Category: Security
-
Google expands Android AI scam detection to more Pixel devices
Google expands Android AI scam detection to more Pixel devices Google has announced an increased rollout of new AI-powered scam detection features on Android to help protect users from increasingly sophisticated phone and text social engineering scams. […] Bill Toulas Go to bleepingcomputer
-
Rubrik rotates authentication keys after log server breach
Rubrik rotates authentication keys after log server breach Rubrik disclosed last month that one of its servers hosting log files was breached, causing the company to rotate potentially leaked authentication keys. […] Lawrence Abrams Go to bleepingcomputer
-
DHS says CISA will not stop monitoring Russian cyber threats
DHS says CISA will not stop monitoring Russian cyber threats The US Cybersecurity and Infrastructure Security Agency says that media reports about it being directed to no longer follow or report on Russian cyber activity are untrue, and its mission remains unchanged. […] Lawrence Abrams Go to bleepingcomputer
-
CISA tags Windows, Cisco vulnerabilities as actively exploited
CISA tags Windows, Cisco vulnerabilities as actively exploited CISA has warned US federal agencies to secure their systems against attacks exploiting vulnerabilities in Cisco and Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint A newly uncovered ClickFix phishing campaign is tricking victims into executing malicious PowerShell commands that deploy the Havok post-exploitation framework for remote access to compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. […] Bill Toulas Go to bleepingcomputer
-
U.S. recovers $31 million stolen in 2021 Uranium Finance hack
U.S. recovers $31 million stolen in 2021 Uranium Finance hack U.S. authorities recovered $31 million in cryptocurrency stolen in 2021 cyberattacks on Uranium Finance, a Binance Smart Chain-based DeFi protocol. […] Bill Toulas Go to bleepingcomputer
-
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data The Qilin ransomware gang has claimed responsibility for the attack at Lee Enterprises that disrupted operations on February 3, leaking samples of data they claim was stolen from the company. […] Bill Toulas Go to bleepingcomputer
-
Police arrests suspects tied to AI-generated CSAM distribution ring
Police arrests suspects tied to AI-generated CSAM distribution ring Law enforcement agencies from 19 countries have arrested 25 suspects linked to a criminal ring that was distributing child sexual abuse material (CSAM) generated using artificial intelligence (AI). […] Sergiu Gatlan Go to bleepingcomputer
-
Serbian police used Cellebrite zero-day hack to unlock Android phones
Serbian police used Cellebrite zero-day hack to unlock Android phones Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. […] Bill Toulas Go to bleepingcomputer
-
Vo1d malware botnet grows to 1.6 million Android TVs worldwide
Vo1d malware botnet grows to 1.6 million Android TVs worldwide A new variant of the Vo1d malware botnet has grown to 1,590,299 infected Android TV devices across 226 countries, recruiting devices as part of anonymous proxy server networks. […] Bill Toulas Go to bleepingcomputer
-
Privacy tech firms warn France’s encryption and VPN laws threaten privacy
Privacy tech firms warn France’s encryption and VPN laws threaten privacy Privacy-focused email provider Tuta (previously Tutanota) and the VPN Trust Initiative (VTI) are raising concerns over proposed laws in France set to backdoor encrypted messaging systems and restrict internet access. […] Bill Toulas Go to bleepingcomputer
-
Over 49,000 misconfigured building access systems exposed online
Over 49,000 misconfigured building access systems exposed online Researchers discovered 49,000 misconfigured and exposed Access Management Systems (AMS) across multiple industries and countries, which could compromise privacy and physical security in critical sectors. […] Bill Toulas Go to bleepingcomputer
-
Belgium probes if Chinese hackers breached its intelligence service
Belgium probes if Chinese hackers breached its intelligence service The Belgian federal prosecutor’s office is investigating whether Chinese hackers were behind a breach of the country’s State Security Service (VSSE). […] Sergiu Gatlan Go to bleepingcomputer
-
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist
FBI confirms Lazarus hackers were behind $1.5B Bybit crypto heist FBI has confirmed that North Korean hackers stole $1.5 billion from cryptocurrency exchange Bybit on Friday in the largest crypto heist recorded until now. […] Sergiu Gatlan Go to bleepingcomputer
-
Southern Water says Black Basta ransomware attack cost £4.5M in expenses
