Category: Security
-
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks A 36-year-old Yemeni national, who is believed to be the developer and primary operator of ‘Black Kingdom’ ransomware, has been indicted by the United States for conducting 1,500 attacks on Microsoft Exchange servers. […] Bill Toulas Go to bleepingcomputer
-
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call
UK NCSC: Cyberattacks impacting UK retailers are a wake-up call The United Kingdom’s National Cyber Security Centre warned that ongoing cyberattacks impacting multiple UK retail chains should be taken as a “wake-up call.” […] Sergiu Gatlan Go to bleepingcomputer
-
TikTok fined €530 million for sending European user data to China
TikTok fined €530 million for sending European user data to China The Irish Data Protection Commission (DPC) has fined TikTok €530 million (over $601 million) for illegally transferring the personal data of users in the European Economic Area (EEA) to China, violating the European Union’s GDPR data protection regulations. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft makes all new accounts passwordless by default
Microsoft makes all new accounts passwordless by default Microsoft has announced that all new Microsoft accounts will be “passwordless by default” to secure them against password attacks such as phishing, brute force, and credential stuffing. […] Sergiu Gatlan Go to bleepingcomputer
-
Hacker ‘NullBulge’ pleads guilty to stealing Disney’s Slack data
Hacker ‘NullBulge’ pleads guilty to stealing Disney’s Slack data A California man who used the alias “NullBulge” has pleaded guilty to illegally accessing Disney’s internal Slack channels and stealing over 1.1 terabytes of internal company data. […] Lawrence Abrams Go to bleepingcomputer
-
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks
Pro-Russia hacktivists bombard Dutch public orgs with DDoS attacks Russia-aligned hacktivists persistently target key public and private organizations in the Netherlands with distributed denial of service (DDoS) attacks, causing access problems and service disruptions. […] Bill Toulas Go to bleepingcomputer
-
Ukrainian extradited to US for Nefilim ransomware attacks
Ukrainian extradited to US for Nefilim ransomware attacks A Ukrainian national has been extradited from Spain to the United States to face charges over allegedly conducting Nefilim ransomware attacks against companies. […] Lawrence Abrams Go to bleepingcomputer
-
Harrods the next UK retailer targeted in a cyberattack
Harrods the next UK retailer targeted in a cyberattack London’s iconic department store, Harrods, has confirmed it was targeted in a cyberattack, becoming the third major UK retailer to report cyberattacks in a week following incidents at M&S and the Co-op. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers abuse IPv6 networking feature to hijack software updates
Hackers abuse IPv6 networking feature to hijack software updates A China-aligned APT threat actor named “TheWizards” abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress plugin disguised as a security tool injects backdoor
WordPress plugin disguised as a security tool injects backdoor A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it. […] Bill Toulas Go to bleepingcomputer
-
WhatsApp unveils ‘Private Processing’ for cloud-based AI features
WhatsApp unveils ‘Private Processing’ for cloud-based AI features WhatsApp has announced the introduction of ‘Private Processing,’ a new technology that enables users to utilize advanced AI features by offloading tasks to privacy-preserving cloud servers. […] Bill Toulas Go to bleepingcomputer
-
SonicWall: SMA100 VPN vulnerabilities now exploited in attacks
SonicWall: SMA100 VPN vulnerabilities now exploited in attacks Cybersecurity company SonicWall has warned customers that several vulnerabilities impacting its Secure Mobile Access (SMA) appliances are now being actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Commvault says recent breach didn’t impact customer backup data
Commvault says recent breach didn’t impact customer backup data Commvault, a leading provider of data protection solutions, says a nation-state threat actor who breached its Azure environment didn’t gain access to customer backup data. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows Server hotpatching to require subscription
Microsoft: Windows Server hotpatching to require subscription Microsoft has announced it will require paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers ramp up scans for leaked Git tokens and secrets
