Category: bleepingcomputer
-
Flickr discloses potential data breach exposing users’ names, emails
Flickr discloses potential data breach exposing users’ names, emails Photo-sharing platform Flickr is notifying users of a potential data breach after a vulnerability at a third-party email service provider exposed their real names, email addresses, IP addresses, and account activity. […] Sergiu Gatlan Go to bleepingcomputer
-
Spain’s Ministry of Science shuts down systems after breach claims
Spain’s Ministry of Science shuts down systems after breach claims Spain’s Ministry of Science (Ministerio de Ciencia) announced a partial shutdown of its IT systems, affecting several citizen- and company-facing services. […] Bill Toulas Go to bleepingcomputer
-
CISA orders federal agencies to replace end-of-life edge devices
CISA orders federal agencies to replace end-of-life edge devices The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new binding operational directive requiring federal agencies to identify and remove network edge devices that no longer receive security updates from manufacturers. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gang uses ISPsystem VMs for stealthy payload delivery
Ransomware gang uses ISPsystem VMs for stealthy payload delivery Ransomware operators are hosting and delivering malicious payloads at scale by abusing virtual machines (VMs) provisioned by ISPsystem, a legitimate virtual infrastructure management provider. […] Bill Toulas Go to bleepingcomputer
-
Microsoft to shut down Exchange Online EWS in April 2027
Microsoft to shut down Exchange Online EWS in April 2027 Microsoft announced today that the Exchange Web Services (EWS) API for Exchange Online will be shut down in April 2027, after nearly 20 years. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers compromise NGINX servers to redirect user traffic
Hackers compromise NGINX servers to redirect user traffic A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker’s backend infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Critical n8n flaws disclosed along with public exploits
Critical n8n flaws disclosed along with public exploits Multiple critical vulnerabilities in the popular n8n open-source workflow automation platform allow escaping the confines of the environment and taking complete control of the host server. […] Bill Toulas Go to bleepingcomputer
-
CISA: VMware ESXi flaw now exploited in ransomware attacks
CISA: VMware ESXi flaw now exploited in ransomware attacks CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was previously used in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA warns of five-year-old GitLab flaw exploited in attacks
CISA warns of five-year-old GitLab flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
The Double-Edged Sword of Non-Human Identities
The Double-Edged Sword of Non-Human Identities Leaked non-human identities like API keys and tokens are becoming a major breach driver in cloud environments. Flare shows how exposed machine credentials quietly grant attackers long-term access to enterprise systems. […] Sponsored by Flare Go to bleepingcomputer
-
New GlassWorm attack targets macOS via compromised OpenVSX extensions
New GlassWorm attack targets macOS via compromised OpenVSX extensions A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers exploit recently patched Microsoft Office bug in attacks
Russian hackers exploit recently patched Microsoft Office bug in attacks Ukraine’s Computer Emergency Response Team (CERT) says that Russian hackers are exploiting CVE-2026-21509, a recently patched vulnerability in multiple versions of Microsoft Office. […] Bill Toulas Go to bleepingcomputer
-
Malicious MoltBot skills used to push password-stealing malware
Malicious MoltBot skills used to push password-stealing malware More than 230 malicious packages for the personal AI assistant OpenClaw (formerly known as Moltbot and ClawdBot) have been published in less than a week on the tool’s official registry and on GitHub. […] Bill Toulas Go to bleepingcomputer
-
Mozilla announces switch to disable all Firefox AI features
Mozilla announces switch to disable all Firefox AI features In response to user feedback on AI integration, Mozilla announced today that the next Firefox release will let users disable AI features entirely or manage them individually. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: January update shutdown bug affects more Windows PCs
Microsoft: January update shutdown bug affects more Windows PCs Microsoft has confirmed that a known issue preventing some Windows 11 devices from shutting down also affects Windows 10 systems with Virtual Secure Mode (VSM) enabled. […] Sergiu Gatlan Go to bleepingcomputer
-
