Category: Security
-
US ransomware negotiators get 4 years in prison over BlackCat attacks
US ransomware negotiators get 4 years in prison over BlackCat attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint were sentenced to four years in prison each for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
New Bluekit phishing service includes an AI assistant, 40 templates
New Bluekit phishing service includes an AI assistant, 40 templates A new phishing kit named Bluekit offers more than 40 templates targeting popular services and includes basic AI features for generating campaign drafts. […] Bill Toulas Go to bleepingcomputer
-
Romanian leader of online swatting ring gets 4 years in prison
Romanian leader of online swatting ring gets 4 years in prison A Romanian national who led an online swatting ring that targeted more than 75 public officials, multiple journalists, and four religious institutions was sentenced to 4 years in federal prison. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI links cybercriminals to sharp surge in cargo theft attacks
FBI links cybercriminals to sharp surge in cargo theft attacks The U.S. Federal Bureau of Investigation (FBI) warned the transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Official SAP npm packages compromised to steal credentials
Official SAP npm packages compromised to steal credentials Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers’ systems. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining
Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers’ servers. […] Bill Toulas Go to bleepingcomputer
-
Popular WordPress redirect plugin hid dormant backdoor for years
Popular WordPress redirect plugin hid dormant backdoor for years The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users’ sites. […] Bill Toulas Go to bleepingcomputer
-
Hackers arrested for hijacking and selling 610,000 Roblox accounts
Hackers arrested for hijacking and selling 610,000 Roblox accounts The Ukrainian police have arrested three individuals who hacked more than 610,000 Roblox gaming accounts and sold them for a profit of $225,000. […] Bill Toulas Go to bleepingcomputer
-
cPanel, WHM emergency update fixes critical auth bypass bug
cPanel, WHM emergency update fixes critical auth bypass bug A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says backend change broke Teams Free chat and calls
Microsoft says backend change broke Teams Free chat and calls Microsoft is working to resolve a known issue that prevents some Microsoft Teams Free users from chatting and calling others. […] Sergiu Gatlan Go to bleepingcomputer
-
Broken VECT 2.0 ransomware acts as a data wiper for large files
Broken VECT 2.0 ransomware acts as a data wiper for large files Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability tracked as CVE-2026-42208. […] Bill Toulas Go to bleepingcomputer
-
Video service Vimeo confirms Anodot breach exposed user data
Video service Vimeo confirms Anodot breach exposed user data Vimeo has disclosed that data belonging to some of its customers and users has been accessed without authorization following the recent breach at the Anodot data anomaly detection company. […] Bill Toulas Go to bleepingcomputer
-
US reportedly charges Scattered Spider hacker arrested in Finland
US reportedly charges Scattered Spider hacker arrested in Finland A 19-year-old dual United States and Estonian citizen arrested in Finland earlier this month faces federal charges in the U.S. alleging he was a prolific member of the notorious Scattered Spider hacking collective. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: New Remote Desktop warnings may display incorrectly
Microsoft: New Remote Desktop warnings may display incorrectly Microsoft has confirmed a new issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files. […] Sergiu Gatlan Go to bleepingcomputer
-
Robinhood account creation flaw abused to send phishing emails
Robinhood account creation flaw abused to send phishing emails Online trading platform Robinhood’s account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity. […] Lawrence Abrams Go to bleepingcomputer
-
GlassWorm malware attacks return via 73 OpenVSX “sleeper” extensions
GlassWorm malware attacks return via 73 OpenVSX “sleeper” extensions A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 “sleeper” extensions that turn malicious after an update. […] Bill Toulas Go to bleepingcomputer
-
Canada arrests three for operating “SMS blaster” device in Toronto
Canada arrests three for operating “SMS blaster” device in Toronto Canadian authorities have arrested three men for operating an “SMS blaster” device that pretends to be a cellular tower to send phishing texts to nearby phones. […] Bill Toulas Go to bleepingcomputer
-
American utility firm Itron discloses breach of internal IT network
American utility firm Itron discloses breach of internal IT network Itron, Inc. has disclosed, via an 8-K filing with the U.S. Securities and Exchange Commission (SEC), a cybersecurity incident in which an unauthorized third party accessed certain internal systems. […] Bill Toulas Go to bleepingcomputer
-
Threat actor uses Microsoft Teams to deploy new “Snow” malware