Hackers ramp up scans for leaked Git tokens and secrets Threat actors are intensifying internet-wide scanning for Git configuration files that can reveal sensitive secrets and authentication tokens used to compromise cloud services and source code repositories. […] Bill Toulas Go to bleepingcomputer
-
France ties Russian APT28 hackers to 12 cyberattacks on French orgs
France ties Russian APT28 hackers to 12 cyberattacks on French orgs Today, the French foreign ministry blamed the APT28 hacking group linked to Russia’s military intelligence service (GRU) for targeting or breaching a dozen French entities over the last four years. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks
Apple ‘AirBorne’ flaws can lead to zero-click AirPlay RCE attacks A set of security vulnerabilities in Apple’s AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code execution. […] Sergiu Gatlan Go to bleepingcomputer
-
Marks & Spencer breach linked to Scattered Spider ransomware attack
Marks & Spencer breach linked to Scattered Spider ransomware attack Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted by a hacking collective known as “Scattered Spider” BleepingComputer has learned from multiple sources. […] Lawrence Abrams Go to bleepingcomputer
-
Hitachi Vantara takes servers offline after Akira ransomware attack
Hitachi Vantara takes servers offline after Akira ransomware attack Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. […] Sergiu Gatlan Go to bleepingcomputer
-
VeriSource now says February data breach impacts 4 million people
VeriSource now says February data breach impacts 4 million people Employee benefits administration firm VeriSource Services is warning that a data breach exposed the personal information of four million people. […] Bill Toulas Go to bleepingcomputer
-
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux warns of update failures after losing repo signing key
Kali Linux warns of update failures after losing repo signing key Offensive Security warned Kali Linux users to manually install a new Kali repository signing key to avoid experiencing update failures. […] Sergiu Gatlan Go to bleepingcomputer
-
Coinbase fixes 2FA log error making people think they were hacked
Coinbase fixes 2FA log error making people think they were hacked Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
Brave’s Cookiecrumbler tool taps community to help block cookie notices
Brave’s Cookiecrumbler tool taps community to help block cookie notices Brave has open-sourceed a new tool called “Cookiecrumbler,” which uses large language models (LLMs) to detect cookie consent notices and then community-driven reviews to block those that won’t break site functionality. […] Bill Toulas Go to bleepingcomputer
-
DragonForce expands ransomware model with white-label branding scheme
DragonForce expands ransomware model with white-label branding scheme The ransomware scene is re-organizing, with one gang known as DragonForce working to gather other operations under a cartel-like structure. […] Ionut Ilascu Go to bleepingcomputer
-
WooCommerce admins targeted by fake security patches that hijack sites
WooCommerce admins targeted by fake security patches that hijack sites A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a “critical patch” that adds a WordPress backdoor to the site. […] Bill Toulas Go to bleepingcomputer
-
Craft CMS RCE exploit chain used in zero-day attacks to steal data
Craft CMS RCE exploit chain used in zero-day attacks to steal data Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense. […] Lawrence Abrams Go to bleepingcomputer
-
Marks & Spencer pauses online orders after cyberattack
Marks & Spencer pauses online orders after cyberattack British retailer giant Marks & Spencer (M&S) has suspended online orders while working to recover from a recently disclosed cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Mobile provider MTN says cyberattack compromised customer data
Mobile provider MTN says cyberattack compromised customer data African mobile giant MTN Group announced that a cybersecurity incident has compromised the personal information of some of its subscribers in certain countries. […] Bill Toulas Go to bleepingcomputer
-
FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches
FBI seeks help to unmask Salt Typhoon hackers behind telecom breaches The FBI has asked the public for information on Chinese Salt Typhoon hackers behind widespread breaches of telecommunications providers in the United States and worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts
Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts Russian threat actors have been abusing legitimate OAuth 2.0 authentication workflows to hijack Microsoft 365 accounts of employees of organizations related to Ukraine and human rights. […] Bill Toulas Go to bleepingcomputer
