Category: Security
-
New CrushFTP zero-day exploited in attacks to hijack servers
New CrushFTP zero-day exploited in attacks to hijack servers CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. […] Lawrence Abrams Go to bleepingcomputer
-
Arch Linux pulls AUR packages that installed Chaos RAT malware
Arch Linux pulls AUR packages that installed Chaos RAT malware Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR) were used to install the CHAOS remote access trojan (RAT) on Linux devices. […] Lawrence Abrams Go to bleepingcomputer
-
UK ties GRU to stealthy Microsoft 365 credential-stealing malware
UK ties GRU to stealthy Microsoft 365 credential-stealing malware The UK National Cyber Security Centre (NCSC) has formally attributed ‘Authentic Antics’ espionage malware attacks to APT28 (Fancy Bear), threat actor already linked to Russia’s military intelligence service (GRU). […] Bill Toulas Go to bleepingcomputer
-
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks A critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed “CitrixBleed 2,” was actively exploited nearly two weeks before proof-of-concept (PoC) exploits were made public, despite Citrix stating that there was no evidence of attacks. […] Lawrence Abrams Go to bleepingcomputer
-
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Teams voice calls abused to push Matanbuchus malware
Microsoft Teams voice calls abused to push Matanbuchus malware The Matanbuchus malware loader has been seen being distributed through social engineering over Microsoft Teams calls impersonating IT helpdesk. […] Bill Toulas Go to bleepingcomputer
-
Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices
Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices Google has filed a lawsuit against the anonymous operators of the Android BadBox 2.0 malware botnet, accusing them of running a global ad fraud scheme against the company’s advertising platforms. […] Lawrence Abrams Go to bleepingcomputer
-
Co-op confirms data of 6.5 million members stolen in cyberattack
Co-op confirms data of 6.5 million members stolen in cyberattack UK retailer Co-op has confirmed that personal data of 6.5 million members was stolen in the massive cyberattack in April that shut down systems and caused food shortages in its grocery stores. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. Army soldier pleads guilty to extorting 10 tech, telecom firms
U.S. Army soldier pleads guilty to extorting 10 tech, telecom firms A 21-year old former U.S. Army soldier pleaded guilty to charges of hacking and extorting at least ten telecommunications and technology companies in the country. […] Bill Toulas Go to bleepingcomputer
-
Louis Vuitton says regional data breaches tied to same cyberattack
Louis Vuitton says regional data breaches tied to same cyberattack Luxury fashion giant Louis Vuitton confirmed that breaches impacting customers in the UK, South Korea, and Turkey stem from the same security incident, which is believed to be linked to the ShinyHunters extortion group. […] Lawrence Abrams Go to bleepingcomputer
-
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack To quash speculation of a cyberattack or BGP hijack incident causing the recent 1.1.1.1 Resolver service outage, Cloudflare explains in a post mortem that the incident was caused by an internal misconfiguration. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances. […] Ionut Ilascu Go to bleepingcomputer
-
Google fixes actively exploited sandbox escape zero day in Chrome
Google fixes actively exploited sandbox escape zero day in Chrome Google has released a security update for Chrome to address half a dozen vulnerabilities, one of them actively exploited by attackers to escape the browser’s sandbox protection. […] Bill Toulas Go to bleepingcomputer
-
Abacus dark web drug market goes offline in suspected exit scam
Abacus dark web drug market goes offline in suspected exit scam Abacus Market, the largest Western darknet marketplace supporting Bitcoin payments, has shut down its public infrastructure in a move suspected to be an exit scam. […] Bill Toulas Go to bleepingcomputer
-
North Korean XORIndex malware hidden in 67 malicious npm packages
North Korean XORIndex malware hidden in 67 malicious npm packages North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems. […] Bill Toulas Go to bleepingcomputer
-
UK launches vulnerability research program for external experts
UK launches vulnerability research program for external experts UK’s National Cyber Security Centre (NCSC) has announced a new Vulnerability Research Initiative (VRI) that aims to strengthen relations with external cybersecurity experts. […] Bill Toulas Go to bleepingcomputer
-
Interlock ransomware adopts FileFix method to deliver malware