Threat actor uses Microsoft Teams to deploy new “Snow” malware A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named ‘Snow’ which includes a browser extension, a tunneler, and a backdoor. […] Bill Toulas Go to bleepingcomputer
-
ADT confirms data breach after ShinyHunters leak threat
ADT confirms data breach after ShinyHunters leak threat Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer
-
Firestarter malware survives Cisco firewall updates, security patches
Firestarter malware survives Cisco firewall updates, security patches Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. […] Bill Toulas Go to bleepingcomputer
-
New BlackFile extortion group linked to surge of vishing attacks
New BlackFile extortion group linked to surge of vishing attacks A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to roll out Entra passkeys on Windows in late April
Microsoft to roll out Entra passkeys on Windows in late April Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit file upload bug in Breeze Cache WordPress plugin
Hackers exploit file upload bug in Breeze Cache WordPress plugin Hackers are actively exploiting a critical vulnerability in the Breeze Cache plugin for WordPress that allows uploading arbitrary files on the server without authentication. […] Bill Toulas Go to bleepingcomputer
-
Bitwarden CLI npm package compromised to steal developer credentials
Bitwarden CLI npm package compromised to steal developer credentials The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects. […] Lawrence Abrams Go to bleepingcomputer
-
Trigona ransomware attacks use custom exfiltration tool to steal data
Trigona ransomware attacks use custom exfiltration tool to steal data Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently. […] Bill Toulas Go to bleepingcomputer
-
New Checkmarx supply-chain breach affects KICS analysis tool
New Checkmarx supply-chain breach affects KICS analysis tool Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments. […] Bill Toulas Go to bleepingcomputer
-
Cosmetics giant Rituals discloses data breach affecting customers
Cosmetics giant Rituals discloses data breach affecting customers Dutch cosmetics giant Rituals disclosed a data breach after attackers stole the personal information of an undisclosed number of customers from its “My Rituals” membership database. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple fixes bug that let the FBI recover deleted Signal messages
Apple fixes bug that let the FBI recover deleted Signal messages Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked for deletion to remain stored on the device. […] Lawrence Abrams Go to bleepingcomputer
-
New Mirai campaign exploits RCE flaw in EoL D-Link routers
New Mirai campaign exploits RCE flaw in EoL D-Link routers A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet. […] Bill Toulas Go to bleepingcomputer
-
Kyber ransomware gang toys with post-quantum encryption on Windows
Kyber ransomware gang toys with post-quantum encryption on Windows A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. […] Bill Toulas Go to bleepingcomputer
-
Spain dismantles major $4.7M manga piracy platform, arrests four
Spain dismantles major $4.7M manga piracy platform, arrests four The Spanish police have dismantled the largest Spanish-language manga piracy platform, operating since 2014, with millions of monthly users from around the globe. […] Bill Toulas Go to bleepingcomputer
-
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process Fraud operations now operate like call centers, complete with hiring, training, and performance tracking. Flare reveals how cybercriminals manage “Caller-as-a-Service” operations like a professional sales team. […] Sponsored by Flare Go to bleepingcomputer
-
New GoGra malware for Linux uses Microsoft Graph API for comms
New GoGra malware for Linux uses Microsoft Graph API for comms A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases emergency patches for critical ASP.NET flaw
Microsoft releases emergency patches for critical ASP.NET flaw Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
French govt agency confirms breach as hacker offers to sell data
French govt agency confirms breach as hacker offers to sell data France Titres, the government agency in France for issuing and managince administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data. […] Bill Toulas Go to bleepingcomputer
-
New Lotus data wiper used against Venezuelan energy, utility firms
New Lotus data wiper used against Venezuelan energy, utility firms A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. […] Bill Toulas Go to bleepingcomputer
-
NGate Android malware uses HandyPay NFC app to steal card data
NGate Android malware uses HandyPay NFC app to steal card data A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. […] Bill Toulas Go to bleepingcomputer
-
KelpDAO suffers $290 million heist tied to Lazarus hackers
KelpDAO suffers $290 million heist tied to Lazarus hackers State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday. […] Bill Toulas Go to bleepingcomputer
-
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
The Gentlemen ransomware now uses SystemBC for bot-powered attacks A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate. […] Bill Toulas Go to bleepingcomputer
-
China’s Apple App Store infiltrated by crypto-stealing wallet apps