Exposed MongoDB instances still targeted in data extortion attacks
Exposed MongoDB instances still targeted in data extortion attacks A threat actor is targeting exposed MongoDB instances in automated data extortion attacks demanding low ransoms from owners to restore the data. […] Bill Toulas Go to bleepingcomputer
-
New Apple privacy feature limits location tracking on iPhones, iPads
New Apple privacy feature limits location tracking on iPhones, iPads Apple is introducing a new privacy feature that lets users limit the precision of location data shared with cellular networks on some iPhone and iPad models. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says you can trust ChatGPT answers, as it kicks off ads rollout preparation
OpenAI says you can trust ChatGPT answers, as it kicks off ads rollout preparation OpenAI previously confirmed that it’s testing ads in ChatGPT for free and $8 Go accounts, and now we’re seeing early signs of that rollout, at least on Android. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough OpenAI has confirmed that it’s retiring ChatGPT’s most popular model called GPT-4o and several other models, including GPT-5 Instant, GPT-5 Thinking, GPT-4.1, GPT-4.1 mini, and o4-mini. […] Mayank Parmar Go to bleepingcomputer
-
U.S. convicts ex-Google engineer for sending AI tech data to China
U.S. convicts ex-Google engineer for sending AI tech data to China A U.S. federal jury has convicted Linwei Ding, a former software engineer at Google, for stealing AI supercomputer data from his employer and secretly sharing it with Chinese tech firms. […] Bill Toulas Go to bleepingcomputer
-
Cloud storage payment scam floods inboxes with fake renewals
Cloud storage payment scam floods inboxes with fake renewals Over the past few months, a large-scale cloud storage subscription scam campaign has been targeting users worldwide with repeated emails falsely warning recipients that their photos, files, and accounts are about to be blocked or deleted due to an alleged payment failure. […] Lawrence Abrams Go to…
-
Mandiant details how ShinyHunters abuse SSO to steal cloud data
Mandiant details how ShinyHunters abuse SSO to steal cloud data Mandiant says a wave of recent ShinyHunters SaaS data-theft attacks is being fueled by targeted voice phishing (vishing) attacks and company-branded phishing sites that steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. […] Lawrence Abrams Go to bleepingcomputer
-
Crypto wallets received a record $158 billion in illicit funds last year
Crypto wallets received a record $158 billion in illicit funds last year Illegal cryptocurrency flows hit a record $158 billion in 2025, reversing a three-year trend of declining amounts from $86B in 2021 to $64B in 2024. […] Bill Toulas Go to bleepingcomputer
-
Operation Switch Off dismantles major pirate TV streaming services
Operation Switch Off dismantles major pirate TV streaming services The latest phase of the global law enforcement action resulted in seizing three industrial-scale illegal IPTV services. […] Bill Toulas Go to bleepingcomputer
-
Microsoft to disable NTLM by default in future Windows releases
Microsoft to disable NTLM by default in future Windows releases Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Outlook bug blocking access to encrypted emails
Microsoft fixes Outlook bug blocking access to encrypted emails Microsoft has fixed a known issue that prevented Microsoft 365 customers from opening encrypted emails in classic Outlook after a recent update. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5074105 update fixes boot, sign-in, and activation issues
Windows 11 KB5074105 update fixes boot, sign-in, and activation issues Microsoft has released the KB5074105 preview cumulative update for Windows 11 systems, which includes 32 changes, including fixes for sign-in, boot, and activation issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft links Windows 11 boot failures to failed December 2025 update
Microsoft links Windows 11 boot failures to failed December 2025 update Microsoft has linked recent reports of Windows 11 boot failures after installing the January 2026 updates to previously failed attempts to install the December 2025 security update, which left systems in an “improper state.” […] Lawrence Abrams Go to bleepingcomputer
-
Hugging Face abused to spread thousands of Android malware variants
Hugging Face abused to spread thousands of Android malware variants A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services. […] Bill Toulas Go to bleepingcomputer
-
Ivanti warns of two EPMM flaws exploited in zero-day attacks
Ivanti warns of two EPMM flaws exploited in zero-day attacks Ivanti has disclosed two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340, that were exploited in zero-day attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Google disrupts IPIDEA residential proxy networks fueled by malware
