Category: Security
-
New SuperBlack ransomware exploits Fortinet auth bypass flaws
New SuperBlack ransomware exploits Fortinet auth bypass flaws A new ransomware operator named ‘Mora_001’ is exploiting two Fortinet vulnerabilities to gain unauthorized access to firewall appliances and deploy a custom ransomware strain dubbed SuperBlack. […] Bill Toulas Go to bleepingcomputer
-
Juniper patches bug that let Chinese cyberspies backdoor routers
Juniper patches bug that let Chinese cyberspies backdoor routers Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access. […] Sergiu Gatlan Go to bleepingcomputer
-
Facebook discloses FreeType 2 flaw exploited in attacks
Facebook discloses FreeType 2 flaw exploited in attacks Facebook is warning that a FreeType vulnerability in all versions up to 2.13 can lead to arbitrary code execution, with reports that the flaw has been exploited in attacks. […] Bill Toulas Go to bleepingcomputer
-
CISA: Medusa ransomware hit over 300 critical infrastructure orgs
CISA: Medusa ransomware hit over 300 critical infrastructure orgs CISA says the Medusa ransomware operation has impacted over 300 organizations in critical infrastructure sectors in the United States until last month. […] Sergiu Gatlan Go to bleepingcomputer
-
New North Korean Android spyware slips onto Google Play
New North Korean Android spyware slips onto Google Play A new Android spyware named ‘KoSpy’ is linked to North Korean threat actors who have infiltrated Google Play and third-party app store APKPure through at least five malicious apps. […] Bill Toulas Go to bleepingcomputer
-
Garantex crypto exchange admin arrested while on vacation
Garantex crypto exchange admin arrested while on vacation Indian authorities arrested Aleksej Besciokov, the co-founder and one of the administrators of the Russian Garantex crypto-exchange while vacationing with his family in Varkala, India. […] Sergiu Gatlan Go to bleepingcomputer
-
Mozilla warns users to update Firefox before certificate expires
Mozilla warns users to update Firefox before certificate expires Mozilla is warning Firefox users to update their browsers to the latest version to avoid facing disruption and security risks caused by the upcoming expiration of one of the company’s root certificates. […] Bill Toulas Go to bleepingcomputer
-
North Korean Lazarus hackers infect hundreds via npm packages
North Korean Lazarus hackers infect hundreds via npm packages Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in “extremely sophisticated” attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws Today is Microsoft’s March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
X hit by ‘massive cyberattack’ amid Dark Storm’s DDoS claims
X hit by ‘massive cyberattack’ amid Dark Storm’s DDoS claims The Dark Storm hacktivist group claims to be behind DDoS attacks causing multiple X worldwide outages on Monday, leading the company to enable DDoS protections from Cloudflare. […] Lawrence Abrams Go to bleepingcomputer
-
US govt says Americans lost record $12.5 billion to fraud in 2024
US govt says Americans lost record $12.5 billion to fraud in 2024 The U.S. Federal Trade Commission (FTC) said today that Americans lost a record $12.5 billion to fraud last year, a 25% increase over the previous year. […] Sergiu Gatlan Go to bleepingcomputer
-
FTC will send $25.5 million to victims of tech support scams
FTC will send $25.5 million to victims of tech support scams Later this week, the Federal Trade Commission (FTC) will start distributing over $25.5 million in refunds to those misled by tech support companies Restoro and Reimage’s scare tactics. […] Sergiu Gatlan Go to bleepingcomputer
-
Swiss critical sector faces new 24-hour cyberattack reporting rule
Swiss critical sector faces new 24-hour cyberattack reporting rule Switzerland’s National Cybersecurity Centre (NCSC) has announced a new reporting obligation for critical infrastructure organizations in the country, requiring them to report cyberattacks to the agency within 24 hours of their discovery. […] Bill Toulas Go to bleepingcomputer
-
US cities warn of wave of unpaid parking phishing texts
US cities warn of wave of unpaid parking phishing texts US cities are warning of an ongoing mobile phishing campaign pretending to be texts from the city’s parking violation departments about unpaid parking invoices, that if unpaid, will incur an additional $35 fine per day. […] Lawrence Abrams Go to bleepingcomputer
-
Developer guilty of using kill switch to sabotage employer’s systems