China’s Apple App Store infiltrated by crypto-stealing wallet apps A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […] Bill Toulas Go to bleepingcomputer
-
Seiko USA website defaced as hacker claims customer data theft
Seiko USA website defaced as hacker claims customer data theft The Seiko USA website was defaced over the weekend, displaying a message from attackers claiming they stole its Shopify customer database and threatening to leak it unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer
-
Vercel confirms breach as hackers claim to be selling stolen data
Vercel confirms breach as hackers claim to be selling stolen data Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data. […] Lawrence Abrams Go to bleepingcomputer
-
Apple account change alerts abused to send phishing emails
Apple account change alerts abused to send phishing emails Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple’s servers, increasing legitimacy and potentially allowing them to bypass spam filters. […] Lawrence Abrams Go to bleepingcomputer
-
NIST to stop rating non-priority flaws due to volume increase
NIST to stop rating non-priority flaws due to volume increase The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes. […] Bill Toulas Go to bleepingcomputer
-
Critical flaw in Protobuf library enables JavaScript code execution
Critical flaw in Protobuf library enables JavaScript code execution Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google’s Protocol Buffers. […] Bill Toulas Go to bleepingcomputer
-
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support NAKIVO Inc. announced the general availability of NAKIVO Backup & Replication v11.2, focused on fast, reliable, and proactive data protection. […] Sponsored by NAKIVO Go to bleepingcomputer
-
Payouts King ransomware uses QEMU VMs to bypass endpoint security
Payouts King ransomware uses QEMU VMs to bypass endpoint security The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. […] Bill Toulas Go to bleepingcomputer
-
Grinex exchange blames “Western intelligence” for $13.7M crypto hack
Grinex exchange blames “Western intelligence” for $13.7M crypto hack Kyrgyzstan-based cryptocurrency exchange Grinex has suspended its operations after suffering a $13.7 million hack attributed to Western intelligence agencies. […] Bill Toulas Go to bleepingcomputer
-
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops In cybercrime markets, trust isn’t assumed, it’s verified. Flare reveals how underground guides teach actors to evaluate carding shops based on data quality, reputation, and survivability. […] Sponsored by Flare Go to bleepingcomputer
-
Webinar: From phishing to fallout — Why MSPs must rethink both security and recovery
Webinar: From phishing to fallout — Why MSPs must rethink both security and recovery Cyberattacks are evolving faster than many MSP and corporate defenses can keep up, with phishing driving much of today’s cybercrime. Join our upcoming webinar to learn how to combine security and recovery strategies to reduce risk and maintain business continuity. […]…
-
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
CISA flags Apache ActiveMQ flaw as actively exploited in attacks CISA warned that attackers are now exploiting a high-severity Apache ActiveMQ vulnerability, which was patched earlier this month after going undetected for 13 years. […] Sergiu Gatlan Go to bleepingcomputer
-
Man gets 30 months for selling thousands of hacked DraftKings accounts
Man gets 30 months for selling thousands of hacked DraftKings accounts 23-year-old Kamerin Stokes of Memphis, Tennessee, was sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Recently leaked Windows zero-days now exploited in attacks
Recently leaked Windows zero-days now exploited in attacks Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. […] Sergiu Gatlan Go to bleepingcomputer
-
Operation PowerOFF identifies 75k DDoS users, takes down 53 domains
Operation PowerOFF identifies 75k DDoS users, takes down 53 domains The latest wave of “Operation PowerOFF,” on April 13, 2026, targeted the distributed denial-of-service (DDoS) ecosystem and its users across 21 countries. […] Bill Toulas Go to bleepingcomputer
-
US nationals behind DPRK IT worker ‘laptop farm’ sent to prison
US nationals behind DPRK IT worker ‘laptop farm’ sent to prison Two U.S. nationals have been sent to prison for helping North Korean remote information technology (IT) workers to pose as U.S. residents and get hired by over 100 companies across the country, including many Fortune 500 firms. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Nginx UI auth bypass flaw now actively exploited in the wild
Critical Nginx UI auth bypass flaw now actively exploited in the wild A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. […] Bill Toulas Go to bleepingcomputer
-
New AgingFly malware used in attacks on Ukraine govt, hospitals
New AgingFly malware used in attacks on Ukraine govt, hospitals A new malware family named ‘AgingFly’ has been identified in attacks against local governments and hospitals that steal authentication data from Chromium-based browsers and WhatsApp messenger. […] Bill Toulas Go to bleepingcomputer
-
WordPress plugin suite hacked to push malware to thousands of sites
WordPress plugin suite hacked to push malware to thousands of sites More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them. […] Bill Toulas Go to bleepingcomputer