Southern Water says Black Basta ransomware attack cost £4.5M in expenses United Kingdom water supplier Southern Water has disclosed that it incurred costs of £4.5 million ($5.7M) due to a cyberattack it suffered in February 2024. […] Bill Toulas Go to bleepingcomputer
-
GrassCall malware campaign drains crypto wallets via fake job interviews
GrassCall malware campaign drains crypto wallets via fake job interviews A recent social engineering campaign targeted job seekers in the Web3 space with fake job interviews through a malicious “GrassCall” meeting app that installs information-stealing malware to steal cryptocurrency wallets. […] Lawrence Abrams Go to bleepingcomputer
-
VSCode extensions with 9 million installs pulled over security risks
VSCode extensions with 9 million installs pulled over security risks Microsoft has removed two popular VSCode extensions, ‘Material Theme – Free’ and ‘Material Theme Icons – Free,’ from the Visual Studio Marketplace for allegedly containing malicious code. […] Bill Toulas Go to bleepingcomputer
-
PyPi package with 100K installs pirated music from Deezer for years
PyPi package with 100K installs pirated music from Deezer for years A malicious PyPi package named ‘automslc’ has been downloaded over 100,000 times from the Python Package Index since 2019, abusing hard-coded credentials to pirate music from the Deezer streaming service. […] Bill Toulas Go to bleepingcomputer
-
Have I Been Pwned adds 284M accounts stolen by infostealer malware
Have I Been Pwned adds 284M accounts stolen by infostealer malware The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel. […] Sergiu Gatlan Go to bleepingcomputer
-
Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers
Firefox continues Manifest V2 support as Chrome disables MV2 ad-blockers Mozilla has renewed its promise to continue supporting Manifest V2 extensions alongside Manifest V3, giving users the freedom to use the extensions they want in their browser. […] Bill Toulas Go to bleepingcomputer
-
OpenAI bans ChatGPT accounts used by North Korean hackers
OpenAI bans ChatGPT accounts used by North Korean hackers OpenAI says it blocked several North Korean hacking groups from using its ChatGPT platform to research future targets and find ways to hack into their networks. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia warns financial sector of major IT service provider hack
Russia warns financial sector of major IT service provider hack Russia’s National Coordination Center for Computer Incidents (NKTsKI) is warning organizations in the country’s credit and financial sector about a breach at LANIT, a major Russian IT service and software provider. […] Bill Toulas Go to bleepingcomputer
-
Australia bans all Kaspersky products on government systems
Australia bans all Kaspersky products on government systems The Australian government has banned all Kaspersky Lab products and web services from its systems and devices following an analysis that claims the company poses a significant security risk to the country. […] Bill Toulas Go to bleepingcomputer
-
Botnet targets Basic Auth in Microsoft 365 password spray attacks
Botnet targets Basic Auth in Microsoft 365 password spray attacks A massive botnet of over 130,000 compromised devices is conducting password-spray attacks against Microsoft 365 (M365) accounts worldwide, attempting to confirm credentials. […] Bill Toulas Go to bleepingcomputer
-
Google Cloud introduces quantum-safe digital signatures in KMS
Google Cloud introduces quantum-safe digital signatures in KMS Google Cloud has introduced quantum-safe digital signatures to its Cloud Key Management Service (Cloud KMS), making them available in preview. […] Bill Toulas Go to bleepingcomputer
-
Beware: PayPal “New Address” feature abused to send phishing emails
Beware: PayPal “New Address” feature abused to send phishing emails An ongoing PayPal email scam exploits the platform’s address settings to send fake purchase notifications, tricking users into granting remote access to scammers […] Lawrence Abrams Go to bleepingcomputer
-
Fake CS2 tournament streams used to steal crypto, Steam accounts
Fake CS2 tournament streams used to steal crypto, Steam accounts Threat actors are exploiting major Counter-Strike 2 (CS2) competitions, like IEM Katowice 2025 and PGL Cluj-Napoca 2025, to defraud gamers and steal their Steam accounts and cryptocurrency. […] Bill Toulas Go to bleepingcomputer
-
SpyLend Android malware downloaded 100,000 times from Google Play
SpyLend Android malware downloaded 100,000 times from Google Play An Android malware app called SpyLend has been downloaded over 100,000 times from Google Play, where it masqueraded as a financial tool but became a predatory loan app for those in India. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals record $1.46 billion from Bybit ETH cold wallet
