Category: Security
-
Charter confirms data breach after ShinyHunters extortion threat
Charter confirms data breach after ShinyHunters extortion threat U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer
-
How Varonis Atlas integrates Claude Compliance API for AI governance
How Varonis Atlas integrates Claude Compliance API for AI governance AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. […] Sponsored by Varonis Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Drupal vulnerability
CISA orders feds to patch actively exploited Drupal vulnerability CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. […] Sergiu Gatlan Go to bleepingcomputer
-
7-Eleven data breach exposes personal information of 185,000 people
7-Eleven data breach exposes personal information of 185,000 people The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). […] Lawrence Abrams Go to bleepingcomputer
-
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. […] Bill Toulas Go to bleepingcomputer
-
Laravel Lang packages hijacked to deploy credential-stealing malware
Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. […] Lawrence Abrams Go to bleepingcomputer
-
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
Netherlands seizes 800 servers of hosting firm enabling cyberattacks Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. […] Bill Toulas Go to bleepingcomputer
-
Former US execs plead guilty to aiding tech support scammers
Former US execs plead guilty to aiding tech support scammers Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Trend Micro warns of Apex One zero-day exploited in the wild
Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Drupal: Critical SQL injection flaw now targeted in attacks
Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a “highly critical” SQL injection vulnerability announced earlier this week. […] Bill Toulas Go to bleepingcomputer
-
Why Chargebacks are Just One Piece of the Fraud Puzzle
Why Chargebacks are Just One Piece of the Fraud Puzzle Fraud losses don’t stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact. […] Sponsored by IPQS Go to bleepingcomputer
-
US and Canada arrest and charge suspected Kimwolf botnet admin
US and Canada arrest and charge suspected Kimwolf botnet admin U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Google accidentally exposed details of unfixed Chromium flaw
Google accidentally exposed details of unfixed Chromium flaw Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device. […] Bill Toulas Go to bleepingcomputer
-
Apple blocked over $11 billion in App Store fraud in 6 years
Apple blocked over $11 billion in App Store fraud in 6 years Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. […] Sergiu Gatlan Go to bleepingcomputer
-
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet Modern crypto drainers don’t hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishing and automation. […] Sponsored by Flare Go to bleepingcomputer
-
Chinese hackers target telcos with new Linux, Windows malware
Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. […] Bill Toulas Go to bleepingcomputer
-
Microsoft warns of new Defender zero-days exploited in attacks
Microsoft warns of new Defender zero-days exploited in attacks On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
GitHub links repo breach to TanStack npm supply-chain attack
GitHub links repo breach to TanStack npm supply-chain attack GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week’s TanStack npm supply-chain attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
Ukraine identifies infostealer operator tied to 28,000 stolen accounts The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation targeting users of an online store in California. […] Bill Toulas Go to bleepingcomputer
-
Hackers bypass SonicWall VPN MFA due to incomplete patching
Hackers bypass SonicWall VPN MFA due to incomplete patching Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. […] Bill Toulas Go to bleepingcomputer
-
Grafana breach caused by missed token rotation after TanStack attack
Grafana breach caused by missed token rotation after TanStack attack The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. […] Bill Toulas Go to bleepingcomputer
-
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. […] Sergiu Gatlan Go to bleepingcomputer
-
GitHub investigates internal repositories breach claimed by TeamPCP
GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containing private code. […] Sergiu Gatlan Go to bleepingcomputer
-
Max-severity flaw in ChromaDB for AI apps allows server hijacking
Max-severity flaw in ChromaDB for AI apps allows server hijacking A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. […] Bill Toulas Go to bleepingcomputer
-
Cybercrime service disrupted for abusing Microsoft platform to sign malware
Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company’s Artifact Signing service to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals. […] Lawrence Abrams Go to bleepingcomputer
-
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers More than 200 individuals were arrested for cybercrime activities during INTERPOL’s Operation Ramz, which focused on the Middle East and North Africa. […] Bill Toulas Go to bleepingcomputer
-
SHub macOS infostealer variant spoofs Apple security updates
SHub macOS infostealer variant spoofs Apple security updates A new variant of the ‘SHub’ macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. […] Bill Toulas Go to bleepingcomputer
-
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees Many employees already use shadow AI tools at work without security review. Adaptive Security breaks down how teams can build practical AI governance without adding friction for employees. […] Sponsored by Adaptive Security Go to bleepingcomputer
-
Leaked Shai-Hulud malware fuels new npm infostealer campaign
Leaked Shai-Hulud malware fuels new npm infostealer campaign The Shai-Hulud malware leaked last week is now used in new attacks on the Node Package Manager (npm) index, as infected packages emerged over the weekend. […] Bill Toulas Go to bleepingcomputer
-
Grafana says stolen GitHub token let hackers steal codebase
Grafana says stolen GitHub token let hackers steal codebase Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. […] Bill Toulas Go to bleepingcomputer
-
Microsoft confirms Windows 11 security update install issues
Microsoft confirms Windows 11 security update install issues Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. […] Sergiu Gatlan Go to bleepingcomputer
-
Exploit available for new DirtyDecrypt Linux root escalation flaw
Exploit available for new DirtyDecrypt Linux root escalation flaw A recently patched local privilege escalation vulnerability in the Linux kernel’s rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026 The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws. […] Sergiu Gatlan Go to bleepingcomputer
-
New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released
New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed “MiniPlasma” that lets attackers gain SYSTEM privileges on fully patched Windows systems. […] Lawrence Abrams Go to bleepingcomputer
-
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. […] Bill Toulas Go to bleepingcomputer
-
Microsoft rejects critical Azure vulnerability report, no CVE issued
Microsoft rejects critical Azure vulnerability report, no CVE issued A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that “no product changes were made,” despite the researcher documenting a silent fix.…
-
Russian hackers turn Kazuar backdoor into modular P2P botnet
Russian hackers turn Kazuar backdoor into modular P2P botnet The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. […] Bill Toulas Go to bleepingcomputer
-
Funnel Builder WordPress plugin bug exploited to steal credit cards
Funnel Builder WordPress plugin bug exploited to steal credit cards A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. […] Sergiu Gatlan Go to bleepingcomputer
-
Popular node-ipc npm package compromised to steal credentials
Popular node-ipc npm package compromised to steal credentials Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. […] Bill Toulas Go to bleepingcomputer
-
Avada Builder WordPress plugin flaws allow site credential theft
Avada Builder WordPress plugin flaws allow site credential theft Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. […] Bill Toulas Go to bleepingcomputer
-
Microsoft backpedals: Edge to stop loading passwords into memory
Microsoft backpedals: Edge to stop loading passwords into memory Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was “by design.” […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft warns of Exchange zero-day flaw exploited in attacks
Microsoft warns of Exchange zero-day flaw exploited in attacks On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. […] Sergiu Gatlan Go to bleepingcomputer
-
TeamPCP hackers advertise Mistral AI code repos for sale
TeamPCP hackers advertise Mistral AI code repos for sale The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. […] Ionut Ilascu Go to bleepingcomputer
-
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI confirms security breach in TanStack supply chain attack
OpenAI confirms security breach in TanStack supply chain attack OpenAI says two employees’ devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. […] Lawrence Abrams Go to bleepingcomputer
-
US charges suspected Dream Market admin arrested in Germany
US charges suspected Dream Market admin arrested in Germany The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laundering charges. […] Sergiu Gatlan Go to bleepingcomputer