-
Microsoft adds Windows protections for malicious Remote Desktop files
Microsoft adds Windows protections for malicious Remote Desktop files Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default. […] Lawrence Abrams Go to bleepingcomputer
-
Crypto-exchange Kraken extorted by hackers after insider breach
Crypto-exchange Kraken extorted by hackers after insider breach The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data. […] Bill Toulas Go to bleepingcomputer
-
Over 100 Chrome Web Store extensions steal user accounts, data
Over 100 Chrome Web Store extensions steal user accounts, data More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5082200 extended security update
Microsoft releases Windows 10 KB5082200 extended security update Microsoft has released the Windows 10 KB5082200 extended security update to fix the April 2026 Patch Tuesday vulnerabilities, including 2 zero-days. […] Lawrence Abrams Go to bleepingcomputer
-
McGraw-Hill confirms data breach following extortion threat
McGraw-Hill confirms data breach following extortion threat Education company McGraw-Hill has confirmed in a statement to BleepingComputer that hackers exploited a Salesforce misconfiguration and accessed its internal data. […] Bill Toulas Go to bleepingcomputer
-
European Gym giant Basic-Fit data breach affects 1 million members
European Gym giant Basic-Fit data breach affects 1 million members Dutch fitness giant Basic-Fit announced that hackers breached its systems and gained access to information belonging to a million of its customers. […] Bill Toulas Go to bleepingcomputer
-
Stolen Rockstar Games analytics data leaked by extortion gang
Stolen Rockstar Games analytics data leaked by extortion gang Rockstar Games has suffered a data breach linked to a recent security incident at Anodot, with the ShinyHunters extortion gang now leaking the stolen data on its data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
Critical flaw in wolfSSL library enables forged certificate use
Critical flaw in wolfSSL library enables forged certificate use A critical vulnerability in the wolfSSL SSL/TLS library can weaken security via improper verification of the hash algorithm or its size when checking Elliptic Curve Digital Signature Algorithm (ECDSA) signatures. […] Bill Toulas Go to bleepingcomputer
-
FBI takedown of W3LL phishing service leads to developer arrest
FBI takedown of W3LL phishing service leads to developer arrest The FBI Atlanta Field Office and Indonesian authorities have dismantled the “W3LL” global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer. […] Lawrence Abrams…
-
OpenAI rotates macOS certs after Axios attack hit code-signing workflow
OpenAI rotates macOS certs after Axios attack hit code-signing workflow OpenAI is rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a malicious Axios package during a recent supply chain attack. […] Lawrence Abrams Go to bleepingcomputer
-
Critical Marimo pre-auth RCE flaw now under active exploitation
Critical Marimo pre-auth RCE flaw now under active exploitation A critical pre-authentication remote code execution (RCE) vulnerability in Marimo is now under active exploitation, leveraged for credential theft. […] Bill Toulas Go to bleepingcomputer
-
Over 20,000 crypto fraud victims identified in international crackdown
Over 20,000 crypto fraud victims identified in international crackdown An international law enforcement action led by the U.K.’s National Crime Agency (NCA) has identified over 20,000 victims of cryptocurrency fraud across Canada, the United Kingdom, and the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufactured by Rockwell Automation. […] Sergiu Gatlan Go to bleepingcomputer
-
Analysis of one billion CISA KEV remediation records exposes limits of human-scale security
Analysis of one billion CISA KEV remediation records exposes limits of human-scale security Analysis of 1 billion CISA KEV remediation records reveal a breaking point for human-scale security. Qualys shows most critical flaws are exploited before defenders can patch them. […] Sponsored by Qualys Go to bleepingcomputer
-
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads Hackers gained access to an API for the CPUID project and changed the download links on the official website to serve malicious executables for the popular CPU-Z and HWMonitor tools. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Canadian employees targeted in payroll pirate attacks
Microsoft: Canadian employees targeted in payroll pirate attacks A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees’ salary payments after hijacking their accounts in payroll pirate attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. […] Bill Toulas Go to bleepingcomputer
-
New VENOM phishing attacks steal senior executives’ Microsoft logins
New VENOM phishing attacks steal senior executives’ Microsoft logins Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called “VENOM” are targeting credentials of C-suite executives across multiple industries. […] Bill Toulas Go to bleepingcomputer
-
Healthcare IT solutions provider ChipSoft hit by ransomware attack