Developer guilty of using kill switch to sabotage employer’s systems A software developer has been found guilty of sabotaging his ex-employer’s systems by running custom malware and installing a “kill switch” after being demoted at the company. […] Lawrence Abrams Go to bleepingcomputer
-
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
Undocumented “backdoor” found in Bluetooth chip used by a billion devices The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented “backdoor” that could be leveraged for attacks. […] Bill Toulas Go to bleepingcomputer
-
YouTubers extorted via copyright strikes to spread malware
YouTubers extorted via copyright strikes to spread malware Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos. […] Bill Toulas Go to bleepingcomputer
-
US seizes $23 million in crypto stolen via password manager breach
US seizes $23 million in crypto stolen via password manager breach U.S. authorities have seized over $23 million in cryptocurrency linked to the theft of $150 million from a Ripple crypto wallet in January 2024. Investigators believe hackers who breached LastPass in 2022 were behind the attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Unpatched Edimax IP camera flaw actively exploited in botnet attacks
Unpatched Edimax IP camera flaw actively exploited in botnet attacks A critical command injection vulnerability impacting the Edimax IC-7100 IP camera is currently being exploited by botnet malware to compromise devices. […] Bill Toulas Go to bleepingcomputer
-
Employee charged with stealing unreleased movies, sharing them online
Employee charged with stealing unreleased movies, sharing them online A Memphis man was arrested and charged with stealing DVDs and Blu-ray discs of unreleased movies and sharing ripped digital copies online before their release. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges Garantex admins with money laundering, sanctions violations
US charges Garantex admins with money laundering, sanctions violations The administrators of the Russian Garantex crypto-exchange have been charged in the United States with facilitating money laundering for criminal organizations and violating sanctions. […] Sergiu Gatlan Go to bleepingcomputer
-
Data breach at Japanese telecom giant NTT hits 18,000 companies
Data breach at Japanese telecom giant NTT hits 18,000 companies Japanese telecommunication services provider NTT Communications Corporation (NTT) is warning almost 18,000 corporate customers that their information was compromised during a cybersecurity incident. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says malvertising campaign impacted 1 million PCs
Microsoft says malvertising campaign impacted 1 million PCs Microsoft has taken down an undisclosed number of GitHub repositories used in a massive malvertising campaign that impacted almost one million devices worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gang encrypted network from a webcam to bypass EDR
Ransomware gang encrypted network from a webcam to bypass EDR The Akira ransomware gang was spotted using an unsecured webcam to launch encryption attacks on a victim’s network, effectively circumventing Endpoint Detection and Response (EDR), which was blocking the encryptor in Windows. […] Bill Toulas Go to bleepingcomputer
-
US seizes domain of Garantex crypto exchange used by ransomware gangs
US seizes domain of Garantex crypto exchange used by ransomware gangs The U.S. Secret Service has seized the domain of the sanctioned Russian cryptocurrency exchange Garantex in collaboration with the Department of Justice’s Criminal Division, the FBI, and Europol. […] Sergiu Gatlan Go to bleepingcomputer
-
Cybercrime ‘crew’ stole $635,000 in Taylor Swift concert tickets
Cybercrime ‘crew’ stole $635,000 in Taylor Swift concert tickets New York prosecutors say that two people working at a third-party contractor for the StubHub online ticket marketplace made $635,000 after almost 1,000 concert tickets and reselling them online. […] Sergiu Gatlan Go to bleepingcomputer
-
Ethereum private key stealer on PyPI downloaded over 1,000 times
Ethereum private key stealer on PyPI downloaded over 1,000 times A malicious Python Package Index (PyPI) package named “set-utils” has been stealing Ethereum private keys through intercepted wallet creation functions and exfiltrating them via the Polygon blockchain. […] Bill Toulas Go to bleepingcomputer
-
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks The Electronic Frontier Foundation (EFF) has released a free, open-source tool named Rayhunter that is designed to detect cell-site simulators (CSS), also known as IMSI catchers or Stingrays. […] Bill Toulas Go to bleepingcomputer