Hacker steals record $1.46 billion from Bybit ETH cold wallet Cryptocurrency exchange Bybit revealed today that an unknown attacker stole over $1.46 billion worth of cryptocurrency from one of its ETH cold wallets. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA flags Craft CMS code injection flaw as exploited in attacks
CISA flags Craft CMS code injection flaw as exploited in attacks The U.S. Cybersecurity & Infrastructure Security Agency (CISA) warns that a Craft CMS remote code execution flaw is being exploited in attacks. […] Bill Toulas Go to bleepingcomputer
-
Apple pulls iCloud end-to-end encryption feature in the UK
Apple pulls iCloud end-to-end encryption feature in the UK Apple will no longer offer iCloud end-to-end encryption in the United Kingdom after the government requested a backdoor to access Apple customers’ encrypted cloud data. […] Sergiu Gatlan Go to bleepingcomputer
-
Apiiro unveils free scanner to detect malicious code merges
Apiiro unveils free scanner to detect malicious code merges Security researchers at Apiiro have released two free, open-source tools designed to detect and block malicious code before they are added to software projects to curb supply chain attacks. […] Bill Toulas Go to bleepingcomputer
-
Black Basta ransomware gang’s internal chat logs leak online
Black Basta ransomware gang’s internal chat logs leak online An unknown leaker has released what they claim to be an archive of internal Matrix chat logs belonging to the Black Basta ransomware operation. […] Sergiu Gatlan Go to bleepingcomputer
-
US healthcare org pays $11M settlement over alleged cybersecurity lapses
US healthcare org pays $11M settlement over alleged cybersecurity lapses Health Net Federal Services (HNFS) and its parent company, Centene Corporation, have agreed to pay $11,253,400 to settle allegations that HNFS falsely certified compliance with cybersecurity requirements under its Defense Health Agency (DHA) TRICARE contract. […] Bill Toulas Go to bleepingcomputer
-
Chinese hackers use custom malware to spy on US telecom networks
Chinese hackers use custom malware to spy on US telecom networks The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. telecommunication providers. […] Bill Toulas Go to bleepingcomputer
-
Integrating LLMs into security operations using Wazuh
Integrating LLMs into security operations using Wazuh Large Language Models (LLMs) can provide many benefits to security professionals by helping them analyze logs, detect phishing attacks, or offering threat intelligence. Learn from Wazuh how to incorporate an LLM, like ChatGPT, into its open source security platform. […] Sponsored by Wazuh Go to bleepingcomputer
-
New NailaoLocker ransomware used against EU healthcare orgs
New NailaoLocker ransomware used against EU healthcare orgs A previously undocumented ransomware payload named NailaoLocker has been spotted in attacks targeting European healthcare organizations between June and October 2024. […] Bill Toulas Go to bleepingcomputer
-
CISA and FBI: Ghost ransomware breached orgs in 70 countries
CISA and FBI: Ghost ransomware breached orgs in 70 countries CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries, including critical infrastructure organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing attack hides JavaScript using invisible Unicode trick
Phishing attack hides JavaScript using invisible Unicode trick A new JavaScript obfuscation method utilizing invisible Unicode characters to represent binary values is being actively abused in phishing attacks targeting affiliates of an American political action committee (PAC). […] Bill Toulas Go to bleepingcomputer
-
New FrigidStealer infostealer infects Macs via fake browser updates
New FrigidStealer infostealer infects Macs via fake browser updates The FakeUpdate malware campaigns are increasingly becoming muddled, with two additional cybercrime groups tracked as TA2726 and TA2727, running campaigns that push a new macOS infostealer malware called FrigidStealer. […] Bill Toulas Go to bleepingcomputer
-
Australian fertility services giant Genea hit by security breach
Australian fertility services giant Genea hit by security breach Genea, one of Australia’s largest fertility services providers, disclosed that unknown attackers breached its network and accessed data stored on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
WinRAR 7.10 boosts Windows privacy by stripping MoTW data
