Category: Security
-
Critical ServiceNow code execution flaw now exploited in attacks
Critical ServiceNow code execution flaw now exploited in attacks Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse ViPNet software to target Russian govt agencies
Hackers abuse ViPNet software to target Russian govt agencies An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […] Bill Toulas Go to bleepingcomputer
-
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
WordPress Core “wp2shell” RCE flaws get public exploits, patch now Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft warns of surge in ACR Stealer attacks on customers Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […] Bill Toulas Go to bleepingcomputer
-
The Future of Age Verification: Your Face Never Leaves Your Device
The Future of Age Verification: Your Face Never Leaves Your Device As age verification laws expand worldwide, organizations face growing pressure to protect users’ privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. […] Sponsored by Incode Go…
-
Abbott probes two cyber incidents amid extortion claims
Abbott probes two cyber incidents amid extortion claims Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. […] Lawrence Abrams Go to bleepingcomputer
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […] Bill Toulas Go to bleepingcomputer
-
Ernst & Young discloses data breach after support system hack
Ernst & Young discloses data breach after support system hack Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […] Bill Toulas Go to bleepingcomputer
-
Inside the Search for “Clean” Residential Proxies for Carding
Inside the Search for “Clean” Residential Proxies for Carding Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. […] Sponsored by Flare Go to bleepingcomputer
-
New Windows LegacyHive zero-day gives hackers admin privileges
New Windows LegacyHive zero-day gives hackers admin privileges A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges two over laundering $43 million from investment fraud
US charges two over laundering $43 million from investment fraud U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA urges immediate action on actively exploited Fortinet flaws
CISA urges immediate action on actively exploited Fortinet flaws CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickLock macOS malware traps users into revealing login password
New ClickLock macOS malware traps users into revealing login password A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […] Bill Toulas Go to bleepingcomputer
-
Coca-Cola says Fairlife ransomware attack halts US dairy production
Coca-Cola says Fairlife ransomware attack halts US dairy production The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
Dutch police bust investment fraud ring stealing over €100 million
Dutch police bust investment fraud ring stealing over €100 million The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. […] Bill Toulas Go to bleepingcomputer
-
Zoom warns of critical account takeover vulnerability
Zoom warns of critical account takeover vulnerability Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […] Bill Toulas Go to bleepingcomputer
-
Google Gemini CLI abused as a hacking agent, malware botnet operator
Google Gemini CLI abused as a hacking agent, malware botnet operator A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […] Bill Toulas Go to bleepingcomputer
-
AsyncAPI npm packages infected with credential-stealing malware
AsyncAPI npm packages infected with credential-stealing malware Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. […] Bill Toulas Go to bleepingcomputer
-
We built a vulnerability vending machine: AI tokens in, zero-days out
We built a vulnerability vending machine: AI tokens in, zero-days out Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. […] Sponsored by…
-
CISA warns admins to patch actively exploited SharePoint flaws
CISA warns admins to patch actively exploited SharePoint flaws The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […] Sergiu Gatlan Go to bleepingcomputer
-
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […] Lawrence Abrams Go to bleepingcomputer
-
US charges alleged operators of Russian bulletproof hosting service
US charges alleged operators of Russian bulletproof hosting service U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Spanish Police take down €140 million cyber fraud ring, arrest four
Spanish Police take down €140 million cyber fraud ring, arrest four The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. […] Bill Toulas Go to bleepingcomputer
-
US sanctions VPN, malware providers for enabling ransomware attacks
US sanctions VPN, malware providers for enabling ransomware attacks The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
Japan’s largest taxi operator shuts systems after cyberattack
Japan’s largest taxi operator shuts systems after cyberattack Japan’s largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Hackers backdoor Jscrambler npm package with infostealer malware
Hackers backdoor Jscrambler npm package with infostealer malware The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. […] Bill Toulas Go to bleepingcomputer
-
New CrashStealer malware poses as Apple crash reporting tool
New CrashStealer malware poses as Apple crash reporting tool A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of actively exploited RCE flaws in Joomla extensions
CISA warns of actively exploited RCE flaws in Joomla extensions The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. […] Bill Toulas Go to bleepingcomputer
-
US and allies warn of Russian critical infrastructure attacks
