Category: Security
-
Critical Fortinet flaws now exploited in Qilin ransomware attacks
Critical Fortinet flaws now exploited in Qilin ransomware attacks The Qilin ransomware operation has recently joined attacks exploiting two Fortinet vulnerabilities that allow bypassing authentication on vulnerable devices and executing malicious code remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Police arrests 20 suspects for distributing child sexual abuse content
Police arrests 20 suspects for distributing child sexual abuse content Law enforcement authorities from over a dozen countries have arrested 20 suspects in an international operation targeting the production and distribution of child sexual abuse material. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI: BADBOX 2.0 Android malware infects millions of consumer devices
FBI: BADBOX 2.0 Android malware infects millions of consumer devices The FBI is warning that the BADBOX 2.0 malware campaign has infected over 1 million home Internet-connected devices, converting consumer electronics into residential proxies that are used for malicious activity. […] Lawrence Abrams Go to bleepingcomputer
-
Old AT&T data leak repackaged to link SSNs, DOBs to 49M phone numbers
Old AT&T data leak repackaged to link SSNs, DOBs to 49M phone numbers A threat actor has re-released data from a 2021 AT&T breach affecting 70 million customers, this time combining previously separate files to directly link Social Security numbers and birth dates to individual users. […] Lawrence Abrams Go to bleepingcomputer
-
ViLE gang members sentenced for extortion, police portal breach
ViLE gang members sentenced for extortion, police portal breach Two members of a group of cybercriminals named ViLE were sentenced this week for hacking into a federal law enforcement web portal in an extortion scheme. […] Sergiu Gatlan Go to bleepingcomputer
-
Interlock ransomware claims Kettering Health breach, leaks stolen data
Interlock ransomware claims Kettering Health breach, leaks stolen data The Interlock ransomware gang has claimed a recent cyberattack on the Kettering Health healthcare network and leaked data allegedly stolen from breached systems. […] Sergiu Gatlan Go to bleepingcomputer
-
US offers $10M for tips on state hackers tied to RedLine malware
US offers $10M for tips on state hackers tied to RedLine malware The U.S. Department of State has announced a reward of up to $10 million for any information on government-sponsored hackers with ties to the RedLine infostealer malware operation and its suspected creator, Russian national Maxim Alexandrovich Rudometov. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft unveils free EU cybersecurity program for governments
Microsoft unveils free EU cybersecurity program for governments Microsoft announced in Berlin today a new European Security Program that promises to bolster cybersecurity for European governments. […] Bill Toulas Go to bleepingcomputer
-
FBI: Play ransomware breached 900 victims, including critical orgs
FBI: Play ransomware breached 900 victims, including critical orgs In an update to a joint advisory with CISA and the Australian Cyber Security Centre, the FBI said that the Play ransomware gang had breached roughly 900 organizations as of May 2025, three times the number of victims reported in October 2023. […] Sergiu Gatlan Go…
-
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution. […] Bill Toulas Go to bleepingcomputer
-
Coinbase breach tied to bribed TaskUs support agents in India
Coinbase breach tied to bribed TaskUs support agents in India A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange. […] Bill Toulas Go to bleepingcomputer
-
Cartier discloses data breach amid fashion brand cyberattacks
Cartier discloses data breach amid fashion brand cyberattacks Luxury fashion brand Cartier is warning customers it suffered a data breach that exposed customers’ personal information after its systems were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
The North Face warns customers of April credential stuffing attack
The North Face warns customers of April credential stuffing attack Outdoor apparel retailer The North Face is warning customers that their personal information was stolen in credential stuffing attacks targeting the company’s website in April. […] Bill Toulas Go to bleepingcomputer
-
SentinelOne: Last week’s 7-hour outage caused by software flaw
SentinelOne: Last week’s 7-hour outage caused by software flaw American cybersecurity company SentinelOne revealed over the weekend that a software flaw triggered a seven-hour-long outage on Thursday. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August
Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August Google says it will no longer trust root CA certificates signed by Chunghwa Telecom and Netlock in the Chrome Root Store due to a pattern of compliance failures and failure to make improvements. […] Bill Toulas Go to bleepingcomputer
-
Microsoft and CrowdStrike partner to link hacking group names
Microsoft and CrowdStrike partner to link hacking group names Microsoft and CrowdStrike announced today that they’ve partnered to connect the aliases used for specific threat groups without actually using a single naming standard. […] Sergiu Gatlan Go to bleepingcomputer
-
Exploit details for max severity Cisco IOS XE flaw now public
Exploit details for max severity Cisco IOS XE flaw now public Technical details about a maximum-severity Cisco IOS XE WLC arbitrary file upload flaw tracked as CVE-2025-20188 have been made publicly available, bringing us closer to a working exploit. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting critical flaw in vBulletin forum software
Hackers are exploiting critical flaw in vBulletin forum software Two critical vulnerabilities affecting the open-source forum software vBulletin have been discovered, with one confirmed to be actively exploited in the wild. […] Bill Toulas Go to bleepingcomputer
-
Police takes down AVCheck site used by cybercriminals to scan malware
Police takes down AVCheck site used by cybercriminals to scan malware An international law enforcement operation has taken down AVCheck, a service used by cybercriminals to test whether their malware is detected by commercial antivirus software before deploying it in the wild. […] Bill Toulas Go to bleepingcomputer
-
Germany doxxes Conti ransomware and TrickBot ring leader
Germany doxxes Conti ransomware and TrickBot ring leader The Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) claims that Stern, the leader of the Trickbot and Conti cybercrime gangs, is a 36-year-old Russian named Vitaly Nikolaevich Kovalev. […] Sergiu Gatlan Go to bleepingcomputer
-
Getting Exposure Management Right: Insights from 500 CISOs
Getting Exposure Management Right: Insights from 500 CISOs Pentesting isn’t just about finding flaws — it’s about knowing which ones matter. Pentera’s 2025 State of Pentesting report uncovers which assets attackers target most, where security teams are making progress, and which exposures still fly under the radar. Focus on reducing breach impact, not just breach…
-
Microsoft Authenticator now warns to export passwords before July cutoff
Microsoft Authenticator now warns to export passwords before July cutoff The Microsoft Authenticator app is now issuing notifications warning that the password autofill feature is being deprecated in July, suggesting users move to Microsoft Edge instead. […] Lawrence Abrams Go to bleepingcomputer
-
ConnectWise breached in cyberattack linked to nation-state hackers
ConnectWise breached in cyberattack linked to nation-state hackers IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers. […] Lawrence Abrams Go to bleepingcomputer
-
Threat actors abuse Google Apps Script in evasive phishing attacks
Threat actors abuse Google Apps Script in evasive phishing attacks Threat actors are abusing the trusted Google platform ‘Google Apps Script’ to host phishing pages, making them appear legitimate and eliminating the risk of them getting flagged by security tools. […] Bill Toulas Go to bleepingcomputer
-
Apple Safari exposes users to fullscreen browser-in-the-middle attacks
Apple Safari exposes users to fullscreen browser-in-the-middle attacks A weakness in Apple’s Safari web browser allows threat actors to leverage the fullscreen browser-in-the-middle (BitM) technique to steal account credentials from unsuspecting users. […] Bill Toulas Go to bleepingcomputer
-
Data broker LexisNexis discloses data breach affecting 364,000 people
Data broker LexisNexis discloses data breach affecting 364,000 people Data broker giant LexisNexis Risk Solutions has revealed that unknown attackers stole the personal information of over 364,000 individuals in a December breach. […] Sergiu Gatlan Go to bleepingcomputer
-
APT41 malware abuses Google Calendar for stealthy C2 communication
APT41 malware abuses Google Calendar for stealthy C2 communication The Chinese APT41 hacking group uses a new malware named ‘ToughProgress’ that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service. […] Bill Toulas Go to bleepingcomputer
-
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack The DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers’ systems. […] Lawrence Abrams Go to bleepingcomputer