WinRAR 7.10 boosts Windows privacy by stripping MoTW data WinRAR 7.10 was released yesterday with numerous features, such as larger memory pages, a dark mode, and the ability to fine-tune how Windows Mark-of-the-Web flags are propagated when extracting files. […] Lawrence Abrams Go to bleepingcomputer
-
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners
Cracked Garry’s Mod, BeamNG.drive games infect gamers with miners A large-scale malware campaign dubbed “StaryDobry” has been targeting gamers worldwide with trojanized versions of cracked games such as Garry’s Mod, BeamNG.drive, and Dyson Sphere Program. […] Bill Toulas Go to bleepingcomputer
-
Venture capital giant Insight Partners hit by cyberattack
Venture capital giant Insight Partners hit by cyberattack New York-based venture capital and private equity firm Insight Partners has disclosed that its systems were breached in January following a social engineering attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers abuse Microsoft APP-v tool to evade antivirus
Chinese hackers abuse Microsoft APP-v tool to evade antivirus The Chinese APT hacking group “Mustang Panda” has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. […] Bill Toulas Go to bleepingcomputer
-
Chase will soon block Zelle payments to sellers on social media
Chase will soon block Zelle payments to sellers on social media JPMorgan Chase Bank (Chase) will soon start blocking Zelle payments to social media contacts to combat a significant rise in online scams utilizing the service for fraud. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to remove the Location History feature in Windows
Microsoft to remove the Location History feature in Windows Microsoft announced the deprecation of the Location History feature from Windows, which let applications like the Cortana virtual assistant to fetch location history of the device. […] Bill Toulas Go to bleepingcomputer
-
X now blocks Signal contact links, flags them as malicious
X now blocks Signal contact links, flags them as malicious Social media platform X (formerly Twitter) is now blocking links to “Signal.me,” a URL used by the Signal encrypted messaging to share your account info with another person. […] Bill Toulas Go to bleepingcomputer
-
Microsoft spots XCSSET macOS malware variant used for crypto theft
Microsoft spots XCSSET macOS malware variant used for crypto theft A new variant of the XCSSET macOS modular malware has emerged in attacks that target users’ sensitive information, including digital wallets and data from the legitimate Notes app. […] Bill Toulas Go to bleepingcomputer
-
Google Chrome’s AI-powered security feature rolls out to everyone
Google Chrome’s AI-powered security feature rolls out to everyone Google Chrome has updated the existing “Enhanced protection” feature with AI to offer “real-time” protection against dangerous websites, downloads and extensions. […] Mayank Parmar Go to bleepingcomputer
-
New FinalDraft malware abuses Outlook mail service for stealthy comms
New FinalDraft malware abuses Outlook mail service for stealthy comms A new malware called FinalDraft has been using Outlook email drafts for command-and-control communication in attacks against a ministry in a South American country. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Hackers steal emails in device code phishing attacks
Microsoft: Hackers steal emails in device code phishing attacks An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit authentication bypass in Palo Alto Networks PAN-OS
Hackers exploit authentication bypass in Palo Alto Networks PAN-OS Hackers are launching attacks against Palo Alto Networks PAN-OS firewalls by exploiting a recently fixed vulnerability (CVE-2025-0108) that allows bypassing authentication. […] Bill Toulas Go to bleepingcomputer
-
SonicWall firewall bug leveraged in attacks after PoC exploit release
SonicWall firewall bug leveraged in attacks after PoC exploit release Attackers are now targeting an authentication bypass vulnerability affecting SonicWall firewalls shortly after the release of proof-of-concept (PoC) exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious PirateFi game infects Steam users with Vidar malware
Malicious PirateFi game infects Steam users with Vidar malware A free-to-play game named PirateFi in the Steam store has been distributing the Vidar infostealing malware to unsuspecting users. […] Bill Toulas Go to bleepingcomputer
-
PostgreSQL flaw exploited as zero-day in BeyondTrust breach
PostgreSQL flaw exploited as zero-day in BeyondTrust breach Rapid7’s vulnerability research team says attackers exploited a PostgreSQL security flaw as a zero-day to breach the network of privileged access management company BeyondTrust in December. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese hackers breach more US telecoms via unpatched Cisco routers