Interlock ransomware adopts FileFix method to deliver malware Hackers have adopted the new technique called ‘FileFix’ in Interlock ransomware attacks to drop a remote access trojan (RAT) on targeted systems. […] Bill Toulas Go to bleepingcomputer
-
Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot
Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot Dozens of Gigabyte motherboard models run on UEFI firmware vulnerable to security issues that allow planting bootkit malware that is invisible to the operating system and can survive reinstalls. […] Bill Toulas Go to bleepingcomputer
-
Malicious VSCode extension in Cursor IDE led to $500K crypto theft
Malicious VSCode extension in Cursor IDE led to $500K crypto theft A fake extension for the Cursor AI IDE code editor infected devices with remote access tools and infostealers, which, in one case, led to the theft of $500,000 in cryptocurrency from a Russian crypto developer. […] Lawrence Abrams Go to bleepingcomputer
-
Google Gemini flaw hijacks email summaries for phishing
Google Gemini flaw hijacks email summaries for phishing Google Gemini for Workspace can be exploited to generate email summaries that appear legitimate but include malicious instructions or warnings that direct users to phishing sites without using attachments or direct links. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting critical RCE flaw in Wing FTP Server
Hackers are exploiting critical RCE flaw in Wing FTP Server Hackers have started to exploit a critical remote code execution vulnerability in Wing FTP Server just one day after technical details on the flaw became public. […] Bill Toulas Go to bleepingcomputer
-
‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications
‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applications across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
‘123456’ password exposed chats for 64 million McDonald’s job applicants
‘123456’ password exposed chats for 64 million McDonald’s job applicants Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applicants across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now Proof-of-concept exploits have been released for a critical SQLi vulnerability in Fortinet FortiWeb that can be used to achieve pre-authenticated remote code execution on vulnerable servers. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress Gravity Forms developer hacked to push backdoored plugins
WordPress Gravity Forms developer hacked to push backdoored plugins The popular WordPress plugin Gravity Forms has been compromised in what seems a supply-chain attack where manual installers from the official website were infected with a backdoor. […] Bill Toulas Go to bleepingcomputer
-
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks NVIDIA is warning users to activate System Level Error-Correcting Code mitigation to protect against Rowhammer attacks on graphical processors with GDDR6 memory. […] Bill Toulas Go to bleepingcomputer
-
The zero-day that could’ve compromised every Cursor and Windsurf user
The zero-day that could’ve compromised every Cursor and Windsurf user Learn how one overlooked flaw in OpenVSX discovered by Koi Secureity could’ve let attackers hijack millions of dev machines via an extension supply chain attack. The zero-day threat’s been patched—but the wake-up call is clear: extensions are a new, massive supply chain risk. […] Sponsored…
-
Windows 11 now uses JScript9Legacy engine for improved security
Windows 11 now uses JScript9Legacy engine for improved security Microsoft announced that it has replaced the default scripting engine JScript with the newer and more secure JScript9Legacy on Windows 11 version 24H2 and later. […] Bill Toulas Go to bleepingcomputer
-
Russian pro basketball player arrested for alleged role in ransomware attacks
Russian pro basketball player arrested for alleged role in ransomware attacks Russian professional basketball player Daniil Kasatkin was arrested in France at the request of the United States for allegedly acting as a negotiator for a ransomware gang. […] Lawrence Abrams Go to bleepingcomputer
-
PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars
PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars Four vulnerabilities dubbed PerfektBlue and affecting the BlueSDK Bluetooth stack from OpenSynergy can be exploited to achieve remote code execution and potentially allow access to critical elements in vehicles from multiple vendors, including Mercedes-Benz AG, Volkswagen, and Skoda. […] Bill Toulas Go to bleepingcomputer
-
FBI’s CJIS demystified: Best practices for passwords, MFA & access control
FBI’s CJIS demystified: Best practices for passwords, MFA & access control FBI’s Criminal Justice Information Services (CJIS) compliance isn’t optional when handling law enforcement data. From MFA to password hygiene, see how Specops Software helps meet FBI standards while also securing your Windows Active Directory. […] Sponsored by Specops Software Go to bleepingcomputer