-
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years An Iranian national has pleaded guilty to participating in the Robbinhood ransomware operation, which was used to breach the networks, steal data, and encrypt devices of U.S. cities and organizations in an attempt to extort millions of dollars over a five-year span. […] Lawrence Abrams Go to…
-
Not Every CVE Deserves a Fire Drill: Focus on What’s Exploitable
Not Every CVE Deserves a Fire Drill: Focus on What’s Exploitable Not every “critical” vulnerability is a critical risk. Picus Exposure Validation cuts through the noise by testing what’s actually exploitable in your environment — so you can patch what matters. […] Sponsored by Picus Security Go to bleepingcomputer
-
MATLAB dev confirms ransomware attack behind service outage
MATLAB dev confirms ransomware attack behind service outage MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian Laundry Bear cyberspies linked to Dutch Police hack
Russian Laundry Bear cyberspies linked to Dutch Police hack A previously unknown Russian-backed cyberespionage group now tracked as Laundry Bear has been linked to a September 2024 Dutch police security breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Adidas warns of data breach after customer service provider hack
Adidas warns of data breach after customer service provider hack German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and stole some customers’ data. […] Sergiu Gatlan Go to bleepingcomputer
-
Glitch to end app hosting and user profiles on July 8
Glitch to end app hosting and user profiles on July 8 Glitch has announced it is ending app hosting and user profiles on July 8, 2025, responding to changing market dynamics and extensive abuse problems that have raised operational costs. […] Bill Toulas Go to bleepingcomputer
-
Dozens of malicious packages on NPM collect host and network data
Dozens of malicious packages on NPM collect host and network data 60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals $223 million in Cetus Protocol cryptocurrency heist
Hacker steals $223 million in Cetus Protocol cryptocurrency heist The decentralized exchange Cetus Protocol announced that hackers have stolen $223 million in cryptocurrency and is offering a deal to stop all legal action if the funds are returned. […] Bill Toulas Go to bleepingcomputer
-
FBI warns of Luna Moth extortion attacks targeting law firms
FBI warns of Luna Moth extortion attacks targeting law firms The FBI warned that an extortion gang known as the Silent Ransom Group has been targeting U.S. law firms over the last two years in callback phishing and social engineering attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
TikTok videos now push infostealer malware in ClickFix attacks
TikTok videos now push infostealer malware in ClickFix attacks Cybercriminals are using TikTok videos to trick users into infecting themselves with Vidar and StealC information-stealing malware in ClickFix attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Police takes down 300 servers in ransomware supply-chain crackdown
Police takes down 300 servers in ransomware supply-chain crackdown In the latest phase of Operation Endgame, an international law enforcement operation, national authorities from seven countries seized 300 servers and 650 domains used to launch ransomware attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
US indicts leader of Qakbot botnet linked to ransomware attacks
US indicts leader of Qakbot botnet linked to ransomware attacks The U.S. government has indicted Russian national Rustam Rafailevich Gallyamov, the leader of the Qakbot botnet malware operation that compromised over 700,000 computers and enabled ransomware attacks. […] Ionut Ilascu Go to bleepingcomputer
-
Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE
Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE Critical vulnerabilities in Versa Concerto that are still unpatched could allow remote attackers to bypass authentication and execute arbitrary code on affected systems. […] Bill Toulas Go to bleepingcomputer
-
Critical Samlify SSO flaw lets attackers log in as admin
Critical Samlify SSO flaw lets attackers log in as admin A critical Samlify authentication bypass vulnerability has been discovered that allows attackers to impersonate admin users by injecting unsigned malicious assertions into legitimately signed SAML responses. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers breach orgs to track aid routes to Ukraine