-
New Fragnesia Linux flaw lets attackers gain root privileges
New Fragnesia Linux flaw lets attackers gain root privileges Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root. […] Sergiu Gatlan Go to bleepingcomputer
-
West Pharmaceutical says hackers stole data, encrypted systems
West Pharmaceutical says hackers stole data, encrypted systems West Pharmaceutical Services disclosed that it was the target of a cyberattack that resulted in data exfiltration and system encryption. […] Bill Toulas Go to bleepingcomputer
-
Iranian hackers targeted major South Korean electronics maker
Iranian hackers targeted major South Korean electronics maker The Iran-linked hacking group MuddyWater (a.k.a. Seedworm, Static Kitten) launched a broad cyber-espionage campaign targeting at least nine high-profile organizations across multiple sectors and countries. […] Bill Toulas Go to bleepingcomputer
-
US govt seeks Instructure testimony on massive Canvas cyberattack
US govt seeks Instructure testimony on massive Canvas cyberattack The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company’s Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams. […] Lawrence Abrams Go to…
-
UK fines water supplier $1.3M for exposing data of 664k customers
UK fines water supplier $1.3M for exposing data of 664k customers The Information Commissioner’s Office has fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) over a cyberattack that exposed the personal data of 663,887 customers and employees. […] Bill Toulas Go to bleepingcomputer
-
Webinar: Fixing the gaps in network incident response
Webinar: Fixing the gaps in network incident response IT teams often struggle to quickly coordinate responses across disparate systems during network incidents. This upcoming webinar explores how automation and AI-assisted workflows can reduce response times and help prevent outages. […] BleepingComputer Go to bleepingcomputer
-
Signal adds security warnings for social engineering, phishing attacks
Signal adds security warnings for social engineering, phishing attacks Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5087544 extended security update
Microsoft releases Windows 10 KB5087544 extended security update Microsoft has released the Windows 10 KB5087544 extended security update to fix the May 2026 Patch Tuesday vulnerabilities and resolve an issue with the new Remote Desktop warnings. […] Lawrence Abrams Go to bleepingcomputer
-
Instructure reaches ‘agreement’ with ShinyHunters to stop data leak
Instructure reaches ‘agreement’ with ShinyHunters to stop data leak Instructure, the edtech giant behind the widely popular Canvas learning management system (LMS), has reached an “agreement” with the ShinyHunters extortion group to prevent the data stolen in a recent breach from being leaked online. […] Sergiu Gatlan Go to bleepingcomputer
-
Official CheckMarx Jenkins package compromised with infostealer
Official CheckMarx Jenkins package compromised with infostealer Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. […] Bill Toulas Go to bleepingcomputer
-
New GhostLock tool abuses Windows API to block file access
New GhostLock tool abuses Windows API to block file access A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares. […] Lawrence Abrams Go to bleepingcomputer
-
Instructure confirms hackers used Canvas flaw to deface portals
Instructure confirms hackers used Canvas flaw to deface portals Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message. […] Ionut Ilascu Go to bleepingcomputer
-
TrickMo Android banker adopts TON blockchain for covert comms
TrickMo Android banker adopts TON blockchain for covert comms A new variant of the TrickMo Android banking malware, delivered in campaigns targeting users across Europe, introduces new commands and uses The Open Network (TON) for stealthy command-and-control communications. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Google ads, Claude.ai chats to push Mac malware
Hackers abuse Google ads, Claude.ai chats to push Mac malware Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for “Claude mac download” may come across sponsored search results that list claude.ai as the target website, but lead to instructions that install malware on their Mac. […]…
-
Police shut down reboot of Crimenetwork marketplace, arrest admin
Police shut down reboot of Crimenetwork marketplace, arrest admin German authorities have shut down a relaunch version of the criminal marketplace ‘Crimenetwork’ that generated more than 3.6 million euros, and arrested its operator. […] Bill Toulas Go to bleepingcomputer
-
JDownloader site hacked to replace installers with Python RAT malware