Google disrupts IPIDEA residential proxy networks fueled by malware IPIDEA, one of the largest residential proxy networks used by threat actors, was disrupted earlier this week by Google Threat Intelligence Group (GTIG) in collaboration with industry partners. […] Bill Toulas Go to bleepingcomputer
-
Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match
Match Group breach exposes data from Hinge, Tinder, OkCupid, and Match Match Group, the owner of multiple popular online dating services, Tinder, Match.com, Meetic, OkCupid, and Hinge, confirmed a cybersecurity incident that compromised user data. […] Bill Toulas Go to bleepingcomputer
-
Initial access hackers switch to Tsundere Bot for ransomware attacks
Initial access hackers switch to Tsundere Bot for ransomware attacks A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
Cyberattack on Polish energy grid impacted around 30 facilities
Cyberattack on Polish energy grid impacted around 30 facilities The coordinated attack on Poland’s power grid in late December targeted multiple distributed energy resource (DER) sites across the country, including combined heat and power (CHP) facilities and wind and solar dispatch systems. […] Bill Toulas Go to bleepingcomputer
-
eScan confirms update server breached to push malicious update
eScan confirms update server breached to push malicious update MicroWorld Technologies, the maker of the eScan antivirus product, has confirmed that one of its update servers was breached and used to distribute an unauthorized update later analyzed as malicious to a small subset of customers earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Viral Moltbot AI assistant raises concerns over data security
Viral Moltbot AI assistant raises concerns over data security Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials. […] Bill Toulas Go to bleepingcomputer
-
New sandbox escape flaw exposes n8n instances to RCE attacks
New sandbox escape flaw exposes n8n instances to RCE attacks Two vulnerabilities in the n8n workflow automation platform could allow attackers to fully compromise affected instances, access sensitive data, and execute arbitrary code on the underlying host. […] Bill Toulas Go to bleepingcomputer
-
OpenAI’s ChatGPT ad costs are on par with live NFL broadcasts
OpenAI’s ChatGPT ad costs are on par with live NFL broadcasts OpenAI plans to begin rolling out ads on ChatGPT in the United States if you have a free or $8 Go subscription, but the catch is that the ads could be very expensive for advertisers. […] Mayank Parmar Go to bleepingcomputer
-
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions. […] Lawrence Abrams Go to bleepingcomputer
-
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor
Chinese Mustang Panda hackers deploy infostealers via CoolClient backdoor The Chinese espionage threat group Mustang Panda has updated its CoolClient backdoor to a new variant that can steal login data from browsers and monitor the clipboard. […] Bill Toulas Go to bleepingcomputer
-
WinRAR path traversal flaw still exploited by numerous hackers
WinRAR path traversal flaw still exploited by numerous hackers Multiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for initial access and to deliver various malicious payloads. […] Bill Toulas Go to bleepingcomputer
-
Nike investigates data breach after extortion gang leaks files
Nike investigates data breach after extortion gang leaks files Nike is investigating what it described as a “potential cyber security incident” after the World Leaks ransomware gang leaked 1.4 TB of files allegedly stolen from the sportswear giant. […] Sergiu Gatlan Go to bleepingcomputer
-
New malware service guarantees phishing extensions on Chrome web store
New malware service guarantees phishing extensions on Chrome web store A new malware-as-a-service (MaaS) called ‘Stanley’ promises malicious Chrome extensions that can clear Google’s review process and publish them to the Chrome Web Store. […] Bill Toulas Go to bleepingcomputer
-
New ClickFix attacks abuse Windows App-V scripts to push malware
New ClickFix attacks abuse Windows App-V scripts to push malware A new malicious campaign mixes the ClickFix method with fake CAPTCHA and a signed Microsoft Application Virtualization (App-V) script to ultimately deliver the Amatera infostealing malware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft patches actively exploited Office zero-day vulnerability
Microsoft patches actively exploited Office zero-day vulnerability Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare misconfiguration behind recent BGP route leak