-
Lazarus hackers breach six companies in watering hole attacks
Lazarus hackers breach six companies in watering hole attacks In a recent espionage campaign, the infamous North Korean threat group Lazarus targeted multiple organizations in the software, IT, finance, and telecommunications sectors in South Korea. […] Bill Toulas Go to bleepingcomputer
-
Russian army targeted by new Android malware hidden in mapping app
Russian army targeted by new Android malware hidden in mapping app A new Android malware has been discovered hidden inside trojanized versions of the Alpine Quest mapping app, which is reportedly used by Russian soldiers as part of war zone operational planning. […] Bill Toulas Go to bleepingcomputer
-
WhatsApp’s new Advanced Chat Privacy protects sensitive messages
WhatsApp’s new Advanced Chat Privacy protects sensitive messages WhatsApp has introduced a new Advanced Chat Privacy feature to protect sensitive information exchanged in private chats and group conversations. […] Sergiu Gatlan Go to bleepingcomputer
-
Blue Shield of California leaked health data of 4.7 million members to Google
Blue Shield of California leaked health data of 4.7 million members to Google Blue Shield of California disclosed it suffered a data breach after exposing protected health information of 4.7 million members to Google’s analytics and advertisement platforms. […] Bill Toulas Go to bleepingcomputer
-
FBI: US lost record $16.6 billion to cybercrime in 2024
FBI: US lost record $16.6 billion to cybercrime in 2024 The FBI says cybercriminals have stolen a record $16,6 billion in 2024, marking an increase in losses of over 33% compared to the previous year. […] Sergiu Gatlan Go to bleepingcomputer
-
ASUS releases fix for AMI bug that lets hackers brick servers
ASUS releases fix for AMI bug that lets hackers brick servers ASUS has released security updates to address CVE-2024-54085, a maximum severity flaw that could allow attackers to hijack and potentially brick servers. […] Bill Toulas Go to bleepingcomputer
-
Marks & Spencer confirms a cyberattack as customers face delayed orders
Marks & Spencer confirms a cyberattack as customers face delayed orders Marks & Spencer (M&S) has disclosed that it is responding to a cyberattack over the past few days that has impacted operations, including its Click and Collect service. […] Lawrence Abrams Go to bleepingcomputer
-
Active! Mail RCE flaw exploited in attacks on Japanese orgs
Active! Mail RCE flaw exploited in attacks on Japanese orgs An Active! Mail zero-day remote code execution vulnerability is actively exploited in attacks on large organizations in Japan. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Zoom remote control feature for crypto-theft attacks
Hackers abuse Zoom remote control feature for crypto-theft attacks A hacking group dubbed ‘Elusive Comet’ targets cryptocurrency users in social engineering attacks that exploit Zoom’s remote control feature to trick users into granting them access to their machines. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Entra account lockouts caused by user token logging mishap
Microsoft Entra account lockouts caused by user token logging mishap Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress ad-fraud plugins generated 1.4 billion ad requests per day
WordPress ad-fraud plugins generated 1.4 billion ad requests per day A large-scale ad fraud operation called ‘Scallywag’ is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that generate billions of daily fraudulent requests. […] Bill Toulas Go to bleepingcomputer
-
Phishers abuse Google OAuth to spoof Google in DKIM replay attack
Phishers abuse Google OAuth to spoof Google in DKIM replay attack In a rather clever attack, hackers leveraged a weakness that allowed them to send a fake email that seemed delivered from Google’s systems, passing all verifications but pointing to a fraudulent page that collected logins. […] Ionut Ilascu Go to bleepingcomputer
-
State-sponsored hackers embrace ClickFix social engineering tactic
State-sponsored hackers embrace ClickFix social engineering tactic ClickFix attacks are being increasingly adopted by threat actors of all levels, with researchers now seeing multiple advanced persistent threat (APT) groups from North Korea, Iran, and Russia utilizing the tactic to breach networks. […] Bill Toulas Go to bleepingcomputer
-
Widespread Microsoft Entra lockouts tied to new security feature rollout
