan Go to bleepingcomputer
-
Infostealer malware found stealing OpenClaw secrets for first time
Infostealer malware found stealing OpenClaw secrets for first time With the massive adoption of the OpenClaw agentic AI assistant, information-stealing malware has been spotted stealing files associated with the framework that contain API keys, authentication tokens, and other secrets. […] Bill Toulas Go to bleepingcomputer
-
Google patches first Chrome zero-day exploited in attacks this year
Google patches first Chrome zero-day exploited in attacks this year Google has released emergency updates to fix a high-severity Chrome vulnerability exploited in zero-day attacks, marking the first such security flaw patched since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Canada Goose investigating as hackers leak 600K customer records
Canada Goose investigating as hackers leak 600K customer records ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of…
-
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware, making this the first known use of DNS as a channel in these campaigns. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5077181 fixes boot failures linked to failed updates
Windows 11 KB5077181 fixes boot failures linked to failed updates Microsoft says it has resolved a Windows 11 bug that caused some commercial systems to fail to boot with an “UNMOUNTABLE_BOOT_VOLUME” error after installing recent security updates, with the fix delivered in the February 2026 Patch Tuesday update. […] Lawrence Abrams Go to bleepingcomputer
-
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups CTM360 reports 4,000+ malicious Google Groups and 3,500+ Google-hosted URLs used to spread the Lumma Stealer infostealing malware and a trojanized “Ninja Browser.” The report details how attackers abuse trusted Google services to steal credentials and maintain persistence across Windows and Linux systems. […]…
-
One threat actor responsible for 83% of recent Ivanti RCE attacks
One threat actor responsible for 83% of recent Ivanti RCE attacks Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. […] Bill Toulas Go to bleepingcomputer
-
Snail mail letters target Trezor and Ledger users in crypto-theft attacks
Snail mail letters target Trezor and Ledger users in crypto-theft attacks Threat actors are sending physical letters pretending to be from Trezor and Ledger, makers of cryptocurrency hardware wallets, to trick users into submitting recovery phrases in crypto theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Fake job recruiters hide malware in developer coding challenges
Fake job recruiters hide malware in developer coding challenges A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. […] Bill Toulas Go to bleepingcomputer
-
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. […] Bill Toulas Go to bleepingcomputer
-
Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches
Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches South Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more than 5.5 million customers. […] Bill Toulas Go to…
-
Turning IBM QRadar Alerts into Action with Criminal IP
Turning IBM QRadar Alerts into Action with Criminal IP Criminal IP now integrates with IBM QRadar SIEM and SOAR to bring external IP-based threat intelligence directly into detection and response workflows. See how risk scoring and automated enrichment help SOC teams prioritize high-risk IPs and accelerate investigations without leaving QRadar. […] Sponsored by Criminal IP…
-
CISA flags critical Microsoft SCCM flaw as exploited in attacks
CISA flags critical Microsoft SCCM flaw as exploited in attacks CISA ordered federal agencies on Thursday to secure their systems against a critical Microsoft Configuration Manager vulnerability patched in October 2024 and now exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes bug that blocked Google Chrome from launching
Microsoft fixes bug that blocked Google Chrome from launching Microsoft has fixed a known issue causing its Family Safety parental control service to block Windows users from launching Google Chrome and other web browsers. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia tries to block WhatsApp, Telegram in communication blockade
Russia tries to block WhatsApp, Telegram in communication blockade The Russian government is attempting to block WhatsApp in the country as its crackdown on communication platforms not under its control intensifies. […] Bill Toulas Go to bleepingcomputer
-
Bitwarden introduces ‘Cupid Vault’ for secure password sharing
Bitwarden introduces ‘Cupid Vault’ for secure password sharing Bitwarden has launched a new system called ‘Cupid Vault’ that allows users to safely share passwords with trusted email addresses. […] Bill Toulas Go to bleepingcomputer
-
Critical BeyondTrust RCE flaw now exploited in attacks, patch now
Critical BeyondTrust RCE flaw now exploited in attacks, patch now A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access appliances is now being exploited in attacks after a PoC was published online. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: New Windows LNK spoofing issues aren’t vulnerabilities
Microsoft: New Windows LNK spoofing issues aren’t vulnerabilities Today, at Wild West Hackin’ Fest, security researcher Wietze Beukema disclosed multiple vulnerabilities in Windows LK shortcut files that allow attackers to deploy malicious payloads. […] Sergiu Gatlan Go to bleepingcomputer
-
Google says hackers are abusing Gemini AI for all attacks stages
Google says hackers are abusing Gemini AI for all attacks stages Google Threat Intelligence Group (GTIG) has published a new report warning about AI model extraction/distillation attacks, in which private-sector firms and researchers use legitimate API access to systematically probe models and replicate their logic and reasoning. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 Notepad flaw let files execute silently via Markdown links
Windows 11 Notepad flaw let files execute silently via Markdown links Microsoft has fixed a “remote code execution” vulnerability in Windows 11 Notepad that allowed attackers to execute local or remote programs by tricking users into clicking specially crafted Markdown links, without displaying any Windows security warnings. […] Lawrence Abrams Go to bleepingcomputer
-
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks Apple has released security updates to fix a zero-day vulnerability that was exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts
Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts The AgreeTo add-in for Outlook has been hijacked and turned into a phishing kit that stole more than 4,000 Microsoft account credentials. […] Bill Toulas Go to bleepingcomputer
-
Crazy ransomware gang abuses employee monitoring tool in attacks
Crazy ransomware gang abuses employee monitoring tool in attacks A member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft releases Windows 11 26H1 for select and upcoming CPUs
Microsoft releases Windows 11 26H1 for select and upcoming CPUs Microsoft has announced Windows 11 26H1, but it’s not for existing PCs. Instead, it will ship on devices with Snapdragon X2 processors and possibly other rumored ARM chips.w […] Mayank Parmar Go to bleepingcomputer
-
New Linux botnet SSHStalker uses old-school IRC for C2 comms
New Linux botnet SSHStalker uses old-school IRC for C2 comms A newly documented Linux botnet named SSHStalker is using the IRC (Internet Relay Chat) communication protocol for command-and-control (C2) operations. […] Bill Toulas Go to bleepingcomputer
-
North Korean hackers use new macOS malware in crypto-theft attacks
North Korean hackers use new macOS malware in crypto-theft attacks North Korean hackers are running tailored campaigns using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5075912 extended security update
Microsoft releases Windows 10 KB5075912 extended security update Microsoft has released the Windows 10 KB5075912 extended security update to fix February 2026 Patch Tuesday vulnerabilities, including six zero-days, and continue rolling out replacements for expiring Secure Boot certificates. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious 7-Zip site distributes installer laced with proxy tool
Malicious 7-Zip site distributes installer laced with proxy tool A fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user’s computer into a residential proxy node. […] Bill Toulas Go to bleepingcomputer
-
Fugitive behind $73M ‘pig butchering’ scheme gets 20 years in prison
Fugitive behind $73M ‘pig butchering’ scheme gets 20 years in prison A dual Chinese and St. Kitts and Nevis national was sentenced to 20 years in prison in absentia for his role in an international cryptocurrency investment scheme (also known as pig butchering or romance baiting) that defrauded victims of more than $73 million. […]…
-
Chinese cyberspies breach Singapore’s four largest telcos
Chinese cyberspies breach Singapore’s four largest telcos The Chinese threat actor tracked as UNC3886 breached Singapore’s four largest telecommunication service providers, Singtel, StarHub, M1, and Simba, at least once last year. […] Bill Toulas Go to bleepingcomputer
-
Hackers breach SmarterTools network using flaw in its own software
Hackers breach SmarterTools network using flaw in its own software SmarterTools confirmed last week that the Warlock ransomware gang breached its network after compromising an email system, but did not impact business applications or account data. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks Hackers are now exploiting SolarWinds Web Help Desk (WHD) vulnerabilities to gain code execution rights on exposed systems and deploy legitimate tools, including the Velociraptor forensics tools, for persistence and remote control. […] Bill Toulas Go to bleepingcomputer
-
Password guessing without AI: How attackers build targeted wordlists
Password guessing without AI: How attackers build targeted wordlists Attackers don’t need AI to crack passwords, they build targeted wordlists from an organization’s own public language. This article explains how tools like CeWL turn websites into high-success password guesses and why complexity rules alone fall short. […] Sponsored by Specops Software Go to bleepingcomputer
-
European Commission discloses breach that exposed staff data
European Commission discloses breach that exposed staff data The European Commission is investigating a breach after finding evidence that its mobile device management platform was hacked. […] Sergiu Gatlan Go to bleepingcomputer
-
New tool blocks imposter attacks disguised as safe commands
New tool blocks imposter attacks disguised as safe commands A new open-source and cross-platform tool called Tirith can detect homoglyph attacks over command-line environments by analyzing URLs in typed commands and stopping their execution. […] Bill Toulas Go to bleepingcomputer
-
State actor targets 155 countries in ‘Shadow Campaigns’ espionage op
State actor targets 155 countries in ‘Shadow Campaigns’ espionage op A new state-aligned cyberespionage threat group tracked as TGR-STA-1030/UNC6619, has conducted a global-scale operation dubbed the “Shadow Campaigns,” where it targeted government infrastructure in 155 countries. […] Bill Toulas Go to bleepingcomputer
-
Payments platform BridgePay confirms ransomware attack behind outage
Payments platform BridgePay confirms ransomware attack behind outage A major U.S. payment gateway and solutions provider says a ransomware attack has knocked key systems offline, triggering a widespread outage affecting multiple services. The incident began on Friday and quickly escalated into a nationwide disruption across BridgePay’s platform. […] Ax Sharma Go to bleepingcomputer
-
Germany warns of Signal account hijacking targeting senior figures
Germany warns of Signal account hijacking targeting senior figures Germany’s domestic intelligence agency is warning of suspected state-sponsored threat actors targeting high-ranking individuals in phishing attacks via messaging apps like Signal. […] Bill Toulas Go to bleepingcomputer
-
DKnife Linux toolkit hijacks router traffic to spy, deliver malware
DKnife Linux toolkit hijacks router traffic to spy, deliver malware A newly discovered toolkit called DKnife has been used since 2019 to hijack traffic at the edge-device level and deliver malware in espionage campaigns. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of SmarterMail RCE flaw used in ransomware attacks
CISA warns of SmarterMail RCE flaw used in ransomware attacks The Cybersecurity & Infrastructure Security Agency (CISA) in the U.S. has issued a warning about CVE-2026-24423, an unauthenticated remote code execution (RCE) flaw in SmarterMail that is used in ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
EDR, Email, and SASE Miss This Entire Class of Browser Attacks
EDR, Email, and SASE Miss This Entire Class of Browser Attacks Many modern attacks happen entirely inside the browser, leaving little evidence for traditional security tools. Keep Aware shows why EDR, email, and SASE miss browser-only attacks and how visibility changes prevention. […] Sponsored by Keep Aware Go to bleepingcomputer