JDownloader site hacked to replace installers with Python RAT malware The website for the popular JDownloader download manager was compromised earlier this week to distribute malicious Windows and Linux installers, with the Windows payload found deploying a Python-based remote access trojan. […] Lawrence Abrams Go to bleepingcomputer
-
Fake OpenAI repository on Hugging Face pushes infostealer malware
Fake OpenAI repository on Hugging Face pushes infostealer malware A malicious Hugging Face repository that reached the platform’s trending list impersonated OpenAI’s “Privacy Filter” project to deliver information-stealing malware to Windows users. […] Bill Toulas Go to bleepingcomputer
-
NVIDIA confirms GeForce NOW data breach affecting Armenian users
NVIDIA confirms GeForce NOW data breach affecting Armenian users NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach. […] Bill Toulas Go to bleepingcomputer
-
Why More Analysts Won’t Solve Your SOC’s Alert Problem
Why More Analysts Won’t Solve Your SOC’s Alert Problem Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts faster and focus on real threats. […] Sponsored by Prophet Security Go to bleepingcomputer
-
Trellix source code breach claimed by RansomHouse hackers
Trellix source code breach claimed by RansomHouse hackers The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. […] Bill Toulas Go to bleepingcomputer
-
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
CISA gives feds four days to patch Ivanti flaw exploited as zero-day CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Zara data breach exposed personal information of 197,000 people
Zara data breach exposed personal information of 197,000 people Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned. […] Sergiu Gatlan Go to bleepingcomputer
-
Former govt contractor convicted for wiping dozens of federal databases
Former govt contractor convicted for wiping dozens of federal databases A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor. […] Sergiu Gatlan Go to bleepingcomputer
-
New Linux ‘Dirty Frag’ zero-day gives root on all major distros
New Linux ‘Dirty Frag’ zero-day gives root on all major distros A new Linux zero-day vulnerability, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command. […] Sergiu Gatlan Go to bleepingcomputer
-
Canvas login portals hacked in mass ShinyHunters extortion campaign
Canvas login portals hacked in mass ShinyHunters extortion campaign The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to deface Canvas login portals for hundreds of colleges and universities. […] Lawrence Abrams Go to bleepingcomputer
-
New TCLBanker malware self-spreads over WhatsApp and Outlook
New TCLBanker malware self-spreads over WhatsApp and Outlook A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems. […] Bill Toulas Go to bleepingcomputer
-
New PCPJack worm steals credentials, cleans TeamPCP infections
New PCPJack worm steals credentials, cleans TeamPCP infections A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP’s access to the systems. […] Bill Toulas Go to bleepingcomputer
-
Fake Claude AI website delivers new ‘Beagle’ Windows malware
Fake Claude AI website delivers new ‘Beagle’ Windows malware A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Google ads for GoDaddy ManageWP login phishing
Hackers abuse Google ads for GoDaddy ManageWP login phishing A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites. […] Bill Toulas Go to bleepingcomputer
-
Critical vm2 sandbox bug lets attackers execute code on hosts
Critical vm2 sandbox bug lets attackers execute code on hosts A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system. […] Bill Toulas Go to bleepingcomputer
-
New Cisco DoS flaw requires manual reboot to revive devices
New Cisco DoS flaw requires manual reboot to revive devices Cisco patched a Crosswork Network Controller and Network Services Orchestrator denial-of-service vulnerability that requires manually rebooting targeted systems for recovery. […] Sergiu Gatlan Go to bleepingcomputer
-
DAEMON Tools devs confirm breach, release malware-free version
DAEMON Tools devs confirm breach, release malware-free version Disc Soft Limited, the maker of DAEMON Tools Lite, confirmed that the software had been trojanized in a supply chain attack and released a new, malware-free version. […] Sergiu Gatlan Go to bleepingcomputer
-
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks Palo Alto Networks warned customers today that a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal is being exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
New stealthy Quasar Linux malware targets software developers
New stealthy Quasar Linux malware targets software developers A previously undocumented Linux implant named Quasar Linux (QLNX) is targeting developers’ systems with a mix of rootkit, backdoor, and credential-stealing capabilities. […] Bill Toulas Go to bleepingcomputer
-