Chinese hackers breach more US telecoms via unpatched Cisco routers China’s Salt Typhoon hackers are still actively targeting telecoms worldwide and have breached more U.S. telecommunications providers via unpatched Cisco IOS XE network devices. […] Sergiu Gatlan Go to bleepingcomputer
-
whoAMI attacks give hackers code execution on Amazon EC2 instances
whoAMI attacks give hackers code execution on Amazon EC2 instances Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name. […] Bill Toulas Go to bleepingcomputer
-
Hacker leaks account data of 12 million Zacks Investment users
Hacker leaks account data of 12 million Zacks Investment users Zacks Investment Research (Zacks) last year reportedly suffered another data breach that exposed sensitive information related to roughly 12 million accounts. […] Bill Toulas Go to bleepingcomputer
-
Chinese espionage tools deployed in RA World ransomware attack
Chinese espionage tools deployed in RA World ransomware attack A China-based threat actor, tracked as Emperor Dragonfly and commonly associated with cybercriminal endeavors, has been observed using in a ransomware attack a toolset previously attributed to espionage actors. […] Bill Toulas Go to bleepingcomputer
-
zkLend loses $9.5M in crypto heist, asks hacker to return 90%
zkLend loses $9.5M in crypto heist, asks hacker to return 90% Decentralized money lender zkLend suffered a breach where threat actors exploited a smart contract flaw to steal 3,600 Ethereum, worth $9.5 million at the time. […] Lawrence Abrams Go to bleepingcomputer
-
Surge in attacks exploiting old ThinkPHP and ownCloud flaws
Surge in attacks exploiting old ThinkPHP and ownCloud flaws Increased hacker activity has been observed in attempts to compromise poorly maintained devices that are vulnerable to older security issues from 2022 and 2023. […] Bill Toulas Go to bleepingcomputer
-
Sarcoma ransomware claims breach at giant PCB maker Unimicron
Sarcoma ransomware claims breach at giant PCB maker Unimicron A relatively new ransomware operation named ‘Sarcoma’ has claimed responsibility for an attack against the Unimicron printed circuit boards (PCB) maker in Taiwan. […] Bill Toulas Go to bleepingcomputer
-
DPRK hackers dupe targets into typing PowerShell commands as admin
DPRK hackers dupe targets into typing PowerShell commands as admin North Korean state actor ‘Kimsuky’ (aka ‘Emerald Sleet’ or ‘Velvet Chollima’) has been observed using a new tactic inspired from the now widespread ClickFix campaigns. […] Bill Toulas Go to bleepingcomputer
-
Ivanti fixes three critical flaws in Connect Secure & Policy Secure
Ivanti fixes three critical flaws in Connect Secure & Policy Secure Ivanti has released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to address multiple vulnerabilities, including three critical severity problems. […] Bill Toulas Go to bleepingcomputer
-
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws Today is Microsoft’s February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Fortinet discloses second firewall auth bypass patched in January
Fortinet discloses second firewall auth bypass patched in January Fortinet has disclosed a second authentication bypass vulnerability that was fixed as part of a January 2025 update for FortiOS and FortiProxy devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian military hackers deploy malicious Windows activators in Ukraine
Russian military hackers deploy malicious Windows activators in Ukraine The Sandworm Russian military cyber-espionage group is targeting Windows users in Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 12,000 KerioControl firewalls exposed to exploited RCE flaw
Over 12,000 KerioControl firewalls exposed to exploited RCE flaw Over twelve thousand GFI KerioControl firewall instances are exposed to a critical remote code execution vulnerability tracked as CVE-2024-52875. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes zero-day exploited in ‘extremely sophisticated’ attacks
Apple fixes zero-day exploited in ‘extremely sophisticated’ attacks Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and “extremely sophisticated” attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Hacker pleads guilty to SIM swap attack on US SEC X account
Hacker pleads guilty to SIM swap attack on US SEC X account Today, an Alabama man pleaded guilty to hijacking the U.S. Securities and Exchange Commission (SEC) account on X in a January 2024 SIM swapping attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Police arrests 4 Phobos ransomware suspects, seizes 8Base sites