-
Four arrested in UK over M&S, Co-op, Harrods cyberattacks
Four arrested in UK over M&S, Co-op, Harrods cyberattacks The UK’s National Crime Agency (NCA) arrested four people suspected of being involved in cyberattacks on major retailers in the country, including Marks & Spencer, Co-op, and Harrods. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Authenticator on iOS moves backups fully to iCloud
Microsoft Authenticator on iOS moves backups fully to iCloud Microsoft is rolling out a new backup system in September for its Authenticator app on iOS, removing the requirement to use a Microsoft personal account to back up TOTP secrets and account names. […] Lawrence Abrams Go to bleepingcomputer
-
Qantas confirms data breach impacts 5.7 million customers
Qantas confirms data breach impacts 5.7 million customers Australian airline Qantas has confirmed that 5.7 million people have been impacted by a recent data breach, in which threat actors stole customers’ data. […] Lawrence Abrams Go to bleepingcomputer
-
Google reveals details on Android’s Advanced Protection for Chrome
Google reveals details on Android’s Advanced Protection for Chrome Google is sharing more information on how Chrome operates when Android mobile users enable Advanced Protection, highlighting strong security improvements. […] Bill Toulas Go to bleepingcomputer
-
Bitcoin Depot breach exposes data of nearly 27,000 crypto users
Bitcoin Depot breach exposes data of nearly 27,000 crypto users Bitcoin Depot, an operator of Bitcoin ATMs, is notifying customers of a data breach incident that has exposed their sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Samsung announces major security enhancements coming to One UI 8
Samsung announces major security enhancements coming to One UI 8 Samsung has announced multiple data security and privacy enhancements for its upcoming Galaxy smartphones running One UI 8, its custom user interface on top of Android. […] Bill Toulas Go to bleepingcomputer
-
M&S confirms social engineering led to massive ransomware attack
M&S confirms social engineering led to massive ransomware attack M&S confirmed today that the retail outlet’s network was initially breached in a “sophisticated impersonation attack” that ultimately led to a DragonForce ransomware attack. […] Lawrence Abrams Go to bleepingcomputer
-
New Android TapTrap attack fools users with invisible UI trick
New Android TapTrap attack fools users with invisible UI trick A novel tapjacking technique can exploit user interface animations to bypass Android’s permission system and allow access to sensitive data or trick users into performing destructive actions, such as wiping the device. […] Bill Toulas Go to bleepingcomputer
-
Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage
Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage A Chinese national was arrested in Milan, Italy, last week for allegedly being linked to the state-sponsored Silk Typhoon hacking group, which responsible for cyberattacks against American organizations and government agencies. […] Lawrence Abrams Go to bleepingcomputer
-
Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now
Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now Researchers have released proof-of-concept (PoC) exploits for a critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed CitrixBleed2, warning that the flaw is easily exploitable and can successfully steal user session tokens. […] Lawrence Abrams Go to bleepingcomputer
-
Employee gets $920 for credentials used in $140 million bank heist
Employee gets $920 for credentials used in $140 million bank heist Hackers stole nearly $140 million from six banks in Brazil by using an employee’s credentials from C&M, a company that offers financial connectivity solutions. […] Bill Toulas Go to bleepingcomputer
-
Atomic macOS infostealer adds backdoor for persistent attacks
Atomic macOS infostealer adds backdoor for persistent attacks Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as ‘AMOS’) that comes with a backdoor, to attackers persistent access to compromised systems. […] Bill Toulas Go to bleepingcomputer
-
Qantas is being extorted in recent data-theft cyberattack
Qantas is being extorted in recent data-theft cyberattack Qantas has confirmed that it is now being extorted by threat actors following a cyberattack that potentially exposed the data for 6 million customers. […] Lawrence Abrams Go to bleepingcomputer
-
Ingram Micro outage caused by SafePay ransomware attack
Ingram Micro outage caused by SafePay ransomware attack An ongoing outage at IT giant Ingram Micro is caused by a SafePay ransomware attack that led to the shutdown of internal systems, BleepingComputer has learned. […] Lawrence Abrams Go to bleepingcomputer
-