-
Silk Typhoon hackers now target IT supply chains to breach networks
Silk Typhoon hackers now target IT supply chains to breach networks Microsoft warns that Chinese cyber-espionage threat group ‘Silk Typhoon’ has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. […] Bill Toulas Go to bleepingcomputer
-
US charges Chinese hackers linked to critical infrastructure breaches
US charges Chinese hackers linked to critical infrastructure breaches The US Justice Department has charged Chinese state security officers along with APT27 and i-Soon hackers for network breaches and cyberattacks that have targeted victims globally since 2011. […] Sergiu Gatlan Go to bleepingcomputer
-
BadBox malware disrupted on 500K infected Android devices
BadBox malware disrupted on 500K infected Android devices The BadBox Android malware botnet has been disrupted again by removing 24 malicious apps from Google Play and sinkholing communications for half a million infected devices. […] Bill Toulas Go to bleepingcomputer
-
YouTube warns of AI-generated video of its CEO used in phishing attacks
YouTube warns of AI-generated video of its CEO used in phishing attacks YouTube warns that scammers are using an AI-generated video featuring the company’s CEO in phishing attacks to steal creators’ credentials. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake BianLian ransom notes mailed to US CEOs in postal mail scam
Fake BianLian ransom notes mailed to US CEOs in postal mail scam Scammers are impersonating the BianLian ransomware gang in fake ransom notes sent to US companies via snail mail through the United States Postal Service. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks. […] Lawrence Abrams Go to bleepingcomputer
-
New Eleven11bot botnet infects 86,000 devices for DDoS attacks
New Eleven11bot botnet infects 86,000 devices for DDoS attacks A new botnet malware named ‘Eleven11bot’ has infected over 86,000 IoT devices, primarily security cameras and network video recorders (NVRs), to conduct DDoS attacks. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of Webex for BroadWorks flaw exposing credentials
Cisco warns of Webex for BroadWorks flaw exposing credentials Cisco warned customers today of a vulnerability in Webex for BroadWorks that could let unauthenticated attackers access credentials remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Google expands Android AI scam detection to more Pixel devices
Google expands Android AI scam detection to more Pixel devices Google has announced an increased rollout of new AI-powered scam detection features on Android to help protect users from increasingly sophisticated phone and text social engineering scams. […] Bill Toulas Go to bleepingcomputer
-
Rubrik rotates authentication keys after log server breach
Rubrik rotates authentication keys after log server breach Rubrik disclosed last month that one of its servers hosting log files was breached, causing the company to rotate potentially leaked authentication keys. […] Lawrence Abrams Go to bleepingcomputer
-
DHS says CISA will not stop monitoring Russian cyber threats
DHS says CISA will not stop monitoring Russian cyber threats The US Cybersecurity and Infrastructure Security Agency says that media reports about it being directed to no longer follow or report on Russian cyber activity are untrue, and its mission remains unchanged. […] Lawrence Abrams Go to bleepingcomputer
-
CISA tags Windows, Cisco vulnerabilities as actively exploited
CISA tags Windows, Cisco vulnerabilities as actively exploited CISA has warned US federal agencies to secure their systems against attacks exploiting vulnerabilities in Cisco and Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint A newly uncovered ClickFix phishing campaign is tricking victims into executing malicious PowerShell commands that deploy the Havok post-exploitation framework for remote access to compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. […] Bill Toulas Go to bleepingcomputer
-
U.S. recovers $31 million stolen in 2021 Uranium Finance hack
U.S. recovers $31 million stolen in 2021 Uranium Finance hack U.S. authorities recovered $31 million in cryptocurrency stolen in 2021 cyberattacks on Uranium Finance, a Binance Smart Chain-based DeFi protocol. […] Bill Toulas Go to bleepingcomputer
-
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data The Qilin ransomware gang has claimed responsibility for the attack at Lee Enterprises that disrupted operations on February 3, leaking samples of data they claim was stolen from the company. […] Bill Toulas Go to bleepingcomputer