Police arrests 4 Phobos ransomware suspects, seizes 8Base sites A global law enforcement operation targeting the Phobos ransomware gang has led to the arrest of four suspected hackers in Phuket, Thailand, and the seizure of 8Base’s dark web sites. The suspects are accused of conducting cyberattacks on over 1,000 victims worldwide. […] Bill Toulas Go…
-
Brave now lets you inject custom JavaScript to tweak websites
Brave now lets you inject custom JavaScript to tweak websites Brave Browser is getting a new feature called ‘custom scriptlets’ that lets advanced users inject their own JavaScript into websites, allowing deep customization and control over their browsing experience. […] Bill Toulas Go to bleepingcomputer
-
A Cybersecurity Leader’s Guide to SecVal in 2025
A Cybersecurity Leader’s Guide to SecVal in 2025 Are your defenses truly battle-tested? Security validation ensures you’re not just hoping your security works—it proves it. Learn more from Pentera on how to validate against ransomware, credential threats, and unpatched vulnerabilities in the GOAT Guide. […] Sponsored by Pentera Go to bleepingcomputer
-
Massive brute force attack uses 2.8 million IPs to target VPN devices
Massive brute force attack uses 2.8 million IPs to target VPN devices A large-scale brute force password attack using almost 2.8 million IP addresses is underway, attempting to guess the credentials for a wide range of networking devices, including those from Palo Alto Networks, Ivanti, and SonicWall. […] Bill Toulas Go to bleepingcomputer
-
HPE notifies employees of data breach after Russian Office 365 hack
HPE notifies employees of data breach after Russian Office 365 hack Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company’s Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers
Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers Software vendor Trimble is warning that hackers are exploiting a Cityworks deserialization vulnerability to remotely execute commands on IIS servers and deploy Cobalt Strike beacons for initial network access. […] Bill Toulas Go to bleepingcomputer
-
US health system notifies 882,000 patients of August 2023 breach
US health system notifies 882,000 patients of August 2023 breach Hospital Sisters Health System notified over 882,000 patients that an August 2023 cyberattack led to a data breach that exposed their personal and health information. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare outage caused by botched blocking of phishing URL
Cloudflare outage caused by botched blocking of phishing URL An attempt to block a phishing URL in Cloudflare’s R2 object storage platform backfired yesterday, triggering a widespread outage that brought down multiple services for nearly an hour. […] Bill Toulas Go to bleepingcomputer
-
Microsoft shares workaround for Windows security update issues
Microsoft shares workaround for Windows security update issues Microsoft has shared a workaround for users affected by a known issue that blocks Windows security updates from deploying on some Windows 11 24H2 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says attackers use exposed ASP.NET keys to deploy malware
Microsoft says attackers use exposed ASP.NET keys to deploy malware Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. […] Sergiu Gatlan Go to bleepingcomputer
-
Kimsuky hackers use new custom RDP Wrapper for remote access
Kimsuky hackers use new custom RDP Wrapper for remote access The North Korean hacking group known as Kimsuky was observed in recent attacks using a custom-built RDP Wrapper and proxy tools to directly access infected machines. […] Bill Toulas Go to bleepingcomputer
-
Critical RCE bug in Microsoft Outlook now exploited in attacks
Critical RCE bug in Microsoft Outlook now exploited in attacks CISA warned U.S. federal agencies on Thursday to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution (RCE) vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware
Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware Hackers are targeting vulnerable SimpleHelp RMM clients to create administrator accounts, drop backdoors, and potentially lay the groundwork for ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
Critical Cisco ISE bug can let attackers run commands as root
Critical Cisco ISE bug can let attackers run commands as root Cisco has fixed two critical Identity Services Engine (ISE) vulnerabilities that can let attackers with read-only admin privileges bypass authorization and run commands as root. […] Sergiu Gatlan Go to bleepingcomputer
-
New Microsoft script updates Windows media with bootkit malware fixes