Ingram Micro suffers global outage as internal systems inaccessible
Ingram Micro suffers global outage as internal systems inaccessible IT giant Ingram Micro is experiencing a global outage that is impacting its websites and internal systems, with customers concerned that it may be a cyberattack after the company remains silent on the cause of the issues. […] Lawrence Abrams Go to bleepingcomputer
-
Hacker leaks Telefónica data allegedly stolen in a new breach
Hacker leaks Telefónica data allegedly stolen in a new breach A hacker is threatening to leak 106GB of data allegedly stolen from Spanish telecommunications company Telefónica in a breach that the company did not acknowledge. […] Ionut Ilascu Go to bleepingcomputer
-
Grafana releases critical security update for Image Renderer plugin
Grafana releases critical security update for Image Renderer plugin Grafana Labs has addressed four Chromium vulnerabilities in critical security updates for the Grafana Image Renderer plugin and Synthetic Monitoring Agent. […] Bill Toulas Go to bleepingcomputer
-
IdeaLab confirms data stolen in ransomware attack last year
IdeaLab confirms data stolen in ransomware attack last year IdeaLab is notifying individuals impacted by a data breach incident last October when hackers accessed sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Microsoft asks users to ignore Windows Firewall config errors
Microsoft asks users to ignore Windows Firewall config errors Microsoft asked customers this week to disregard incorrect Windows Firewall errors that appear after rebooting their systems following the installation of the June 2025 preview update. […] Sergiu Gatlan Go to bleepingcomputer
-
NimDoor crypto-theft macOS malware revives itself when killed
NimDoor crypto-theft macOS malware revives itself when killed North Korean state-backed hackers have been using a new family of macOS malware called NimDoor in a campaign that targets web3 and cryptocurrency organizations. […] Bill Toulas Go to bleepingcomputer
-
DOJ investigates ex-ransomware negotiator over extortion kickbacks
DOJ investigates ex-ransomware negotiator over extortion kickbacks An ex-ransomware negotiator is under criminal investigation by the Department of Justice for allegedly working with ransomware gangs to profit from extortion payment deals. […] Lawrence Abrams Go to bleepingcomputer
-
Spain arrests hackers who targeted politicians and journalists
Spain arrests hackers who targeted politicians and journalists The Spanish police have arrested two individuals in the province of Las Palmas for their alleged involvement in cybercriminal activity, including data theft from the country’s government. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns that Unified CM has hardcoded root SSH credentials
Cisco warns that Unified CM has hardcoded root SSH credentials Cisco has removed a backdoor account from its Unified Communications Manager (Unified CM), which would have allowed remote attackers to log in to unpatched devices with root privileges. […] Sergiu Gatlan Go to bleepingcomputer
-
Qantas discloses cyberattack amid Scattered Spider aviation breaches
Qantas discloses cyberattack amid Scattered Spider aviation breaches Australian airline Qantas disclosed that it detected a cyberattack on Monday after threat actors gained access to a third-party platform containing customer data. […] Lawrence Abrams Go to bleepingcomputer
-
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks AT&T has launched a new security feature called “Wireless Lock” that protects customers from SIM swapping attacks by preventing changes to their account information and the porting of phone numbers while the feature is enabled. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft open-sources VS Code Copilot Chat extension on GitHub
Microsoft open-sources VS Code Copilot Chat extension on GitHub Microsoft has released the source code for the GitHub Copilot Chat extension for VS Code under the MIT license. […] Bill Toulas Go to bleepingcomputer
-
Kelly Benefits says 2024 data breach impacts 550,000 customers
Kelly Benefits says 2024 data breach impacts 550,000 customers Kelly & Associates Insurance Group (dba Kelly Benefits) is informing more than half a million people of a data breach that compromised their personal information. […] Bill Toulas Go to bleepingcomputer
-
Aeza Group sanctioned for hosting ransomware, infostealer servers
Aeza Group sanctioned for hosting ransomware, infostealer servers The U.S. Department of the Treasury has sanctioned Russian hosting company Aeza Group and four operators for allegedly acting as a bulletproof hosting company for ransomware gangs, infostealer operations, darknet drug markets, and Russian disinformation campaigns. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. warns of Iranian cyber threats on critical infrastructure
