Category: Security
-
New China-linked hackers breach telcos using edge device exploits
New China-linked hackers breach telcos using edge device exploits A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe. […] Bill Toulas Go to bleepingcomputer
-
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of Identity Service Engine flaw with exploit code
Cisco warns of Identity Service Engine flaw with exploit code Cisco has patched an ISE vulnerability with public proof-of-concept exploit code that can be abused by attackers with admin privileges. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags max severity HPE OneView flaw as actively exploited
CISA tags max severity HPE OneView flaw as actively exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a maximum-severity HPE OneView vulnerability as actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
New GoBruteforcer attack wave targets crypto, blockchain projects
New GoBruteforcer attack wave targets crypto, blockchain projects A new wave of GoBruteforcer botnet malware attacks is targeting databases of cryptocurrency and blockchain projects on exposed servers believed to be configured using AI-generated examples. […] Bill Toulas Go to bleepingcomputer
-
Critical jsPDF flaw lets hackers steal secrets via generated PDFs
Critical jsPDF flaw lets hackers steal secrets via generated PDFs The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files. […] Bill Toulas Go to bleepingcomputer
-
Taiwan says China’s attacks on its energy sector increased tenfold
Taiwan says China’s attacks on its energy sector increased tenfold The National Security Bureau in Taiwan says that China’s attacks on the country’s energy sector increased tenfold in 2025 compared to the previous year. […] Bill Toulas Go to bleepingcomputer
-
Kimwolf Android botnet abuses residential proxies to infect internal devices
Kimwolf Android botnet abuses residential proxies to infect internal devices The Kimwolf botnet, an Android variant of the Aisuru malware, has grown to more than two million hosts, most of them infected by exploiting vulnerabilities in residential proxy networks to target devices on internal networks. […] Bill Toulas Go to bleepingcomputer
-
New D-Link flaw in legacy DSL routers actively exploited in attacks
New D-Link flaw in legacy DSL routers actively exploited in attacks Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago. […] Bill Toulas Go to bleepingcomputer
-
Cloud file-sharing sites targeted for corporate data theft attacks
Cloud file-sharing sites targeted for corporate data theft attacks A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. […] Bill Toulas Go to bleepingcomputer
-
ClickFix attack uses fake Windows BSOD screens to push malware
ClickFix attack uses fake Windows BSOD screens to push malware A new ClickFix social engineering campaign is targeting the hospitality sector in Europe, using fake Windows Blue Screen of Death (BSOD) screens to trick users into manually compiling and executing malware on their systems. […] Bill Toulas Go to bleepingcomputer
-
VSCode IDE forks expose users to “recommended extension” attacks
VSCode IDE forks expose users to “recommended extension” attacks Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions. […] Bill Toulas Go to bleepingcomputer
-
US broadband provider Brightspeed investigates breach claims
US broadband provider Brightspeed investigates breach claims Brightspeed, one of the largest fiber broadband companies in the United States, is investigating security breach and data theft claims made by the Crimson Collective extortion gang. […] Sergiu Gatlan Go to bleepingcomputer
-
Ledger customers impacted by third-party Global-e data breach
Ledger customers impacted by third-party Global-e data breach Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e. […] Bill Toulas Go to bleepingcomputer
-
Hackers claim to hack Resecurity, firm says it was a honeypot
Hackers claim to hack Resecurity, firm says it was a honeypot The ShinyHunters hacking group claims it breached the systems of cybersecurity firm Resecurity and stole internal data, while Resecurity says the attackers only accessed a deliberately deployed honeypot containing fake information used to monitor their activity. […] Lawrence Abrams Go to bleepingcomputer
-
Covenant Health says May data breach impacted nearly 478,000 patients
Covenant Health says May data breach impacted nearly 478,000 patients The Covenant Health organization has revised to nearly 500,000 the number of individuals affected by a data breach discovered last May. […] Ionut Ilascu Go to bleepingcomputer
-
Cryptocurrency theft attacks traced to 2022 LastPass breach
Cryptocurrency theft attacks traced to 2022 LastPass breach Blockchain investigation firm TRM Labs says ongoing cryptocurrency thefts have been traced to the 2022 LastPass breach, with attackers draining wallets years after encrypted vaults were stolen and laundering the crypto through Russian exchanges. […] Lawrence Abrams Go to bleepingcomputer
-