Widespread Microsoft Entra lockouts tied to new security feature rollout Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID’s “leaked credentials” detection app called MACE. […] Lawrence Abrams Go to bleepingcomputer
-
New Android malware steals your credit cards for NFC relay attacks
New Android malware steals your credit cards for NFC relay attacks A new malware-as-a-service (MaaS) platform named ‘SuperCard X’ has emerged, targeting Android devices via NFC relay attacks that enable point-of-sale and ATM transactions using compromised payment card data. […] Bill Toulas Go to bleepingcomputer
-
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now
Critical Erlang/OTP SSH RCE bug now has public exploits, patch now Public exploits are now available for a critical Erlang/OTP SSH vulnerability tracked as CVE-2025-32433, allowing unauthenticated attackers to remotely execute code on impacted devices. […] Lawrence Abrams Go to bleepingcomputer
-
Interlock ransomware gang pushes fake IT tools in ClickFix attacks
Interlock ransomware gang pushes fake IT tools in ClickFix attacks The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices. […] Bill Toulas Go to bleepingcomputer
-
FBI: Scammers pose as FBI IC3 employees to ‘help’ recover lost funds
FBI: Scammers pose as FBI IC3 employees to ‘help’ recover lost funds The FBI warns that scammers posing as FBI IC3 employees are offering to “help” fraud victims recover money lost to other scammers. […] Sergiu Gatlan Go to bleepingcomputer
-
ASUS warns of critical auth bypass flaw in routers using AiCloud
ASUS warns of critical auth bypass flaw in routers using AiCloud ASUS is warning about an authentication bypass vulnerability in routers with AiCloud enabled that could allow remote attackers to perform unauthorized execution of functions on the device. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA VPN devices targeted in attacks since January
SonicWall SMA VPN devices targeted in attacks since January A remote code execution vulnerability affecting SonicWall Secure Mobile Access (SMA) appliances has been under active exploitation since at least January 2025, according to cybersecurity company Arctic Wolf. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Erlang/OTP SSH pre-auth RCE is ‘Surprisingly Easy’ to exploit, patch now
Critical Erlang/OTP SSH pre-auth RCE is ‘Surprisingly Easy’ to exploit, patch now A critical vulnerability in the Erlang/OTP SSH, tracked as CVE-2025-32433, has been disclosed that allows for unauthenticated remote code execution on vulnerable devices. […] Lawrence Abrams Go to bleepingcomputer
-
Entertainment services giant Legends International discloses data breach
Entertainment services giant Legends International discloses data breach Entertainment venue management firm Legends International warns it suffered a data breach in November 2024, which has impacted employees and people who visited venues under its management. […] Bill Toulas Go to bleepingcomputer
-
Chrome extensions with 6 million installs have hidden tracking code
Chrome extensions with 6 million installs have hidden tracking code A set of 57 Chrome extensions with 6,000,000 users have been discovered with very risky capabilities, such as monitoring browsing behavior, accessing cookies for domains, and potentially executing remote scripts. […] Bill Toulas Go to bleepingcomputer
-
Windows NTLM hash leak flaw exploited in phishing attacks on governments
Windows NTLM hash leak flaw exploited in phishing attacks on governments A Windows vulnerability that exposes NTLM hashes using .library-ms files is now actively exploited by hackers in phishing campaigns targeting government entities and private companies. […] Bill Toulas Go to bleepingcomputer
-
Ahold Delhaize confirms data theft after INC ransomware claims attack
Ahold Delhaize confirms data theft after INC ransomware claims attack Food retail giant Ahold Delhaize confirms that data was stolen from its U.S. business systems during a November 2024 cyberattack. […] Bill Toulas Go to bleepingcomputer
-
CISA tags SonicWall VPN flaw as actively exploited in attacks
CISA tags SonicWall VPN flaw as actively exploited in attacks On Wednesday, CISA warned federal agencies to secure their SonicWall Secure Mobile Access (SMA) 100 series appliances against attacks exploiting a high-severity remote code execution vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 16,000 Fortinet devices compromised with symlink backdoor
Over 16,000 Fortinet devices compromised with symlink backdoor Over 16,000 internet-exposed Fortinet devices have been detected as compromised with a new symlink backdoor that allows read-only access to sensitive files on previously compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