New Microsoft script updates Windows media with bootkit malware fixes Microsoft has released a PowerShell script to help Windows users and admins update bootable media so it utilizes the new “Windows UEFI CA 2023” certificate before the mitigations of the BlackLotus UEFI bootkit are enforced later this year. […] Lawrence Abrams Go to bleepingcomputer
-
Robocallers posing as FCC fraud prevention team call FCC staff
Robocallers posing as FCC fraud prevention team call FCC staff The FCC has proposed a $4,492,500 fine against VoIP service provider Telnyx for allegedly allowing customers to make robocalls posing as fictitious FCC “Fraud Prevention Team,” by failing to comply with Know Your Customer (KYC) rules. However, Telnyx says the FCC is mistaken and denies…
-
Ransomware payments fell by 35% in 2024, totalling $813,550,000
Ransomware payments fell by 35% in 2024, totalling $813,550,000 Payments to ransomware actors decreased 35% year-over-year in 2024, totaling $813.55 million, down from $1.25 billion recorded in 2023. […] Bill Toulas Go to bleepingcomputer
-
CISA orders agencies to patch Linux kernel bug exploited in attacks
CISA orders agencies to patch Linux kernel bug exploited in attacks CISA has ordered federal agencies to secure their systems within three weeks against a high-severity Linux kernel flaw actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers spoof Microsoft ADFS login pages to steal credentials
Hackers spoof Microsoft ADFS login pages to steal credentials A help desk phishing campaign targets an organization’s Microsoft Active Directory Federation Services (ADFS) using spoofed login pages to steal credentials and bypass multi-factor authentication (MFA) protections. […] Bill Toulas Go to bleepingcomputer
-
Zyxel won’t patch newly exploited flaws in end-of-life routers
Zyxel won’t patch newly exploited flaws in end-of-life routers Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models. […] Bill Toulas Go to bleepingcomputer
-
Cyber agencies share security guidance for network edge devices
Cyber agencies share security guidance for network edge devices Five Eyes cybersecurity agencies in the UK, Australia, Canada, New Zealand, and the U.S. have issued guidance urging makers of network edge devices and appliances to improve forensic visibility to help defenders detect attacks and investigate breaches. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese cyberspies use new SSH backdoor in network device hacks
Chinese cyberspies use new SSH backdoor in network device hacks A Chinese hacking group is hijacking the SSH daemon on network appliances by injecting malware into the process for persistent access and covert operations. […] Bill Toulas Go to bleepingcomputer
-
Netgear warns users to patch critical WiFi router vulnerabilities
Netgear warns users to patch critical WiFi router vulnerabilities Netgear has fixed two critical remote code execution and authentication bypass vulnerabilities affecting multiple WiFi routers and warned customers to update their devices to the latest firmware as soon as possible. […] Sergiu Gatlan Go to bleepingcomputer
-
GrubHub data breach impacts customers, drivers, and merchants
GrubHub data breach impacts customers, drivers, and merchants Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of customers, merchants, and drivers after attackers breached its systems using a service provider account. […] Sergiu Gatlan Go to bleepingcomputer
-
Amazon Redshift gets new default settings to prevent data breaches
Amazon Redshift gets new default settings to prevent data breaches Amazon has announced key security enhancements for Redshift, a popular data warehousing solution, to help prevent data exposures due to misconfigurations and insecure default settings. […] Bill Toulas Go to bleepingcomputer
-
Google fixes Android kernel zero-day exploited in attacks
Google fixes Android kernel zero-day exploited in attacks The February 2025 Android security updates patch 48 vulnerabilities, including a zero-day kernel vulnerability that has been exploited in the wild. […] Sergiu Gatlan Go to bleepingcomputer
-
Canadian charged with stealing $65 million using DeFI crypto exploits
Canadian charged with stealing $65 million using DeFI crypto exploits The U.S. Justice Department has charged a Canadian man with stealing roughly $65 million after exploiting two decentralized finance (DeFI) protocols. […] Sergiu Gatlan Go to bleepingcomputer
-
Google says hackers abuse Gemini AI to empower their attacks
Google says hackers abuse Gemini AI to empower their attacks Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity and to conduct research on potential infrastructure for attacks or for reconnaissance on targets. […] Bill Toulas Go to bleepingcomputer