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass Over 10,000 Internet-exposed Fortinet firewalls are still vulnerable to attacks exploiting a five-year-old two-factor authentication (2FA) bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack Trust Wallet believes the compromise of its web browser to steal roughly $8.5 million from over 2,500 crypto wallets is likely related to an “industry-wide” Sha1-Hulud attack in November. […] Sergiu Gatlan Go to bleepingcomputer
-
The biggest cybersecurity and cyberattack stories of 2025
The biggest cybersecurity and cyberattack stories of 2025 2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course, zero-day flaws exploited in breaches. Some stories, though, were more impactful or popular with our readers than others. This article explores 15 of the biggest cybersecurity stories…
-
New GlassWorm malware wave targets Macs with trojanized crypto wallets
New GlassWorm malware wave targets Macs with trojanized crypto wallets A fourth wave of the “GlassWorm” campaign is targeting macOS developers with malicious VSCode/OpenVSX extensions that deliver trojanized versions of crypto wallet applications. […] Bill Toulas Go to bleepingcomputer
-
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices New York City’s 2026 mayoral inauguration of Zohran Mamdani has published a list of banned items for the event, specifically prohibiting the Flipper Zero and Raspberry Pi devices. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers drain $3.9M from Unleash Protocol after multisig hijack
Hackers drain $3.9M from Unleash Protocol after multisig hijack The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals. […] Bill Toulas Go to bleepingcomputer
-
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
RondoDox botnet exploits React2Shell flaw to breach Next.js servers The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. […] Bill Toulas Go to bleepingcomputer
-
IBM warns of critical API Connect auth bypass vulnerability
IBM warns of critical API Connect auth bypass vulnerability IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Disney will pay $10 million to settle children’s data privacy lawsuit
Disney will pay $10 million to settle children’s data privacy lawsuit Disney has agreed to pay a $10 million civil penalty to settle claims that it violated the Children’s Online Privacy Protection Act by mislabeling videos and allowing data collection for targeted advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
New ErrTraffic service enables ClickFix attacks via fake browser glitches
New ErrTraffic service enables ClickFix attacks via fake browser glitches A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating ‘fake glitches’ on compromised websites to lure users into downloading payloads or following malicious instructions […] Bill Toulas Go to bleepingcomputer
-
European Space Agency confirms breach of “external servers”
European Space Agency confirms breach of “external servers” The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as “unclassified” information on collaborative engineering activities. […] Sergiu Gatlan Go to bleepingcomputer
-
Zoom Stealer browser extensions harvest corporate meeting intelligence
Zoom Stealer browser extensions harvest corporate meeting intelligence A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords. […] Bill Toulas Go to bleepingcomputer
-
US cybersecurity experts plead guilty to BlackCat ransomware attacks
US cybersecurity experts plead guilty to BlackCat ransomware attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese state hackers use rootkit to hide ToneShell malware activity
Chinese state hackers use rootkit to hide ToneShell malware activity A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations. […] Bill Toulas Go to bleepingcomputer
-
Coupang to split $1.17 billion among 33.7 million data breach victims
Coupang to split $1.17 billion among 33.7 million data breach victims Coupang, the largest retailer in South Korea, announced $1.17 billion (1.685 trillion Won) total compensation for the 33.7 million customers whose information was exposed in the data breach discovered last month. […] Bill Toulas Go to bleepingcomputer
-
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software. […] Bill Toulas Go to bleepingcomputer
-
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack Trust Wallet says attackers who compromised its browser extension right before Christmas have drained approximately $7 million from nearly 3,000 cryptocurrency wallet addresses. […] Sergiu Gatlan Go to bleepingcomputer
-
The Real-World Attacks Behind OWASP Agentic AI Top 10
The Real-World Attacks Behind OWASP Agentic AI Top 10 OWASP’s new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused.…
-
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web. […] Ionut Ilascu Go to bleepingcomputer
-
Hacker claims to leak WIRED database with 2.3 million records
Hacker claims to leak WIRED database with 2.3 million records A hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while also warning that they plan to release up to 40 million additional records for other Condé Nast properties. […] Lawrence Abrams Go to…
-
Massive Rainbow Six Siege breach gives players billions of credits
Massive Rainbow Six Siege breach gives players billions of credits Ubisoft’s Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game currency and cosmetic items to accounts worldwide. […] Lawrence Abrams Go to bleepingcomputer