Apple fixes two zero-days exploited in targeted iPhone attacks
Apple fixes two zero-days exploited in targeted iPhone attacks Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an “extremely sophisticated attack” against specific targets’ iPhones. […] Lawrence Abrams Go to bleepingcomputer
-
MITRE warns that funding for critical CVE program expires today
MITRE warns that funding for critical CVE program expires today MITRE Vice President Yosry Barsoum has warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) programs expires today, which could lead to widespread disruption across the global cybersecurity industry. […] Sergiu Gatlan Go to bleepingcomputer
-
Midnight Blizzard deploys new GrapeLoader malware in embassy phishing
Midnight Blizzard deploys new GrapeLoader malware in embassy phishing Russian state-sponsored espionage group Midnight Blizzard is behind a new spear-phishing campaign targeting diplomatic entities in Europe, including embassies. […] Bill Toulas Go to bleepingcomputer
-
Landmark Admin data breach impact now reaches 1.6 million people
Landmark Admin data breach impact now reaches 1.6 million people Landmark Admin has issued an update to its investigation of a cyberattack it suffered in May 2024, increasing the number of impacted individuals to 1.6 million. […] Bill Toulas Go to bleepingcomputer
-
Infamous message board 4chan taken down following major hack
Infamous message board 4chan taken down following major hack 4chan, a notorious online forum, was taken offline earlier today after what appears to be a significant hack and has since been loading intermittently. […] Sergiu Gatlan Go to bleepingcomputer
-
Hertz confirms customer info, drivers’ licenses stolen in data breach
Hertz confirms customer info, drivers’ licenses stolen in data breach Car rental giant Hertz Corporation warns it suffered a data breach after customer data for its Hertz, Thrifty, and Dollar brands was stolen in the Cleo zero-day data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Govtech giant Conduent confirms client data stolen in January cyberattack
Govtech giant Conduent confirms client data stolen in January cyberattack American business services giant and government contractor Conduent disclosed today that client data was stolen in a January 2025 cyberattack. […] Lawrence Abrams Go to bleepingcomputer
-
Cybersecurity firm buying hacker forum accounts to spy on cybercriminals
Cybersecurity firm buying hacker forum accounts to spy on cybercriminals Swiss cybersecurity firm Prodaft has launched a new initiative called ‘Sell your Source’ where the company purchases verified and aged accounts on hacking forums to to spy on cybercriminals. […] Bill Toulas Go to bleepingcomputer
-
SSL/TLS certificate lifespans reduced to 47 days by 2029
SSL/TLS certificate lifespans reduced to 47 days by 2029 The CA/Browser Forum has voted to significantly reduce the lifespan of SSL/TLS certificates over the next 4 years, with a final lifespan of just 47 days starting in 2029. […] Bill Toulas Go to bleepingcomputer
-
New ResolverRAT malware targets pharma and healthcare orgs worldwide
New ResolverRAT malware targets pharma and healthcare orgs worldwide A new remote access trojan (RAT) called ‘ResolverRAT’ is being used against organizations globally, with the malware used in recent attacks targeting the healthcare and pharmaceutical sectors. […] Bill Toulas Go to bleepingcomputer
-
Tycoon2FA phishing kit targets Microsoft 365 with new tricks
Tycoon2FA phishing kit targets Microsoft 365 with new tricks Phishing-as-a-service (PhaaS) platform Tycoon2FA, known for bypassing multi-factor authentication on Microsoft 365 and Gmail accounts, has received updates that improve its stealth and evasion capabilities. […] Bill Toulas Go to bleepingcomputer
-
AI-hallucinated code dependencies become new supply chain risk
AI-hallucinated code dependencies become new supply chain risk A new class of supply chain attacks named ‘slopsquatting’ has emerged from the increased use of generative AI tools for coding and the model’s tendency to “hallucinate” non-existent package names. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender will isolate undiscovered endpoints to block attacks
Microsoft Defender will isolate undiscovered endpoints to block attacks Microsoft is testing a new Defender for Endpoint capability that will block traffic to and from undiscovered endpoints to thwart attackers’ lateral network movement attempts. […] Sergiu Gatlan Go to bleepingcomputer
-
Western Sydney University discloses security breaches, data leak