-
Police arrests suspects tied to AI-generated CSAM distribution ring
Police arrests suspects tied to AI-generated CSAM distribution ring Law enforcement agencies from 19 countries have arrested 25 suspects linked to a criminal ring that was distributing child sexual abuse material (CSAM) generated using artificial intelligence (AI). […] Sergiu Gatlan Go to bleepingcomputer
-
Serbian police used Cellebrite zero-day hack to unlock Android phones
Serbian police used Cellebrite zero-day hack to unlock Android phones Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. […] Bill Toulas Go to bleepingcomputer
-
Vo1d malware botnet grows to 1.6 million Android TVs worldwide
Vo1d malware botnet grows to 1.6 million Android TVs worldwide A new variant of the Vo1d malware botnet has grown to 1,590,299 infected Android TV devices across 226 countries, recruiting devices as part of anonymous proxy server networks. […] Bill Toulas Go to bleepingcomputer
-
Privacy tech firms warn France’s encryption and VPN laws threaten privacy
Privacy tech firms warn France’s encryption and VPN laws threaten privacy Privacy-focused email provider Tuta (previously Tutanota) and the VPN Trust Initiative (VTI) are raising concerns over proposed laws in France set to backdoor encrypted messaging systems and restrict internet access. […] Bill Toulas Go to bleepingcomputer
-
Over 49,000 misconfigured building access systems exposed online
Over 49,000 misconfigured building access systems exposed online Researchers discovered 49,000 misconfigured and exposed Access Management Systems (AMS) across multiple industries and countries, which could compromise privacy and physical security in critical sectors. […] Bill Toulas Go to bleepingcomputer
-
Belgium probes if Chinese hackers breached its intelligence service
Belgium probes if Chinese hackers breached its intelligence service The Belgian federal prosecutor’s office is investigating whether Chinese hackers were behind a breach of the country’s State Security Service (VSSE). […] Sergiu Gatlan Go to bleepingcomputer
-
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist FBI has confirmed that North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit on Friday in the largest crypto heist recorded until now. […] Sergiu Gatlan Go to bleepingcomputer
-
Southern Water says Black Basta ransomware attack cost £4.5M in expenses
Southern Water says Black Basta ransomware attack cost £4.5M in expenses United Kingdom water supplier Southern Water has disclosed that it incurred costs of £4.5 million ($5.7M) due to a cyberattack it suffered in February 2024. […] Bill Toulas Go to bleepingcomputer
-
GrassCall malware campaign drains crypto wallets via fake job interviews
GrassCall malware campaign drains crypto wallets via fake job interviews A recent social engineering campaign targeted job seekers in the Web3 space with fake job interviews through a malicious “GrassCall” meeting app that installs information-stealing malware to steal cryptocurrency wallets. […] Lawrence Abrams Go to bleepingcomputer
-
VSCode extensions with 9 million installs pulled over security risks
VSCode extensions with 9 million installs pulled over security risks Microsoft has removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ from the Visual Studio Marketplace for allegedly containing malicious code. […] Bill Toulas Go to bleepingcomputer
-
PyPi package with 100K installs pirated music from Deezer for years
PyPi package with 100K installs pirated music from Deezer for years A malicious PyPi package named ‘automslc’ has been downloaded over 100,000 times from the Python Package Index since 2019, abusing hard-coded credentials to pirate music from the Deezer streaming service. […] Bill Toulas Go to bleepingcomputer
-
Have I Been Pwned adds 284M accounts stolen by infostealer malware
Have I Been Pwned adds 284M accounts stolen by infostealer malware The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel. […] Sergiu Gatlan Go to bleepingcomputer
-
Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers
Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers Mozilla has renewed its promise to continue supporting Manifest V2 extensions alongside Manifest V3, giving users the freedom to use the extensions they want in their browser. […] Bill Toulas Go to bleepingcomputer
-
OpenAI bans ChatGPT accounts used by North Korean hackers