Russian hackers breach orgs to track aid routes to Ukraine A Russian state-sponsored cyberespionage campaign attributed to APT28 (Fancy Bear/Forest Blizzard) hackers has been targeting and compromising international organizations since 2022 to disrupt aid efforts to Ukraine. […] Ionut Ilascu Go to bleepingcomputer
-
Coinbase says recent data breach impacts 69,461 customers
Coinbase says recent data breach impacts 69,461 customers Coinbase, a cryptocurrency exchange with over 100 million customers, revealed that a recent data breach in which cybercriminals stole customer and corporate data affected 69,461 individuals […] Sergiu Gatlan Go to bleepingcomputer
-
PowerSchool hacker pleads guilty to student data extortion scheme
PowerSchool hacker pleads guilty to student data extortion scheme A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers. […] Lawrence Abrams Go to bleepingcomputer
-
Mobile carrier Cellcom confirms cyberattack behind extended outages
Mobile carrier Cellcom confirms cyberattack behind extended outages Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. […] Lawrence Abrams Go to bleepingcomputer
-
Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks
Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites. […] Bill Toulas Go to bleepingcomputer
-
VanHelsing ransomware builder leaked on hacking forum
VanHelsing ransomware builder leaked on hacking forum The VanHelsing ransomware-as-a-service operation published the source code for its affiliate panel, data leak blog, and Windows encryptor builder after an old developer tried to sell it on the RAMP cybercrime forum. […] Lawrence Abrams Go to bleepingcomputer
-
Fake KeePass password manager leads to ESXi ransomware attack
Fake KeePass password manager leads to ESXi ransomware attack Threat actors have been distributing trojanized versions of the KeePass password manager for at least eight months to install Cobalt Strike beacons, steal credentials, and ultimately, deploy ransomware on the breached network. […] Lawrence Abrams Go to bleepingcomputer
-
O2 UK patches bug leaking mobile user location from call metadata
O2 UK patches bug leaking mobile user location from call metadata A flaw in O2 UK’s implementation of VoLTE and WiFi Calling technologies could allow anyone to expose the general location of a person and other identifiers by calling the target. […] Bill Toulas Go to bleepingcomputer
-
Arla Foods confirms cyberattack disrupts production, causes delays
Arla Foods confirms cyberattack disrupts production, causes delays Arla Foods has confirmed to BleepingComputer that it was targeted by a cyberattack that has disrupted its production operations. […] Bill Toulas Go to bleepingcomputer
-
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender A new tool called ‘Defendnot’ can disable Microsoft Defender on Windows devices by registering a fake antivirus product, even when no real AV is installed. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own
Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own During the second day of Pwn2Own Berlin 2025, competitors earned $435,000 after exploiting zero-day bugs in multiple products, including Microsoft SharePoint, VMware ESXi, Oracle VirtualBox, Red Hat Enterprise Linux, and Mozilla Firefox. […] Sergiu Gatlan Go to bleepingcomputer
-
Printer maker Procolored offered malware-laced drivers for months
Printer maker Procolored offered malware-laced drivers for months For at least half a year, the official software supplied with Procolored printers included malware in the form of a remote access trojan and a cryptocurrency stealer. […] Bill Toulas Go to bleepingcomputer
-
US charges 12 more suspects linked to $230 million crypto theft
US charges 12 more suspects linked to $230 million crypto theft Twelve more suspects were charged in a RICO conspiracy for their alleged involvement in the theft of over $230 million in cryptocurrency and laundering the funds using crypto exchanges and mixing services. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags recently patched Chrome bug as actively exploited
CISA tags recently patched Chrome bug as actively exploited On Thursday, CISA warned U.S. federal agencies to secure their systems against ongoing attacks exploiting a high-severity vulnerability in the Chrome web browser. […] Sergiu Gatlan Go to bleepingcomputer
-
Google fixes high severity Chrome flaw with public exploit
Google fixes high severity Chrome flaw with public exploit Google has released emergency security updates to patch a high-severity Chrome vulnerability that has a public exploit and can let attackers hijack accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to block admin-level browser launches for better security