Cloudflare misconfiguration behind recent BGP route leak Cloudflare has shared more details about a recent 25-minute Border Gateway Protocol (BGP) route leak affecting IPv6 traffic, which caused measurable congestion, packet loss, and approximately 12 Gbps of dropped traffic. […] Bill Toulas Go to bleepingcomputer
-
EU launches investigation into X over Grok-generated sexual images
EU launches investigation into X over Grok-generated sexual images The European Commission is now investigating whether X properly assessed risks before deploying its Grok artificial intelligence tool, following its use to generate sexually explicit images. […] Sergiu Gatlan Go to bleepingcomputer
-
ChatGPT Temporary chat feature is getting a much-needed upgrade
ChatGPT Temporary chat feature is getting a much-needed upgrade OpenAI is testing a big upgrade for ChatGPT’s temporary chat feature. The update will allow you to retain personalization in temporary chat, and still block temporary chat from influencing your account. […] Mayank Parmar Go to bleepingcomputer
-
1Password adds pop-up warnings for suspected phishing sites
1Password adds pop-up warnings for suspected phishing sites The 1Password digital vault and password manager has added built-in protection against phishing URLs to help users identify malicious pages and prevent them from sharing account credentials with threat actors. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates Windows 11 boot failures after January updates
Microsoft investigates Windows 11 boot failures after January updates Microsoft is investigating reports that some Windows 11 devices are failing to boot with “UNMOUNTABLE_BOOT_VOLUME” errors after installing the January 2026 Patch Tuesday security updates. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft releases emergency OOB update to fix Outlook freezes
Microsoft releases emergency OOB update to fix Outlook freezes Microsoft has released emergency, out-of-band updates on Saturday for Windows 10, Windows 11, and Windows Server to fix an issue that prevented Microsoft Outlook classic from opening when using PSTs stored in cloud storage. […] Lawrence Abrams Go to bleepingcomputer
-
Sandworm hackers linked to failed wiper attack on Poland’s energy systems
Sandworm hackers linked to failed wiper attack on Poland’s energy systems A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. […] Lawrence Abrams Go to bleepingcomputer
-
Konni hackers target blockchain engineers with AI-built malware
Konni hackers target blockchain engineers with AI-built malware The North Korean hacker group Konni (Opal Sleet, TA406) is using AI-generated PowerShell malware to target developers and engineers in the blockchain sector. […] Bill Toulas Go to bleepingcomputer
-
ShinyHunters claim to be behind SSO-account data theft attacks
ShinyHunters claim to be behind SSO-account data theft attacks The ShinyHunters extortion gang claims it is behind a wave of ongoing voice phishing attacks targeting single sign-on (SSO) accounts at Okta, Microsoft, and Google, enabling threat actors to breach corporate SaaS platforms and steal company data for extortion. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious AI extensions on VSCode Marketplace steal developer data
Malicious AI extensions on VSCode Marketplace steal developer data Two malicious extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 million times, exfiltrate developer data to China-based servers. […] Bill Toulas Go to bleepingcomputer
-
CISA confirms active exploitation of four enterprise software bugs
CISA confirms active exploitation of four enterprise software bugs The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. warned of active exploitation of four vulnerabilities impacting enterprise software from Versa and Zimbra, the Vite frontend tooling framework, and the Prettier code formatter. […] Bill Toulas Go to bleepingcomputer
-
US to deport Venezuelans who emptied bank ATMs using malware
US to deport Venezuelans who emptied bank ATMs using malware South Carolina federal prosecutors announced that two Venezuelan nationals convicted of stealing hundreds of thousands of dollars from U.S. banks in an ATM jackpotting scheme will be deported after serving their sentences. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit critical telnetd auth bypass flaw to get root
Hackers exploit critical telnetd auth bypass flaw to get root A coordinated campaign has been observed targeting a recently disclosed critical-severity vulnerability that has been present in the GNU InetUtils telnetd server for 11 years. […] Bill Toulas Go to bleepingcomputer
-
Okta SSO accounts targeted in vishing-based data theft attacks