Instructure hacker claims data theft from 8,800 schools, universities
Instructure hacker claims data theft from 8,800 schools, universities The hacker behind a breach at education technology giant Instructure claims to have stolen 280 million data records for students and staff from 8,809 colleges, school districts, and online education platforms. […] Lawrence Abrams Go to bleepingcomputer
-
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
DAEMON Tools trojanized in supply-chain attack to deploy backdoor Hackers trojanized installers for the DAEMON Tools software and since April 8, delivered a backdoor to thousands of systems that downloaded the product from the official website. […] Bill Toulas Go to bleepingcomputer
-
Student hacked Taiwan high-speed rail to trigger emergency brakes
Student hacked Taiwan high-speed rail to trigger emergency brakes A 23-year-old university student in Taiwan was arrested for interfering with the TETRA communication system used by the country’s high-speed railway network (THSR). […] Bill Toulas Go to bleepingcomputer
-
ScarCruft hackers push BirdCall Android malware via game platform
ScarCruft hackers push BirdCall Android malware via game platform The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform. […] Bill Toulas Go to bleepingcomputer
-
Weaver E-cology critical bug exploited in attacks since March
Weaver E-cology critical bug exploited in attacks since March Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands. […] Bill Toulas Go to bleepingcomputer
-
Amazon SES increasingly abused in phishing to evade detection
Amazon SES increasingly abused in phishing to evade detection The Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass standard security filters and render reputation-based blocks ineffective. […] Bill Toulas Go to bleepingcomputer
-
Backdoored PyTorch Lightning package drops credential stealer
Backdoored PyTorch Lightning package drops credential stealer A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a credential-stealing payload targeting browsers, environment files, and cloud services. […] Bill Toulas Go to bleepingcomputer
-
Trellix discloses data breach after source code repository hack
Trellix discloses data breach after source code repository hack Cybersecurity firm Trellix disclosed a data breach after attackers gained access to “a portion” of its source code repository. […] Sergiu Gatlan Go to bleepingcomputer
-
Instructure confirms data breach, ShinyHunters claims attack
Instructure confirms data breach, ShinyHunters claims attack Educational tech giant Instructure has confirmed that data was stolen in a cyberattack, with the ShinyHunters extortion gang claiming responsibility. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some cases, removing certificates from Windows. […] Lawrence Abrams Go to bleepingcomputer
-
Telegram Mini Apps abused for crypto scams, Android malware delivery
Telegram Mini Apps abused for crypto scams, Android malware delivery Cybersecurity researchers have uncovered a large-scale fraud operation that uses Telegram’s Mini App feature to run crypto scams, impersonate well-known brands, and distribute Android malware. […] Lawrence Abrams Go to bleepingcomputer
-
Critrical cPanel flaw mass-exploited in “Sorry” ransomware attacks
Critrical cPanel flaw mass-exploited in “Sorry” ransomware attacks A new disclosed cPanel flaw tracked as CVE-2026-41940 is being mass-exploited to breach websites and encrypt data in “Sorry” ransomware attacks. […] Lawrence Abrams Go to bleepingcomputer
-
ConsentFix v3 attacks target Azure with automated OAuth abuse
ConsentFix v3 attacks target Azure with automated OAuth abuse A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential. […] Bill Toulas Go to bleepingcomputer
-
Edu tech firm Instructure discloses cyber incident, probes impact
Edu tech firm Instructure discloses cyber incident, probes impact Instructure, the company behind the widely used Canvas learning platform, has disclosed that it recently suffered a cybersecurity incident and is now investigating its impact. […] Lawrence Abrams Go to bleepingcomputer
-
15-year-old detained over French govt agency data breach
15-year-old detained over French govt agency data breach French authorities have detained a 15-year-old suspected of selling data stolen in a cyberattack on France Titres (ANTS), the country’s agency for issuing and managing administrative documents. […] Ionut Ilascu Go to bleepingcomputer
-
Story retracted
Story retracted BleepingComputer initially published a story about a new data breach at Instructure. Shortly after publication, we determined that the information was incorrect and primarily based on outdated details from a prior incident. The article has been retracted, and we regret the error. […] BleepingComputer Go to bleepingcomputer