Google Chrome to block admin-level browser launches for better security Google is rolling out a change to Chromium that “de-elevates” Google Chrome so it does not run as an administrator to increase security in Windows. […] Mayank Parmar Go to bleepingcomputer
-
Hackers behind UK retail attacks now targeting US companies
Hackers behind UK retail attacks now targeting US companies Google warned today that hackers using Scattered Spider tactics against retail chains in the United Kingdom have also started targeting retailers in the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gangs join ongoing SAP NetWeaver attacks
Ransomware gangs join ongoing SAP NetWeaver attacks Ransomware gangs have joined ongoing SAP NetWeaver attacks, exploiting a maximum-severity vulnerability that allows threat actors to gain remote code execution on vulnerable servers. […] Sergiu Gatlan Go to bleepingcomputer
-
Australian Human Rights Commission leaks docs to search engines
Australian Human Rights Commission leaks docs to search engines The Australian Human Rights Commission (AHRC) disclosed a data breach incident where private documents leaked online and were indexed by major search engines. […] Bill Toulas Go to bleepingcomputer
-
SAP patches second zero-day flaw exploited in recent attacks
SAP patches second zero-day flaw exploited in recent attacks SAP has released patches to address a second vulnerability exploited in recent attacks targeting SAP NetWeaver servers as a zero-day. […] Sergiu Gatlan Go to bleepingcomputer
-
North Korea ramps up cyberspying in Ukraine to assess war risk
North Korea ramps up cyberspying in Ukraine to assess war risk The state-backed North Korean threat group Konni (Opal Sleet, TA406) was observed targeting Ukrainian government entities in intelligence collection operations. […] Bill Toulas Go to bleepingcomputer
-
Twilio denies breach following leak of alleged Steam 2FA codes
Twilio denies breach following leak of alleged Steam 2FA codes Twilio has denied in a statement for BleepingComputer that it was breached after a threat actor claimed to be holding over 89 million Steam user records with one-time access codes. […] Bill Toulas Go to bleepingcomputer
-
Ivanti fixes EPMM zero-days chained in code execution attacks
Ivanti fixes EPMM zero-days chained in code execution attacks Ivanti warned customers today to patch their Ivanti Endpoint Manager Mobile (EPMM) software against two security vulnerabilities chained in attacks to gain remote code execution. […] Sergiu Gatlan Go to bleepingcomputer
-
ASUS DriverHub flaw let malicious sites run commands with admin rights
ASUS DriverHub flaw let malicious sites run commands with admin rights The ASUS DriverHub driver management utility was vulnerable to a critical remote code execution flaw that allowed malicious sites to execute commands on devices with the software installed. […] Bill Toulas Go to bleepingcomputer
-
Hackers now testing ClickFix attacks against Linux targets
Hackers now testing ClickFix attacks against Linux targets A new campaign employing ClickFix attacks has been spotted targeting both Windows and Linux systems using instructions that make infections on either operating system possible. […] Bill Toulas Go to bleepingcomputer
-
Output Messenger flaw exploited as zero-day in espionage attacks
Output Messenger flaw exploited as zero-day in espionage attacks A Türkiye-backed cyberespionage group exploited a zero-day vulnerability to attack Output Messenger users linked to the Kurdish military in Iraq. […] Sergiu Gatlan Go to bleepingcomputer
-
Moldova arrests suspect linked to DoppelPaymer ransomware attacks
Moldova arrests suspect linked to DoppelPaymer ransomware attacks Moldovan authorities have detained a 45-year-old suspect linked to DoppelPaymer ransomware attacks targeting Dutch organizations in 2021. […] Sergiu Gatlan Go to bleepingcomputer
-
Bluetooth 6.1 enhances privacy with randomized RPA timing
Bluetooth 6.1 enhances privacy with randomized RPA timing The Bluetooth Special Interest Group (SIG) has announced Bluetooth Core Specification 6.1, bringing important improvements to the popular wireless communication protocol. […] Bill Toulas Go to bleepingcomputer
-
iClicker site hack targeted students with malware via fake CAPTCHA
iClicker site hack targeted students with malware via fake CAPTCHA The website of iClicker, a popular student engagement platform, was compromised in a ClickFix attack that used a fake CAPTCHA prompt to trick students and instructors into installing malware on their devices. […] Lawrence Abrams Go to bleepingcomputer