Okta SSO accounts targeted in vishing-based data theft attacks Okta is warning about custom phishing kits built specifically for voice-based social engineering (vishing) attacks. BleepingComputer has learned that these kits are being used in active attacks to steal Okta SSO credentials for data theft. […] Lawrence Abrams Go to bleepingcomputer
-
Curl ending bug bounty program after flood of AI slop reports
Curl ending bug bounty program after flood of AI slop reports The developer of the popular curl command-line utility and library announced that the project will end its HackerOne security bug bounty program at the end of this month, after being overwhelmed by low-quality AI-generated vulnerability reports. […] Lawrence Abrams Go to bleepingcomputer
-
SmarterMail auth bypass flaw now exploited to hijack admin accounts
SmarterMail auth bypass flaw now exploited to hijack admin accounts Hackers began exploiting an authentication bypass vulnerability in SmarterTools’ SmarterMail email server and collaboration tool that allows resetting admin passwords. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to add brand impersonation warnings to calls
Microsoft Teams to add brand impersonation warnings to calls Microsoft will soon add new fraud protection features to Teams calls, warning users about external callers who attempt to impersonate trusted organizations in social engineering attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
INC ransomware opsec fail allowed data recovery for 12 US orgs
INC ransomware opsec fail allowed data recovery for 12 US orgs An operational security failure allowed researchers to recover data that the INC ransomware gang stole from a dozen U.S. organizations. […] Bill Toulas Go to bleepingcomputer
-
Zendesk ticket systems hijacked in massive global spam wave
Zendesk ticket systems hijacked in massive global spam wave People worldwide are being targeted by a massive spam wave originating from unsecured Zendesk support systems, with victims reporting receiving hundreds of emails with strange and sometimes alarming subject lines. […] Lawrence Abrams Go to bleepingcomputer
-
Chainlit AI framework bugs let hackers breach cloud environments
Chainlit AI framework bugs let hackers breach cloud environments Two high-severity vulnerabilities in Chainlit, a popular open-source framework for building conversational AI applications, allow reading any file on the server and leak sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Cisco fixes Unified Communications RCE zero day exploited in attacks
Cisco fixes Unified Communications RCE zero day exploited in attacks Cisco has fixed a critical Unified Communications and Webex Calling remote code execution vulnerability, tracked as CVE-2026-20045, that has been actively exploited as a zero-day in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
New Android malware uses AI to click on hidden browser ads
New Android malware uses AI to click on hidden browser ads A new family of Android click-fraud trojans leverages TensorFlow machine learning models to automatically detect and interact with specific advertisement elements. […] Bill Toulas Go to bleepingcomputer
-
Online retailer PcComponentes says data breach claims are fake
Online retailer PcComponentes says data breach claims are fake PcComponentes, a major technology retailer in Spain, has denied claims of a data breach on its systems impacting 16 million customers, but confirmed it suffered a credential stuffing attack. […] Bill Toulas Go to bleepingcomputer
-
OpenAI’s ChatGPT Atlas browser is testing actions feature
OpenAI’s ChatGPT Atlas browser is testing actions feature Chromium-based ChatGPT Atlas browser is testing a new feature likely called “Actions,” and it can also understand videos, which is why you might see ChatGPT generating timestamps for videos. […] Mayank Parmar Go to bleepingcomputer
-
Google says Gemini won’t have ads, as ChatGPT prepares to add them
Google says Gemini won’t have ads, as ChatGPT prepares to add them OpenAI recently rolled out ads to ChatGPT in the United States if you use $8 Go subscription or a free account, but Google says it does not plan to put ads in Gemini. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI rolls out age prediction model on ChatGPT to detect your age
OpenAI rolls out age prediction model on ChatGPT to detect your age OpenAI is rolling out an age prediction model on ChatGPT to detect your age and apply possible safety-related restrictions to prevent misuse by teens. […] Mayank Parmar Go to bleepingcomputer
-
ACF plugin bug gives hackers admin on 50,000 WordPress sites
ACF plugin bug gives hackers admin on 50,000 WordPress sites A critical-severity vulnerability in the Advanced Custom Fields: Extended (ACF Extended) plugin for WordPress can be exploited remotely by unauthenticated attackers to obtain administrative permissions. […] Bill Toulas Go to bleepingcomputer