US and allies warn of Russian critical infrastructure attacks Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. […] Sergiu Gatlan Go to bleepingcomputer
-
RedHook Android malware now uses Wireless ADB for shell access
RedHook Android malware now uses Wireless ADB for shell access A new version of the RedHook Android malware abuses the Android Wireless Debugging (Wireless ADB) mechanism in a novel way to gain shell-level privileges without requiring a computer connection. […] Bill Toulas Go to bleepingcomputer
-
Australia warns of global campaign targeting vulnerable CMS platforms
Australia warns of global campaign targeting vulnerable CMS platforms The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. […] Bill Toulas Go to bleepingcomputer
-
‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets
‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets A PNG hiding a prompt injection could steal your repo’s secrets, researchers demonstrate. The technique, dubbed ‘Ghostcommit,’ slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo’s .env and…
-
New U-Boot flaws could enable stealthy firmware attacks
New U-Boot flaws could enable stealthy firmware attacks Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. […] Lawrence Abrams Go to bleepingcomputer
-
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems. […] Bill Toulas Go to bleepingcomputer
-
Police suspects Dutch hackers were involved in Odido breach
Police suspects Dutch hackers were involved in Odido breach The Dutch National Police (Politie) says it has found “strong indications” that Dutch hackers have been involved in a February breach at the telecommunications provider Odido. […] Sergiu Gatlan Go to bleepingcomputer
-
Progress urges ShareFile admins to shut down servers over “credible” threat
Progress urges ShareFile admins to shut down servers over “credible” threat Progress Software is emailing ShareFile customers who use Storage Zone Controllers to immediately shut down their servers after identifying what it describes as a “credible external security threat” targeting the on-premises secure file-sharing software. […] Lawrence Abrams Go to bleepingcomputer
-
Former ransomware negotiator gets 4 years for BlackCat attacks
Former ransomware negotiator gets 4 years for BlackCat attacks A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenMandriva Linux says contributor tried to sabotage the project
OpenMandriva Linux says contributor tried to sabotage the project The OpenMandriva Linux project announced that it was the target of an attempted act of internal sabotage after a dispute among contributors. […] Bill Toulas Go to bleepingcomputer
-
Injective SDK on npm infected with cryptocurrency wallet stealer
Injective SDK on npm infected with cryptocurrency wallet stealer Hackers compromised the Injective Labs SDK project’s GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases. […] Bill Toulas Go to bleepingcomputer
-
New Helix vishing group emerges in SharePoint data theft attacks
New Helix vishing group emerges in SharePoint data theft attacks A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to steal data from SharePoint environments. […] Bill Toulas Go to bleepingcomputer
-
Microsoft expects more Windows security updates from AI-discovered flaws
Microsoft expects more Windows security updates from AI-discovered flaws Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. […] Lawrence Abrams Go to bleepingcomputer
-
Police arrests 5,800 suspects in global anti-fraud crackdown
Police arrests 5,800 suspects in global anti-fraud crackdown Law enforcement agencies have arrested 5,811 suspects and seized $293 million in illicit assets in a global anti-fraud operation spanning 97 countries. […] Sergiu Gatlan Go to bleepingcomputer
-
AssuranceAmerica data breach exposes records of 6.9 million drivers
AssuranceAmerica data breach exposes records of 6.9 million drivers American insurance company AssuranceAmerica has disclosed a data breach impacting nearly 7 million drivers after attackers gained access to its systems earlier this year. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft patches RoguePlanet Defender zero-day vulnerability Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesday. […] Sergiu Gatlan Go to bleepingcomputer
-
Mount Royal University confirms breach as hackers claim attack
Mount Royal University confirms breach as hackers claim attack Mount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university’s network. […] Bill Toulas Go to bleepingcomputer
-
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials Malicious packages on the Node Package Manager (npm) and the Python Package Index (PyPI) delivered stealer malware to developers and users of Paysafe, Skrill, and Neteller payment applications. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to prioritize patching Langflow auth bypass flaw
CISA orders feds to prioritize patching Langflow auth bypass flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until Friday to patch an actively exploited vulnerability in the Langflow visual framework for building AI agents. […] Sergiu Gatlan Go to bleepingcomputer
-
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti warns of new max severity UniFi OS vulnerability Ubiquiti has released security updates to patch seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw that can be exploited in command injection attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA orders feds to patch max severity ColdFusion flaw by Friday
CISA orders feds to patch max severity ColdFusion flaw by Friday The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch an actively exploited maximum-severity flaw in the Adobe ColdFusion commercial web app development platform by Friday. […] Sergiu Gatlan Go to bleepingcomputer