Healthcare IT solutions provider ChipSoft hit by ransomware attack Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers. […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds infostealer protection against session cookie theft
Google Chrome adds infostealer protection against session cookie theft Google has rolled out Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows, designed to block info-stealing malware from harvesting session cookies. […] Ionut Ilascu Go to bleepingcomputer
-
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Smart Slider updates hijacked to push malicious WordPress, Joomla versions Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploiting Acrobat Reader zero-day flaw since December
Hackers exploiting Acrobat Reader zero-day flaw since December Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot Bitcoin Depot, which operates one of the largest Bitcoin ATM networks, says attackers stole $3.665 million worth of Bitcoin from its crypto wallets after breaching its systems last month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft suspends dev accounts for high-profile open source projects
Microsoft suspends dev accounts for high-profile open source projects Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers use pixel-large SVG trick to hide credit card stealer
Hackers use pixel-large SVG trick to hide credit card stealer A massive campaign impacting nearly 100 online stores using the Magento e-commerce platform hides credit card-stealing code in a pixel-sized Scalable Vector Graphics (SVG) image. […] Bill Toulas Go to bleepingcomputer
-
Google: New UNC6783 hackers steal corporate Zendesk support tickets
Google: New UNC6783 hackers steal corporate Zendesk support tickets A threat actor tracked as UNC6783 is compromising business process outsourcing (BPO) providers to gain access to high-value companies across multiple sectors. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit critical flaw in Ninja Forms WordPress plugin
Hackers exploit critical flaw in Ninja Forms WordPress plugin A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution. […] Bill Toulas Go to bleepingcomputer
-
FBI: Americans lost a record $21 billion to cybercrime last year
FBI: Americans lost a record $21 billion to cybercrime last year U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise, tech support fraud, and data breaches, the Federal Bureau of Investigation says. […] Bill Toulas Go to bleepingcomputer
-
Snowflake customers hit in data theft attacks after SaaS integrator breach
Snowflake customers hit in data theft attacks after SaaS integrator breach Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen. […] Lawrence Abrams Go to bleepingcomputer
-
US warns of Iranian hackers targeting critical infrastructure
US warns of Iranian hackers targeting critical infrastructure Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
German authorities identify REvil and GandCrab ransomware bosses
German authorities identify REvil and GandCrab ransomware bosses The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. […] Bill Toulas Go to bleepingcomputer
-
New GPUBreach attack enables system takeover via GPU rowhammer
New GPUBreach attack enables system takeover via GPU rowhammer A new attack, dubbed GPUBreach, can induce Rowhammer bit-flips on GPU GDDR6 memories to escalate privileges and lead to a full system compromise. […] Bill Toulas Go to bleepingcomputer
-
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions. […] Bill Toulas Go to bleepingcomputer
-
Traffic violation scams switch to QR codes in new phishing texts
Traffic violation scams switch to QR codes in new phishing texts Scammers are sending fake “Notice of Default” traffic violation text messages impersonating state courts across the U.S., pressuring recipients to scan a QR code that leads to a phishing site demanding a $6.99 payment while stealing personal and financial information. […] Lawrence Abrams Go…
-
New FortiClient EMS flaw exploited in attacks, emergency patch released
New FortiClient EMS flaw exploited in attacks, emergency patch released Fortinet has released an emergency weekend security update for a new critical FortiClient Enterprise Management Server (EMS) vulnerability that is actively exploited in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit React2Shell in automated credential theft campaign
Hackers exploit React2Shell in automated credential theft campaign Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. […] Bill Toulas Go to bleepingcomputer
-
Axios npm hack used fake Teams error fix to hijack maintainer account
Axios npm hack used fake Teams error fix to hijack maintainer account The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers was targeted by a social engineering campaign believed to have been conducted by North Korean threat actors. […] Lawrence Abrams Go to bleepingcomputer
-
Device code phishing attacks surge 37x as new kits spread online
Device code phishing attacks surge 37x as new kits spread online Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. […] Bill Toulas Go to bleepingcomputer
-
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data A new report dubbed “BrowserGate” warns that Microsoft’s LinkedIn is using hidden JavaScript scripts on its website to scan visitors’ browsers for installed extensions and collect device data. […] Lawrence Abrams Go to bleepingcomputer