-
VoidLink cloud malware shows clear signs of being AI-generated
VoidLink cloud malware shows clear signs of being AI-generated The recently discovered cloud-focused VoidLink malware framework is believed to have been developed by a single person with the help of an artificial intelligence model. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT Go now unlocks unlimited access to GPT-5.2 Instant for $8
ChatGPT Go now unlocks unlimited access to GPT-5.2 Instant for $8 ChatGPT Go is finally worth your money, as OpenAI has almost doubled the usage limits and enabled ultimate access to GPT 5.2 Instant. […] Mayank Parmar Go to bleepingcomputer
-
You can get ChatGPT’s $20 Plus subscription for free for a limited time
You can get ChatGPT’s $20 Plus subscription for free for a limited time OpenAI is offering ChatGPT Plus, which costs $20 in the United States, for free, but the offer is valid for some accounts only, and it’s a limited-time deal. […] Mayank Parmar Go to bleepingcomputer
-
Fake ad blocker extension crashes the browser for ClickFix attacks
Fake ad blocker extension crashes the browser for ClickFix attacks A malvertising campaign is using a fake ad-blocking Chrome and Edge extension named NexShield that intentionally crashes the browser in preparation for ClickFix attacks. […] Bill Toulas Go to bleepingcomputer
-
New PDFSider Windows malware deployed on Fortune 100 firm’s network
New PDFSider Windows malware deployed on Fortune 100 firm’s network Ransomware attackers targeting a Fortune 100 company in the finance sector used a new malware strain, dubbed PDFSider, to deliver malicious payloads on Windows systems. […] Bill Toulas Go to bleepingcomputer
-
UK govt. warns about ongoing Russian hacktivist group attacks
UK govt. warns about ongoing Russian hacktivist group attacks The U.K. government is warning of continued malicious activity from Russian-aligned hacktivist groups targeting critical infrastructure and local government organizations in the country in disruptive denial-of-service (DDoS) attacks. […] Bill Toulas Go to bleepingcomputer
-
OpenAI hostname hints at a new ChatGPT feature codenamed “Sonata”
OpenAI hostname hints at a new ChatGPT feature codenamed “Sonata” OpenAI is reportedly testing a new feature or product codenamed “Sonata,” and it could be related to music or audio-related experiences on ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
New OpenAI leak hints at upcoming ChatGPT features
New OpenAI leak hints at upcoming ChatGPT features OpenAI is internally testing a new update for ChatGPT, at least on the web. It’ll begin rolling out in the coming weeks. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft releases OOB Windows updates to fix shutdown, Cloud PC bugs
Microsoft releases OOB Windows updates to fix shutdown, Cloud PC bugs Microsoft has released multiple emergency, out-of-band updates for Windows 10, Windows 11, and Windows Server to fix two issues caused by the January Patch Tuesday updates. […] Lawrence Abrams Go to bleepingcomputer
-
CIRO confirms data breach exposed info on 750,000 Canadian investors
CIRO confirms data breach exposed info on 750,000 Canadian investors The Canadian Investment Regulatory Organization (CIRO) confirmed that the data breach it suffered last year impacts about 750,000 Canadian investors. […] Bill Toulas Go to bleepingcomputer
-
Google Chrome tests Gemini-powered AI “Skills”
Google Chrome tests Gemini-powered AI “Skills” Google is testing “Skills” for Gemini in Chrome, which will allow AI in Chrome to perform tasks automatically, and it could challenge Perplexity Comet or Edge’s Copilot mode. […] Mayank Parmar Go to bleepingcomputer
-
Google Chrome now lets you turn off on-device AI model powering scam detection
Google Chrome now lets you turn off on-device AI model powering scam detection Google Chrome now lets you delete the local AI models that power the “Enhanced Protection” feature, which was upgraded with AI capabilities last year. […] Mayank Parmar Go to bleepingcomputer
-
Credential-stealing Chrome extensions target enterprise HR platforms
Credential-stealing Chrome extensions target enterprise HR platforms Malicious Chrome extensions on the Chrome Web Store masquerading as productivity and security tools for enterprise HR and ERP platforms were discovered stealing authentication credentials or blocking management pages used to respond to security incidents. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious GhostPoster browser extensions found with 840,000 installs