Western Sydney University discloses security breaches, data leak Western Sydney University (WSU) announced two security incidents that exposed personal information belonging to members of its community. […] Bill Toulas Go to bleepingcomputer
-
Fortinet: Hackers retain access to patched FortiGate VPNs using symlinks
Fortinet: Hackers retain access to patched FortiGate VPNs using symlinks Fortinet warns that threat actors use a post-exploitation technique that helps them maintain read-only access to previously compromised FortiGate VPN devices even after the original attack vector was patched. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete Microsoft has now confirmed that an April 2025 Windows security update is creating a new empty “inetpub” folder and warned users not to delete it. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit WordPress plugin auth bypass hours after disclosure
Hackers exploit WordPress plugin auth bypass hours after disclosure Hackers started exploiting a high-severity flaw that allows bypassing authentication in the OttoKit (formerly SureTriggers) plugin for WordPress just hours after public disclosure. […] Bill Toulas Go to bleepingcomputer
-
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials
Hackers target SSRF bugs in EC2-hosted sites to steal AWS credentials A targeted campaign exploited Server-Side Request Forgery (SSRF) vulnerabilities in websites hosted on AWS EC2 instances to extract EC2 Metadata, which could include Identity and Access Management (IAM) credentials from the IMDSv1 endpoint. […] Bill Toulas Go to bleepingcomputer
-
Oracle says “obsolete servers” hacked, denies cloud breach
Oracle says “obsolete servers” hacked, denies cloud breach Oracle finally confirmed in email notifications sent to customers that a hacker stole and leaked credentials that were stolen from what it described as “two obsolete servers.” […] Sergiu Gatlan Go to bleepingcomputer
-
Fake Microsoft Office add-in tools push malware via SourceForge
Fake Microsoft Office add-in tools push malware via SourceForge Threat actors are abusing SourceForge to distribute fake Microsoft add-ins that install malware on victims’ computers to both mine and steal cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft: Windows CLFS zero-day exploited by ransomware gang Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims’ systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws Today is Microsoft’s April 2025 Patch Tuesday, which includes security updates for 134 flaws, including one actively exploited zero-day vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research. […] Bill Toulas Go to bleepingcomputer
-
Six arrested for AI-powered investment scams that stole $20 million
Six arrested for AI-powered investment scams that stole $20 million Spain’s police arrested six individuals behind a large-scale cryptocurrency investment scam that used AI tools to generate deepfake ads featuring popular public figures to lure people. […] Bill Toulas Go to bleepingcomputer
-
Everest ransomware’s dark web leak site defaced, now offline
Everest ransomware’s dark web leak site defaced, now offline The dark web leak site of the Everest ransomware gang has apparently been hacked over the weekend by an unknown attacker and is now offline. […] Sergiu Gatlan Go to bleepingcomputer
-
Google fixes Android zero-days exploited in attacks, 60 other flaws
Google fixes Android zero-days exploited in attacks, 60 other flaws Google has released patches for 62 vulnerabilities in Android’s April 2025 security update, including two zero-days exploited in targeted attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
E-ZPass toll payment texts return in massive phishing wave
E-ZPass toll payment texts return in massive phishing wave An ongoing phishing campaign impersonating E-ZPass and other toll agencies has surged recently, with recipients receiving multiple iMessage and SMS texts to steal personal and credit card information. […] Bill Toulas Go to bleepingcomputer
-
Carding tool abusing WooCommerce API downloaded 34K times on PyPI
Carding tool abusing WooCommerce API downloaded 34K times on PyPI A newly discovered malicious PyPi package named ‘disgrasya’ that abuses legitimate WooCommerce stores for validating stolen credit cards has been downloaded over 34,000 times from the open-source package platform. […] Bill Toulas Go to bleepingcomputer
-
Coinbase to fix 2FA account activity entry freaking out users
Coinbase to fix 2FA account activity entry freaking out users Coinbase is fixing an incorrect account activity message that freaks out customers and makes them think their credentials were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