OpenAI bans ChatGPT accounts used by North Korean hackers OpenAI says it blocked several North Korean hacking groups from using its ChatGPT platform to research future targets and find ways to hack into their networks. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia warns financial sector of major IT service provider hack
Russia warns financial sector of major IT service provider hack Russia’s National Coordination Center for Computer Incidents (NKTsKI) is warning organizations in the country’s credit and financial sector about a breach at LANIT, a major Russian IT service and software provider. […] Bill Toulas Go to bleepingcomputer
-
Australia bans all Kaspersky products on government systems
Australia bans all Kaspersky products on government systems The Australian government has banned all Kaspersky Lab products and web services from its systems and devices following an analysis that claims the company poses a significant security risk to the country. […] Bill Toulas Go to bleepingcomputer
-
Botnet targets Basic Auth in Microsoft 365 password spray attacks
Botnet targets Basic Auth in Microsoft 365 password spray attacks A massive botnet of over 130,000 compromised devices is conducting password-spray attacks against Microsoft 365 (M365) accounts worldwide, attempting to confirm credentials. […] Bill Toulas Go to bleepingcomputer
-
Google Cloud introduces quantum-safe digital signatures in KMS
Google Cloud introduces quantum-safe digital signatures in KMS Google Cloud has introduced quantum-safe digital signatures to its Cloud Key Management Service (Cloud KMS), making them available in preview. […] Bill Toulas Go to bleepingcomputer
-
Beware: PayPal “New Address” feature abused to send phishing emails
Beware: PayPal “New Address” feature abused to send phishing emails An ongoing PayPal email scam exploits the platform’s address settings to send fake purchase notifications, tricking users into granting remote access to scammers […] Lawrence Abrams Go to bleepingcomputer
-
Fake CS2 tournament streams used to steal crypto, Steam accounts
Fake CS2 tournament streams used to steal crypto, Steam accounts Threat actors are exploiting major Counter-Strike 2 (CS2) competitions, like IEM Katowice 2025 and PGL Cluj-Napoca 2025, to defraud gamers and steal their Steam accounts and cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
SpyLend Android malware downloaded 100,000 times from Google Play
SpyLend Android malware downloaded 100,000 times from Google Play An Android malware app called SpyLend has been downloaded over 100,000 times from Google Play, where it masqueraded as a financial tool but became a predatory loan app for those in India. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals record $1.46 billion from Bybit ETH cold wallet
Hacker steals record $1.46 billion from Bybit ETH cold wallet Cryptocurrency exchange Bybit revealed today that an unknown attacker stole over $1.46 billion worth of cryptocurrency from one of its ETH cold wallets. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA flags Craft CMS code injection flaw as exploited in attacks
CISA flags Craft CMS code injection flaw as exploited in attacks The U.S. Cybersecurity & Infrastructure Security Agency (CISA) warns that a Craft CMS remote code execution flaw is being exploited in attacks. […] Bill Toulas Go to bleepingcomputer
-
Apple pulls iCloud end-to-end encryption feature in the UK
Apple pulls iCloud end-to-end encryption feature in the UK Apple will no longer offer iCloud end-to-end encryption in the United Kingdom after the government requested a backdoor to access Apple customers’ encrypted cloud data. […] Sergiu Gatlan Go to bleepingcomputer
-
Apiiro unveils free scanner to detect malicious code merges
Apiiro unveils free scanner to detect malicious code merges Security researchers at Apiiro have released two free, open-source tools designed to detect and block malicious code before they are added to software projects to curb supply chain attacks. […] Bill Toulas Go to bleepingcomputer
-
Black Basta ransomware gang’s internal chat logs leak online
Black Basta ransomware gang’s internal chat logs leak online An unknown leaker has released what they claim to be an archive of internal Matrix chat logs belonging to the Black Basta ransomware operation. […] Sergiu Gatlan Go to bleepingcomputer
-
US healthcare org pays $11M settlement over alleged cybersecurity lapses
US healthcare org pays $11M settlement over alleged cybersecurity lapses Health Net Federal Services (HNFS) and its parent company, Centene Corporation, have agreed to pay $11,253,400 to settle allegations that HNFS falsely certified compliance with cybersecurity requirements under its Defense Health Agency (DHA) TRICARE contract. […] Bill Toulas Go to bleepingcomputer