Malicious GhostPoster browser extensions found with 840,000 installs Another set of 17 malicious extensions linked to the GhostPoster campaign has been discovered in Chrome, Firefox, and Edge stores, where they accumulated a total of 840,000 installations. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT Go subscription rolls out worldwide at $8, but it’ll show you ads
ChatGPT Go subscription rolls out worldwide at $8, but it’ll show you ads OpenAI’s $8 ChatGPT Go subscription, which gives you 10x more messages, is now available in the United States and other regions. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI says its new ChatGPT ads won’t influence answers
OpenAI says its new ChatGPT ads won’t influence answers OpenAI has confirmed ChatGPT is getting ads in the coming weeks, but it promises that ads won’t influence answers generated by ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
StealC hackers hacked as researchers hijack malware control panels
StealC hackers hacked as researchers hijack malware control panels A cross-site scripting (XSS) flaw in the web-based control panel used by operators of the StealC info-stealing malware allowed researchers to observe active sessions and gather intelligence on the attackers’ hardware. […] Bill Toulas Go to bleepingcomputer
-
Black Basta boss makes it onto Interpol’s ‘Red Notice’ list
Black Basta boss makes it onto Interpol’s ‘Red Notice’ list The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. […] Bill Toulas Go to bleepingcomputer
-
China-linked hackers exploited Sitecore zero-day for initial access
China-linked hackers exploited Sitecore zero-day for initial access An advanced threat actor tracked as UAT-8837 and believed to be linked to China has been focusing on critical infrastructure systems in North America, gaining access by exploiting both known and zero-day vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
Cisco finally fixes AsyncOS zero-day exploited since November
Cisco finally fixes AsyncOS zero-day exploited since November Cisco finally patched a maximum-severity AsyncOS zero-day exploited in attacks targeting Secure Email Gateway (SEG) appliances since November 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Some Windows PCs fail to shut down after January update
Microsoft: Some Windows PCs fail to shut down after January update Microsoft has confirmed a new issue that prevents Windows 11 23H2 devices with System Guard Secure Launch enabled from shutting down. […] Sergiu Gatlan Go to bleepingcomputer
-
Google now lets you change your @gmail.com address, rolling out
Google now lets you change your @gmail.com address, rolling out Google has confirmed that it’s now possible to change your @gmail.com address. This means that if your current email is [email protected], you can now change it to [email protected]. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT is now more reliable at finding and remembering your past chat
ChatGPT is now more reliable at finding and remembering your past chat OpenAI is rolling out a big upgrade for ChatGPT with support for advanced chat history search, but the feature is rolling out to Plus and Pro subscribers only. […] Mayank Parmar Go to bleepingcomputer
-
Gootloader now uses 1,000-part ZIP archives for stealthy delivery
Gootloader now uses 1,000-part ZIP archives for stealthy delivery The Gootloader malware, typically used for initial access, is now using a malformed ZIP archive designed to evade detection by concatenating up to 1,000 archives. […] Bill Toulas Go to bleepingcomputer
-
FTC bans GM from selling drivers’ location data for five years
FTC bans GM from selling drivers’ location data for five years The FTC has finalized an order with General Motors, settling charges that it collected and sold the location and driving data of millions of drivers without consent. […] Sergiu Gatlan Go to bleepingcomputer
-
Palo Alto Networks warns of DoS bug letting hackers disable firewalls
Palo Alto Networks warns of DoS bug letting hackers disable firewalls Palo Alto Networks patched a high-severity vulnerability that could allow unauthenticated attackers to disable firewall protections in denial-of-service (DoS) attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft disrupts massive RedVDS cybercrime virtual desktop service
Microsoft disrupts massive RedVDS cybercrime virtual desktop service Microsoft announced on Wednesday that it disrupted RedVDS, a massive cybercrime platform linked to at least $40 million in reported losses in the United States alone since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
ChatGPT’s upcoming cross-platform feature is codenamed “Agora”
ChatGPT’s upcoming cross-platform feature is codenamed “Agora” OpenAI is internally testing a new feature called “Agora,” and it could be related to some sort of cross-platform feature that works in real time or some other new product. […] Mayank Parmar Go to bleepingcomputer