U.S. warns of Iranian cyber threats on critical infrastructure U.S. cyber agencies, the FBI, and NSA issued an urgent warning today about potential cyberattacks from Iranian-affiliated hackers targeting U.S. critical infrastructure. […] Lawrence Abrams Go to bleepingcomputer
-
Germany asks Google, Apple to remove DeepSeek AI from app stores
Germany asks Google, Apple to remove DeepSeek AI from app stores The Berlin Commissioner for Data Protection has formally requested Google and Apple to remove the DeepSeek AI application from the application stores due to GDPR violations. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender for Office 365 now blocks email bombing attacks
Microsoft Defender for Office 365 now blocks email bombing attacks Microsoft says its Defender for Office 365 cloud-based email security suite will now automatically detect and block email bombing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Switzerland says government data stolen in ransomware attack
Switzerland says government data stolen in ransomware attack The government in Switzerland is informing that sensitive information from various federal offices has been impacted by a ransomware attack at the third-party organization Radix. […] Bill Toulas Go to bleepingcomputer
-
Hikvision Canada ordered to cease operations over security risks
Hikvision Canada ordered to cease operations over security risks The Canadian government has ordered Hikvision’s subsidiary in the country to cease all operations following a review that determined them to pose a national security risk. […] Bill Toulas Go to bleepingcomputer
-
Bluetooth flaws could let hackers spy through your microphone
Bluetooth flaws could let hackers spy through your microphone Vulnerabilities affecting a Bluetooth chipset present in more than two dozen audio devices from ten vendors can be exploited for eavesdropping or stealing sensitive information. […] Ionut Ilascu Go to bleepingcomputer
-
Cloudflare open-sources Orange Meets with End-to-End encryption
Cloudflare open-sources Orange Meets with End-to-End encryption Cloudflare has implemented end-to-end encryption (E2EE) to its video calling app Orange Meets and open-sourced the solution for transparency. […] Bill Toulas Go to bleepingcomputer
-
Let’s Encrypt ends certificate expiry emails to cut costs, boost privacy
Let’s Encrypt ends certificate expiry emails to cut costs, boost privacy Let’s Encrypt has announced it will no longer notify users about imminent certificate expirations via email due to high costs, privacy concerns, and unnecessary complexities. […] Bill Toulas Go to bleepingcomputer
-
Scattered Spider hackers shift focus to aviation, transportation firms
Scattered Spider hackers shift focus to aviation, transportation firms Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors […] Lawrence Abrams Go to bleepingcomputer
-
Citrix Bleed 2 flaw now believed to be exploited in attacks
Citrix Bleed 2 flaw now believed to be exploited in attacks A critical NetScaler ADC and Gateway vulnerability dubbed “Citrix Bleed 2” (CVE-2025-5777) is now likely exploited in attacks, according to cybersecurity firm ReliaQuest, seeing an increase in suspicious sessions on Citrix devices. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Ahold Delhaize says data breach affects 2.2 million people
Retail giant Ahold Delhaize says data breach affects 2.2 million people Ahold Delhaize, one of the world’s largest food retail chains, is notifying over 2.2 million individuals that their personal, financial, and health information was stolen in a November ransomware attack that impacted its U.S. systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Whole Foods supplier UNFI restores core systems after cyberattack
Whole Foods supplier UNFI restores core systems after cyberattack American grocery wholesale giant United Natural Foods (UNFI) reports that it has restored its core systems and brought online the electronic ordering and invoicing systems affected by a cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Hawaiian Airlines discloses cyberattack, flights not affected
Hawaiian Airlines discloses cyberattack, flights not affected Hawaiian Airlines, the tenth-largest commercial airline in the United States, is investigating a cyberattack that has disrupted access to some of its systems. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks CISA says a maximum severity vulnerability in AMI’s MegaRAC Baseboard Management Controller (BMC) software, which enables attackers to hijack and brick servers, is currently under active exploitation. […] Sergiu Gatlan Go to bleepingcomputer
-
Hacker ‘IntelBroker’ charged in US for global data theft breaches