-
Accenture confirms breach after hacker offers stolen data for sale
Accenture confirms breach after hacker offers stolen data for sale IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. […] Lawrence Abrams Go to bleepingcomputer
-
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers develop LONGLEASH malware to expand ORB network Chinese hackers tracked as ‘UAT-7810’ are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. […] Bill Toulas Go to bleepingcomputer
-
BeyondTrust warns of critical flaws in remote access software
BeyondTrust warns of critical flaws in remote access software BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing poses as big-brand job interview to steal Google accounts
Phishing poses as big-brand job interview to steal Google accounts A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals. […] Ionut Ilascu Go to bleepingcomputer
-
Fake IT support calls on Microsoft Teams push EtherRAT malware
Fake IT support calls on Microsoft Teams push EtherRAT malware Threat actors are abusing Microsoft Teams voice calls by impersonating corporate IT support staff to trick employees into installing the EtherRAT malware, giving attackers initial access to corporate networks. […] Lawrence Abrams Go to bleepingcomputer
-
Flipper Zero firmware development continues with community help
Flipper Zero firmware development continues with community help Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. […] Bill Toulas Go to bleepingcomputer
-
JadePuffer ransomware used AI agent to automate entire attack
JadePuffer ransomware used AI agent to automate entire attack Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent. […] Bill Toulas Go to bleepingcomputer
-
NetNut proxy network disrupted, 2 million infected devices cut off
NetNut proxy network disrupted, 2 million infected devices cut off A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes. […] Ionut Ilascu Go to bleepingcomputer
-
ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit
ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit A new phishing-as-a-service (PhaaS) platform dubbed “ARToken” appears to operate as an affiliate of the EvilTokens phishing platform, giving researchers a glimpse into an extensive toolkit designed to compromise Microsoft 365. […] Lawrence Abrams Go to bleepingcomputer
-
Swimming Pools, Pee, and Trying to Delete Your Data From the Internet
Swimming Pools, Pee, and Trying to Delete Your Data From the Internet I can’t recall if someone else originally came up with this saying or if I said it in some off-the-cuff comment and it just propagated, but since it’s often attributed back to me, I’ll relay it here regardless: Trying to delete yourself from…
-
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. […] Sponsored by Huntress Labs Go to bleepingcomputer
-
Alleged Scattered Spider hacker extradited to the United States
Alleged Scattered Spider hacker extradited to the United States A dual United States and Estonian citizen has been extradited to the U.S. to face charges alleging he was a member of the Scattered Spider hacking collective. […] Sergiu Gatlan Go to bleepingcomputer
-
Medtronic notifies customers impacted by ShinyHunters data breach
Medtronic notifies customers impacted by ShinyHunters data breach Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party. […] Bill Toulas Go to bleepingcomputer
-
FortiBleed credential-theft campaign linked to Lynx ransomware
FortiBleed credential-theft campaign linked to Lynx ransomware The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. […] Lawrence Abrams Go to bleepingcomputer
-
Kubota says hackers had month-long access to network systems
Kubota says hackers had month-long access to network systems Kubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year. […] Bill Toulas Go to bleepingcomputer
-
New ChocoPoC malware targets researchers via trojanized PoC exploits
New ChocoPoC malware targets researchers via trojanized PoC exploits Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. […] Bill Toulas Go to bleepingcomputer
-
Amazon fined $2.25M for withholding evidence from fraud victims
Amazon fined $2.25M for withholding evidence from fraud victims The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims’ access to transaction records. […] Sergiu Gatlan Go to bleepingcomputer
-
Adobe patches seven max severity ColdFusion, Campaign flaws
Adobe patches seven max severity ColdFusion, Campaign flaws Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform. […] Sergiu Gatlan Go to bleepingcomputer
-
New BioShocking attack manipulates AI browser into data theft
New BioShocking attack manipulates AI browser into data theft A new prompt injection attack dubbed “BioShocking” could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Kali Linux 2026.2 released with 9 new tools, NetHunter updates Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. […] Sergiu Gatlan Go to bleepingcomputer
-
Blackfield ransomware asks Nidec Corporation for $2 million ransom
Blackfield ransomware asks Nidec Corporation for $2 million ransom The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. […] Bill Toulas Go to bleepingcomputer
-
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
CISA: Windows BlueHammer flaw now exploited by ransomware gangs CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan discloses employee data breach linked to Oracle zero-day attacks Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. […] Lawrence Abrams Go to bleepingcomputer
-
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. […] Bill Toulas Go to bleepingcomputer