-
Chinese hackers use custom malware to spy on US telecom networks
Chinese hackers use custom malware to spy on US telecom networks The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. telecommunication providers. […] Bill Toulas Go to bleepingcomputer
-
Integrating LLMs into security operations using Wazuh
Integrating LLMs into security operations using Wazuh Large Language Models (LLMs) can provide many benefits to security professionals by helping them analyze logs, detect phishing attacks, or offering threat intelligence. Learn from Wazuh how to incorporate an LLM, like ChatGPT, into its open source security platform. […] Sponsored by Wazuh Go to bleepingcomputer
-
New NailaoLocker ransomware used against EU healthcare orgs
New NailaoLocker ransomware used against EU healthcare orgs A previously undocumented ransomware payload named NailaoLocker has been spotted in attacks targeting European healthcare organizations between June and October 2024. […] Bill Toulas Go to bleepingcomputer
-
CISA and FBI: Ghost ransomware breached orgs in 70 countries
CISA and FBI: Ghost ransomware breached orgs in 70 countries CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries, including critical infrastructure organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing attack hides JavaScript using invisible Unicode trick
Phishing attack hides JavaScript using invisible Unicode trick A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political action committee (PAC). […] Bill Toulas Go to bleepingcomputer
-
New FrigidStealer infostealer infects Macs via fake browser updates
New FrigidStealer infostealer infects Macs via fake browser updates The FakeUpdate malware campaigns are increasingly becoming muddled, with two additional cybercrime groups tracked as TA2726 and TA2727, running campaigns that push a new macOS infostealer malware called FrigidStealer. […] Bill Toulas Go to bleepingcomputer
-
Australian fertility services giant Genea hit by security breach
Australian fertility services giant Genea hit by security breach Genea, one of Australia’s largest fertility services providers, disclosed that unknown attackers breached its network and accessed data stored on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
WinRAR 7.10 boosts Windows privacy by stripping MoTW data
WinRAR 7.10 boosts Windows privacy by stripping MoTW data WinRAR 7.10 was released yesterday with numerous features, such as larger memory pages, a dark mode, and the ability to fine-tune how Windows Mark-of-the-Web flags are propagated when extracting files. […] Lawrence Abrams Go to bleepingcomputer
-
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners A large-scale malware campaign dubbed “StaryDobry” has been targeting gamers worldwide with trojanized versions of cracked games such as Garry’s Mod, BeamNG.drive, and Dyson Sphere Program. […] Bill Toulas Go to bleepingcomputer
-
Venture capital giant Insight Partners hit by cyberattack
Venture capital giant Insight Partners hit by cyberattack New York-based venture capital and private equity firm Insight Partners has disclosed that its systems were breached in January following a social engineering attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers abuse Microsoft APP-v tool to evade antivirus
Chinese hackers abuse Microsoft APP-v tool to evade antivirus The Chinese APT hacking group “Mustang Panda” has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. […] Bill Toulas Go to bleepingcomputer
-
Chase will soon block Zelle payments to sellers on social media
Chase will soon block Zelle payments to sellers on social media JPMorgan Chase Bank (Chase) will soon start blocking Zelle payments to social media contacts to combat a significant rise in online scams utilizing the service for fraud. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to remove the Location History feature in Windows
Microsoft to remove the Location History feature in Windows Microsoft announced the deprecation of the Location History feature from Windows, which let applications like the Cortana virtual assistant to fetch location history of the device. […] Bill Toulas Go to bleepingcomputer
-
X now blocks Signal contact links, flags them as malicious
X now blocks Signal contact links, flags them as malicious Social media platform X (formerly Twitter) is now blocking links to “Signal.me,” a URL used by the Signal encrypted messaging to share your account info with another person. […] Bill Toulas Go to bleepingcomputer