Hacker ‘IntelBroker’ charged in US for global data theft breaches A British national known online as “IntelBroker” has been charged by the U.S. for stealing and selling sensitive data from dozens of victims, causing an estimated $25 million in damages. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers turn ScreenConnect into malware using Authenticode stuffing
Hackers turn ScreenConnect into malware using Authenticode stuffing Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client’s Authenticode signature. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks A sophisticated malicious campaign that researchers call OneClik has been leveraging Microsoft’s ClickOnce software deployment tool and custom Golang backdoors to compromise organizations within the energy, oil, and gas sectors. […] Ionut Ilascu Go to bleepingcomputer
-
SonicWall warns of trojanized NetExtender stealing VPN logins
SonicWall warns of trojanized NetExtender stealing VPN logins SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials. […] Bill Toulas Go to bleepingcomputer
-
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
APT28 hackers use Signal chats to launch new malware attacks on Ukraine The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. […] Bill Toulas Go to bleepingcomputer
-
Malware on Google Play, Apple App Store stole your photos—and crypto
Malware on Google Play, Apple App Store stole your photos—and crypto A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices. […] Bill Toulas Go to bleepingcomputer
-
US Homeland Security warns of escalating Iranian cyberattack risks
US Homeland Security warns of escalating Iranian cyberattack risks The U.S. Department of Homeland Security (DHS) warned over the weekend of escalating cyberattack risks by Iran-backed hacking groups and pro-Iranian hacktivists. […] Sergiu Gatlan Go to bleepingcomputer
-
Canada says Salt Typhoon hacked telecom firm via Cisco flaw
Canada says Salt Typhoon hacked telecom firm via Cisco flaw The Canadian Centre for Cyber Security and the FBI confirm that the Chinese state-sponsored ‘Salt Typhoon’ hacking group is also targeting Canadian telecommunication firms, breaching a telecom provider in February. […] Bill Toulas Go to bleepingcomputer
-
Revil ransomware members released after time served on carding charges
Revil ransomware members released after time served on carding charges Four REvil ransomware members arrested in January 2022 were released by Russia on time served after they pleaded guilty to carding and malware distribution charges. […] Sergiu Gatlan Go to bleepingcomputer
-
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup CoinMarketCap, the popular cryptocurrency price tracking site, suffered a website supply chain attack that exposed site visitors to a wallet drainer campaign to steal visitors’ crypto. […] Lawrence Abrams Go to bleepingcomputer
-
Oxford City Council suffers breach exposing two decades of data
Oxford City Council suffers breach exposing two decades of data Oxford City Council warns it suffered a data breach where attackers accessed personally identifiable information from legacy systems. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers bypass Gmail MFA using stolen app passwords
Russian hackers bypass Gmail MFA using stolen app passwords Russian hackers bypass multi-factor authentication and access Gmail accounts by leveraging app-specific passwords in advanced social engineering attacks that impersonate U.S. Department of State officials. […] Ionut Ilascu Go to bleepingcomputer
-
WordPress Motors theme flaw mass-exploited to hijack admin accounts
WordPress Motors theme flaw mass-exploited to hijack admin accounts Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme “Motors” to hijack administrator accounts and gain complete control of a targeted site. […] Bill Toulas Go to bleepingcomputer
-
BitoPro exchange links Lazarus hackers to $11 million crypto heist
BitoPro exchange links Lazarus hackers to $11 million crypto heist The Taiwanese cryptocurrency exchange BitoPro claims the North Korean hacking group Lazarus is behind a cyberattack that led to the theft of $11,000,000 worth of cryptocurrency on May 8, 2025. […] Bill Toulas Go to bleepingcomputer
-
Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider
Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider Cloudflare says it mitigated a record-breaking distributed denial of service (DDoS) attack in May 2025 that peaked at 7.3 Tbps, targeting a hosting provider. […] Bill Toulas Go to bleepingcomputer
-
Aflac discloses breach amidst Scattered Spider insurance attacks
Aflac discloses breach amidst Scattered Spider insurance attacks On Friday, American insurance giant Aflac disclosed that its systems were breached in a broader campaign targeting insurance companies across the United States by attackers who may have stolen personal and health information. […] Sergiu Gatlan Go to bleepingcomputer
-
Can users reset their own passwords without sacrificing security?