-
Data breach exposes up to 14.2 million email logins at six ISPs
Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. […] Bill Toulas Go to bleepingcomputer
-
Clean GitHub repo tricks AI coding agents into running malware
Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. […] Bill Toulas Go to bleepingcomputer
-
FBI: Russian hackers now target Signal backup recovery keys
FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages. […] Lawrence Abrams Go to bleepingcomputer
-
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA sets urgent deadline to fix Cisco flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. […] Bill Toulas Go to bleepingcomputer
-
Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lose $3 million in supply-chain attack Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform’s frontend following a breach at a third-party vendor. […] Bill Toulas Go to bleepingcomputer
-
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Cybersecurity firms targeted by fraudulent OpenAI organization invites Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. […] Lawrence Abrams Go to bleepingcomputer
-
Your First GRC Agent: A Red Teamer’s Walkthrough
Your First GRC Agent: A Red Teamer’s Walkthrough AI won’t replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. […] Sponsored by Anecdotes Go to bleepingcomputer
-
Poland busts SIM-swapping gang tied to millions in crypto theft
Poland busts SIM-swapping gang tied to millions in crypto theft Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. […] Bill Toulas Go to bleepingcomputer
-
Order-tracking app Shop abused to push callback phishing attacks
Order-tracking app Shop abused to push callback phishing attacks Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users’ order histories to trick them into providing sensitive data or installing remote access software. […] Bill Toulas Go to bleepingcomputer
-
Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft quietly extends free Windows 10 ESU support to October 2027 Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. […] Lawrence Abrams Go to bleepingcomputer
-
New macOS malware embeds fake errors to confuse AI analysis tools
New macOS malware embeds fake errors to confuse AI analysis tools A newly discovered macOS malware dubbed “Gaslight” is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. […] Lawrence Abrams Go to bleepingcomputer
-
DraftKings hacker ‘Snoopy’ sentenced to 18 months in prison
DraftKings hacker ‘Snoopy’ sentenced to 18 months in prison A 21-year-old using the alias “Snoopy” was sentenced to 18 months in prison for his role in hacking DraftKings accounts in the November 2022 cyberattack. […] Bill Toulas Go to bleepingcomputer
-
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious Edge extension abuses Native Messaging as bridge to malware
Malicious Edge extension abuses Native Messaging as bridge to malware A malicious Microsoft Edge extension dubbed ‘Edgecution’ has been used in a ransomware attack to escape the browser sandbox and deploy a Python-based backdoor. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of max severity Ubiquiti flaws exploited in attacks
CISA warns of max severity Ubiquiti flaws exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. […] Bill Toulas Go to bleepingcomputer
-
Tata Electronics confirms cyberattack as hackers leak data
Tata Electronics confirms cyberattack as hackers leak data Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Healthtech firm Xolis suffers data breach impacting 1.4 million people
Healthtech firm Xolis suffers data breach impacting 1.4 million people Healthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network. […] Bill Toulas Go to bleepingcomputer
-
New macOS ClickFix attack silently mounts DMGs to push infostealer
New macOS ClickFix attack silently mounts DMGs to push infostealer A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. […] Lawrence Abrams Go to bleepingcomputer
-
WhatsApp phishing attack uses fake business docs to hack PCs
WhatsApp phishing attack uses fake business docs to hack PCs An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. […] Bill Toulas Go to bleepingcomputer
-
JaredFromSubway MEV bot hacked in $15 million crypto theft
JaredFromSubway MEV bot hacked in $15 million crypto theft The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. […] Bill Toulas Go to bleepingcomputer
-
FFmpeg fixes PixelSmash flaw in widely used video decoder
FFmpeg fixes PixelSmash flaw in widely used video decoder A newly disclosed FFmpeg flaw dubbed ‘PixelSmash’ could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. […] Bill Toulas Go to bleepingcomputer
-
FortiBleed campaign used custom FortiGate sniffer to steal credentials
FortiBleed campaign used custom FortiGate sniffer to steal credentials Security firm SOCRadar says the large-scale FortiBleed campaign targeting Fortinet FortiGate devices used custom sniffers to harvest authentication secrets from compromised firewalls and steal credentials. […] Lawrence Abrams Go to bleepingcomputer
-
AryStinger botnet infected thousands of D-Link routers worldwide
AryStinger botnet infected thousands of D-Link routers worldwide A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. […] Bill Toulas Go to bleepingcomputer
-
New Prinz Eugen ransomware prioritizes recent files for encryption
New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware operation named ‘Prinz Eugen’ prioritizes recently modified files for encryption and leaves no ransom note on the system. […] Bill Toulas Go to bleepingcomputer
-
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. […] Lawrence Abrams Go to bleepingcomputer