-
Fake AI video generators drop new Noodlophile infostealer malware
Fake AI video generators drop new Noodlophile infostealer malware Fake AI-powered video generation tools are being used to distribute a new information-stealing malware family called ‘Noodlophile,’ under the guise of generated media content. […] Bill Toulas Go to bleepingcomputer
-
Ascension says recent data breach affects over 430,000 patients
Ascension says recent data breach affects over 430,000 patients Ascension, one of the largest private healthcare systems in the United States, has revealed that the personal and healthcare information of over 430,000 patients was exposed in a data breach disclosed last month. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to use on-device AI to detect tech support scams
Google Chrome to use on-device AI to detect tech support scams Google is implementing a new Chrome security feature that uses the built-in ‘Gemini Nano’ large-language model (LLM) to detect and block tech support scams while browsing the web. […] Bill Toulas Go to bleepingcomputer
-
Police dismantles botnet selling hacked routers as residential proxies
Police dismantles botnet selling hacked routers as residential proxies Law enforcement authorities have dismantled a botnet that infected thousands of routers over the last 20 years to build two networks of residential proxies known as Anyproxy and 5socks. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers behind attacks targeting SAP NetWeaver servers
Chinese hackers behind attacks targeting SAP NetWeaver servers Forescout Vedere Labs security researchers have linked ongoing attacks targeting a maximum severity vulnerability impacting SAP NetWeaver instances to a Chinese threat actor. […] Sergiu Gatlan Go to bleepingcomputer
-
Germany takes down eXch cryptocurrency exchange, seizes servers
Germany takes down eXch cryptocurrency exchange, seizes servers The Federal police in Germany (BKA) seized the server infrastructure and shut down the ‘eXch’ cryptocurrency exchange platform for alleged money laundering cybercrime proceeds. […] Bill Toulas Go to bleepingcomputer
-
FBI: End-of-life routers hacked for cybercrime proxy networks
FBI: End-of-life routers hacked for cybercrime proxy networks The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks. […] Bill Toulas Go to bleepingcomputer
-
Cisco fixes max severity IOS XE flaw letting attackers hijack devices
Cisco fixes max severity IOS XE flaw letting attackers hijack devices Cisco has fixed a maximum severity flaw in IOS XE Software for Wireless LAN Controllers by a hard-coded JSON Web Token (JWT) that allows an unauthenticated remote attacker to take over devices. […] Bill Toulas Go to bleepingcomputer
-
Education giant Pearson hit by cyberattack exposing customer data
Education giant Pearson hit by cyberattack exposing customer data Education giant Pearson suffered a cyberattack, allowing threat actors to steal corporate data and customer information, BleepingComputer has learned. […] Lawrence Abrams Go to bleepingcomputer
-
Supply chain attack hits npm package with 45,000 weekly downloads
Supply chain attack hits npm package with 45,000 weekly downloads An npm package named ‘rand-user-agent’ has been compromised in a supply chain attack to inject obfuscated code that activates a remote access trojan (RAT) on the user’s system. […] Bill Toulas Go to bleepingcomputer
-
Malicious PyPi package hides RAT malware, targets Discord devs since 2022
Malicious PyPi package hides RAT malware, targets Discord devs since 2022 A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three years. […] Sergiu Gatlan Go to bleepingcomputer
-
LockBit ransomware gang hacked, victim negotiations exposed
LockBit ransomware gang hacked, victim negotiations exposed The LockBit ransomware gang has suffered a data breach after its dark web affiliate panels were defaced and replaced with a message linking to a MySQL database dump. […] Lawrence Abrams Go to bleepingcomputer
-
PowerSchool hacker now extorting individual school districts
PowerSchool hacker now extorting individual school districts PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student and teacher data if a ransom is not paid. […] Lawrence Abrams Go to bleepingcomputer
-
CoGUI phishing platform sent 580 million emails to steal credentials
CoGUI phishing platform sent 580 million emails to steal credentials A new phishing kit named ‘CoGUI’ sent over 580 million emails to targets between January and April 2025, aiming to steal account credentials and payment data. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit OttoKit WordPress plugin flaw to add admin accounts