WinRAR flaw bypasses Windows Mark of the Web security alerts
WinRAR flaw bypasses Windows Mark of the Web security alerts A vulnerability in the WinRAR file archiver solution could be exploited to bypass the Mark of the Web (MotW) security warning and execute arbitrary code on a Windows machine. […] Ionut Ilascu Go to bleepingcomputer
-
Port of Seattle says ransomware breach impacts 90,000 people
Port of Seattle says ransomware breach impacts 90,000 people Port of Seattle, the U.S. government agency overseeing Seattle’s seaport and airport, is notifying roughly 90,000 individuals of a data breach after their personal information was stolen in an August 2024 ransomware attack. […] Sergiu Gatlan Go to bleepingcomputer
-
PoisonSeed phishing campaign behind emails with wallet seed phrases
PoisonSeed phishing campaign behind emails with wallet seed phrases A large-scale phishing campaign dubbed ‘PoisonSeed’ compromises corporate email marketing accounts to distribute emails containing crypto seed phrases used to drain cryptocurrency wallets. […] Bill Toulas Go to bleepingcomputer
-
Australian pension funds hit by wave of credential stuffing attacks
Australian pension funds hit by wave of credential stuffing attacks Over the weekend, a massive wave of credential stuffing attacks hit multiple large Australian super funds, compromising thousands of members’ accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Europcar GitLab breach exposes data of up to 200,000 customers
Europcar GitLab breach exposes data of up to 200,000 customers A hacker breached the GitLab repositories of multinational car-rental company Europcar Mobility Group and stole source code for Android and iOS applications, as well as some personal information belonging to up to 200,000 users. […] Ionut Ilascu Go to bleepingcomputer
-
Max severity RCE flaw discovered in widely used Apache Parquet
Max severity RCE flaw discovered in widely used Apache Parquet A maximum severity remote code execution (RCE) vulnerability has been discovered impacting all versions of Apache Parquet up to and including 1.15.0. […] Bill Toulas Go to bleepingcomputer
-
Hunters International shifts from ransomware to pure data extortion
Hunters International shifts from ransomware to pure data extortion The Hunters International Ransomware-as-a-Service (RaaS) operation is shutting down and rebranding with plans to switch to date theft and extortion-only attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA warns of Fast Flux DNS evasion used by cybercrime gangs
CISA warns of Fast Flux DNS evasion used by cybercrime gangs CISA, the FBI, the NSA, and international cybersecurity agencies are calling on organizations and DNS providers to mitigate the “Fast Flux” cybercrime evasion technique used by state-sponsored threat actors and ransomware gangs. […] Bill Toulas Go to bleepingcomputer
-
Ivanti patches Connect Secure zero-day exploited since mid-March
Ivanti patches Connect Secure zero-day exploited since mid-March Ivanti has released security updates to patch a critical Connect Secure remote code execution vulnerability exploited by a China-linked espionage actor to deploy malware since at least mid-March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Genetic data site openSNP to close and delete data over privacy concerns
Genetic data site openSNP to close and delete data over privacy concerns The openSNP project, a platform for sharing genetic and phenotypic data, will shut down on April 30, 2025, and delete all user submissions over privacy concerns and the risk of misuse by authoritarian governments. […] Bill Toulas Go to bleepingcomputer
-
Verizon Call Filter API flaw exposed customers’ incoming call history
Verizon Call Filter API flaw exposed customers’ incoming call history A vulnerability in Verizon’s Call Filter feature allowed customers to access the incoming call logs for another Verizon Wireless number through an unsecured API request. […] Bill Toulas Go to bleepingcomputer
-
GitHub expands security tools after 39 million secrets leaked in 2024
GitHub expands security tools after 39 million secrets leaked in 2024 Over 39 million secrets like API keys and account credentials were leaked on GitHub throughout 2024, exposing organizations and users to significant security risks. […] Bill Toulas Go to bleepingcomputer
-
Microsoft adds hotpatching support to Windows 11 Enterprise
Microsoft adds hotpatching support to Windows 11 Enterprise Microsoft has announced that hotpatch updates are now available for business customers using Windows 11 Enterprise 24H2 on x64 (AMD/Intel) systems, starting today. […] Sergiu Gatlan Go to bleepingcomputer