Can users reset their own passwords without sacrificing security? Self-service password resets (SSPR) reduce helpdesk strain—but without strong security, they can open the door to attackers. Learn why phishing-resistant MFA, context-aware verification, and risk-based detection are critical to secure SSPR implementation. […] Sponsored by Specops Software Go to bleepingcomputer
-
No, the 16 billion credentials leak is not a new data breach
No, the 16 billion credentials leak is not a new data breach News broke today of a “mother of all breaches,” sparking wide media coverage filled with warnings and fear-mongering. However, it appears to be a compilation of previously leaked credentials stolen by infostealers, exposed in data breaches, and via credential stuffing attacks. […] Lawrence Abrams…
-
Godfather Android malware now uses virtualization to hijack banking apps
Godfather Android malware now uses virtualization to hijack banking apps A new version of the Android malware “Godfather” creates isolated virtual environments on mobile devices to steal account data and transactions from legitimate banking apps. […] Bill Toulas Go to bleepingcomputer
-
Webinar: Stolen credentials are the new front door to your network
Webinar: Stolen credentials are the new front door to your network Cybercriminals no longer need zero-days to breach your systems—these days, they just log in. Join BleepingComputer, SC Media, and Specops Software’s Darren Siegel on July 9 at 2:00 PM ET for a live webinar on how attackers are using stolen credentials to infiltrate networks…
-
US recovers $225 million of crypto stolen in investment scams
US recovers $225 million of crypto stolen in investment scams The U.S. Department of Justice has seized more than $225 million in cryptocurrency linked to investment fraud and money laundering operations, the largest crypto seizure in the history of the U.S. Secret Service. […] Bill Toulas Go to bleepingcomputer
-
Krispy Kreme says November data breach impacts over 160,000 people
Krispy Kreme says November data breach impacts over 160,000 people U.S. doughnut chain Krispy Kreme confirmed that attackers stole the personal information of over 160,000 individuals in a November 2024 cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Ryuk ransomware’s initial access expert extradited to the U.S.
Ryuk ransomware’s initial access expert extradited to the U.S. A member of the notorious Ryuk ransomware operation who specialized in gaining initial access to corporate networks has been extradited to the United States. […] Bill Toulas Go to bleepingcomputer
-
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto The pro-Israel “Predatory Sparrow” hacking group claims to have stolen over $90 million in cryptocurrency from Nobitex, Iran’s largest crypto exchange, and burned the funds in a politically motivated cyberattack. […] Lawrence Abrams Go to bleepingcomputer
-
North Korean hackers deepfake execs in Zoom call to spread Mac malware
North Korean hackers deepfake execs in Zoom call to spread Mac malware North Korean advanced persistent threat (APT) ‘BlueNoroff’ (aka ‘Sapphire Sleet’ or ‘TA444’) are using deepfake company executives during fake Zoom calls to trick employees into installing custom malware on their computers. […] Bill Toulas Go to bleepingcomputer
-
New Linux udisks flaw lets attackers get root on major Linux distros
New Linux udisks flaw lets attackers get root on major Linux distros Attackers can exploit two newly discovered local privilege escalation (LPE) vulnerabilities to gain root privileges on systems running major Linux distributions. […] Sergiu Gatlan Go to bleepingcomputer
-
Asana warns MCP AI feature exposed customer data to other orgs
Asana warns MCP AI feature exposed customer data to other orgs Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa. […] Bill Toulas Go to bleepingcomputer