Hackers exploit OttoKit WordPress plugin flaw to add admin accounts Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on targeted sites. […] Bill Toulas Go to bleepingcomputer
-
Play ransomware exploited Windows logging flaw in zero-day attacks
Play ransomware exploited Windows logging flaw in zero-day attacks The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Apache Parquet exploit tool detect servers vulnerable to critical flaw
Apache Parquet exploit tool detect servers vulnerable to critical flaw A proof-of-concept exploit tool has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy to find vulnerable servers. […] Bill Toulas Go to bleepingcomputer
-
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
Samsung MagicINFO 9 Server RCE flaw now exploited in attacks Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. […] Bill Toulas Go to bleepingcomputer
-
UK Legal Aid Agency investigates cybersecurity incident
UK Legal Aid Agency investigates cybersecurity incident The Legal Aid Agency (LAA), an executive agency of the UK’s Ministry of Justice that oversees billions in legal funding, warned law firms of a security incident and said the attackers might have accessed financial information. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Langflow RCE flaw exploited to hack AI app servers
Critical Langflow RCE flaw exploited to hack AI app servers The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and mitigations as soon as possible. […] Bill Toulas Go to bleepingcomputer
-
Linux wiper malware hidden in malicious Go modules on GitHub
Linux wiper malware hidden in malicious Go modules on GitHub A supply-chain attack targets Linux servers with disk-wiping malware hidden in Golang modules published on GitHub. […] Ionut Ilascu Go to bleepingcomputer
-
Luna Moth extortion hackers pose as IT help desks to breach US firms
Luna Moth extortion hackers pose as IT help desks to breach US firms The data-theft extortion group known as Luna Moth, aka Silent Ransom Group, has ramped up callback phishing campaigns in attacks on legal and financial institutions in the United States. […] Bill Toulas Go to bleepingcomputer
-
New “Bring Your Own Installer” EDR bypass used in ransomware attack
New “Bring Your Own Installer” EDR bypass used in ransomware attack A new “Bring Your Own Installer” EDR bypass technique is exploited in attacks to bypass SentinelOne’s tamper protection feature, allowing threat actors to disable endpoint detection and response (EDR) agents to install the Babuk ransomware. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft finds default Kubernetes Helm charts can expose data
Microsoft finds default Kubernetes Helm charts can expose data Microsoft warns about the security risks posed by default configurations in Kubernetes deployments, particularly those using out-of-the-box Helm charts, which could publicly expose sensitive data. […] Bill Toulas Go to bleepingcomputer
-
Passkeys for Normal People
Passkeys for Normal People Let me start by very simply explaining the problem we’re trying to solve with passkeys. Imagine you’re logging on to a website like this: And, because you want to protect your account from being logged into by someone else who may obtain your username and password, you’ve turned on two-factor authentication…
-
StealC malware enhanced with stealth upgrades and data theft tools
StealC malware enhanced with stealth upgrades and data theft tools The creators of StealC, a widely-used information stealer and malware downloader, have released its second major version, bringing multiple stealth and data theft enhancements. […] Bill Toulas Go to bleepingcomputer
-
Microsoft ends Authenticator password autofill, moves users to Edge
Microsoft ends Authenticator password autofill, moves users to Edge Microsoft has announced that it will discontinue the password storage and autofill feature in the Authenticator app starting in July and will complete the deprecation in August 2025. […] Bill Toulas Go to bleepingcomputer
-
Co-op confirms data theft after DragonForce ransomware claims attack
Co-op confirms data theft after DragonForce ransomware claims attack The Co-op cyberattack is far worse than initially reported, with the company now confirming that data was stolen for a significant number of current and past customers. […] Lawrence Abrams Go to bleepingcomputer
-
Magento supply chain attack compromises hundreds of e-stores
Magento supply chain attack compromises hundreds of e-stores A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational. […] Bill Toulas Go to bleepingcomputer