-
Microsoft spots XCSSET macOS malware variant used for crypto theft
Microsoft spots XCSSET macOS malware variant used for crypto theft A new variant of the XCSSET macOS modular malware has emerged in attacks that target users’ sensitive information, including digital wallets and data from the legitimate Notes app. […] Bill Toulas Go to bleepingcomputer
-
Google Chrome’s AI-powered security feature rolls out to everyone
Google Chrome’s AI-powered security feature rolls out to everyone Google Chrome has updated the existing “Enhanced protection” feature with AI to offer “real-time” protection against dangerous websites, downloads and extensions. […] Mayank Parmar Go to bleepingcomputer
-
New FinalDraft malware abuses Outlook mail service for stealthy comms
New FinalDraft malware abuses Outlook mail service for stealthy comms A new malware called FinalDraft has been using Outlook email drafts for command-and-control communication in attacks against a ministry in a South American country. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Hackers steal emails in device code phishing attacks
Microsoft: Hackers steal emails in device code phishing attacks An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit authentication bypass in Palo Alto Networks PAN-OS
Hackers exploit authentication bypass in Palo Alto Networks PAN-OS Hackers are launching attacks against Palo Alto Networks PAN-OS firewalls by exploiting a recently fixed vulnerability (CVE-2025-0108) that allows bypassing authentication. […] Bill Toulas Go to bleepingcomputer
-
SonicWall firewall bug leveraged in attacks after PoC exploit release
SonicWall firewall bug leveraged in attacks after PoC exploit release Attackers are now targeting an authentication bypass vulnerability affecting SonicWall firewalls shortly after the release of proof-of-concept (PoC) exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious PirateFi game infects Steam users with Vidar malware
Malicious PirateFi game infects Steam users with Vidar malware A free-to-play game named PirateFi in the Steam store has been distributing the Vidar infostealing malware to unsuspecting users. […] Bill Toulas Go to bleepingcomputer
-
PostgreSQL flaw exploited as zero-day in BeyondTrust breach
PostgreSQL flaw exploited as zero-day in BeyondTrust breach Rapid7’s vulnerability research team says attackers exploited a PostgreSQL security flaw as a zero-day to breach the network of privileged access management company BeyondTrust in December. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers breach more US telecoms via unpatched Cisco routers
Chinese hackers breach more US telecoms via unpatched Cisco routers China’s Salt Typhoon hackers are still actively targeting telecoms worldwide and have breached more U.S. telecommunications providers via unpatched Cisco IOS XE network devices. […] Sergiu Gatlan Go to bleepingcomputer
-
whoAMI attacks give hackers code execution on Amazon EC2 instances
whoAMI attacks give hackers code execution on Amazon EC2 instances Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name. […] Bill Toulas Go to bleepingcomputer
-
Hacker leaks account data of 12 million Zacks Investment users
Hacker leaks account data of 12 million Zacks Investment users Zacks Investment Research (Zacks) last year reportedly suffered another data breach that exposed sensitive information related to roughly 12 million accounts. […] Bill Toulas Go to bleepingcomputer
-
Chinese espionage tools deployed in RA World ransomware attack
Chinese espionage tools deployed in RA World ransomware attack A China-based threat actor, tracked as Emperor Dragonfly and commonly associated with cybercriminal endeavors, has been observed using in a ransomware attack a toolset previously attributed to espionage actors. […] Bill Toulas Go to bleepingcomputer
-
zkLend loses $9.5M in crypto heist, asks hacker to return 90%
zkLend loses $9.5M in crypto heist, asks hacker to return 90% Decentralized money lender zkLend suffered a breach where threat actors exploited a smart contract flaw to steal 3,600 Ethereum, worth $9.5 million at the time. […] Lawrence Abrams Go to bleepingcomputer
-
Surge in attacks exploiting old ThinkPHP and ownCloud flaws
Surge in attacks exploiting old ThinkPHP and ownCloud flaws Increased hacker activity has been observed in attempts to compromise poorly maintained devices that are vulnerable to older security issues from 2022 and 2023. […] Bill Toulas Go to bleepingcomputer