-
Fake Grubhub emails promise tenfold return on sent cryptocurrency
Fake Grubhub emails promise tenfold return on sent cryptocurrency Grubhub users received fraudulent messages, apparently from a company email address, promising a tenfold bitcoin payout in return for a transfer to a specified wallet. […] Ionut Ilascu Go to bleepingcomputer
-
Trust Wallet confirms extension hack led to $7 million crypto theft
Trust Wallet confirms extension hack led to $7 million crypto theft Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.…
-
Trust Wallet Chrome extension hack tied to millions in losses
Trust Wallet Chrome extension hack tied to millions in losses Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers. […]…
-
Fake MAS Windows activation domain used to spread PowerShell malware
Fake MAS Windows activation domain used to spread PowerShell malware A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the ‘Cosmali Loader’. […] Bill Toulas Go to bleepingcomputer
-
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB warns admins to patch severe RCE flaw immediately MongoDB has warned IT admins to immediately patch a high-severity vulnerability that can be exploited in remote code execution (RCE) attacks targeting vulnerable servers. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI seizes domain storing bank credentials stolen from U.S. victims
FBI seizes domain storing bank credentials stolen from U.S. victims The U.S. government has seized the ‘web3adspanels.org’ domain and the associated database used by cybercriminals to host bank login credentials stolen in account takeover attacks. […] Bill Toulas Go to bleepingcomputer
-
WebRAT malware spread via fake vulnerability exploits on GitHub
WebRAT malware spread via fake vulnerability exploits on GitHub The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
Malicious extensions in Chrome Web store steal user credentials
Malicious extensions in Chrome Web store steal user credentials Two Chrome extensions in the Web Store named ‘Phantom Shuttle’ are posing as plugins for a proxy service to hijack user traffic and steal sensitive data. […] Bill Toulas Go to bleepingcomputer
-
Cyberattack knocks offline France’s postal, banking services
Cyberattack knocks offline France’s postal, banking services The French national postal service’s online services were knocked offline by “a major network incident” on Monday, disrupting digital banking and other services for millions. […] Sergiu Gatlan Go to bleepingcomputer
-
Italy fines Apple $116 million over App Store privacy policy issues
Italy fines Apple $116 million over App Store privacy policy issues Italy’s competition authority (AGCM) has fined Apple €98.6 million ($116 million) for using the App Tracking Transparency (ATT) privacy framework to abuse its dominant market position in mobile app advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
Baker University says 2024 data breach impacts 53,000 people
Baker University says 2024 data breach impacts 53,000 people Baker University has disclosed a data breach after attackers gained access to its network one year ago and stole the personal, health, and financial information of over 53,000 individuals. […] Sergiu Gatlan Go to bleepingcomputer
-
Nissan says thousands of customers exposed in Red Hat breach
Nissan says thousands of customers exposed in Red Hat breach Nissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September. […] Bill Toulas Go to bleepingcomputer
-
New MacSync malware dropper evades macOS Gatekeeper checks
New MacSync malware dropper evades macOS Gatekeeper checks The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application. […] Bill Toulas Go to bleepingcomputer
-
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
Interpol-led action decrypts 6 ransomware strains, arrests hundreds An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents. […] Bill Toulas Go to bleepingcomputer
-
Malicious npm package steals WhatsApp accounts and messages
Malicious npm package steals WhatsApp accounts and messages A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account. […] Bill Toulas Go to bleepingcomputer
-
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
Ukrainian hacker admits affiliate role in Nefilim ransomware gang A Ukrainian national pleaded guilty on Friday to conducting Nefilim ransomware attacks that targeted high-revenue businesses across the United States and other countries. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Critical RCE flaw impacts over 115,000 WatchGuard firewalls Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Docker Hardened Images now open source and available for free
Docker Hardened Images now open source and available for free More than a 1,000 Docker Hardened Images (DHI) are now freely available and open source for software builders, under the Apache 2.0 license. […] Bill Toulas Go to bleepingcomputer
-
RansomHouse upgrades encryption with multi-layered data processing
RansomHouse upgrades encryption with multi-layered data processing The RansomHouse ransomware-as-a-service (RaaS) has recently upgraded its encryptor, switching from a relatively simple single-phase linear technique to a more complex, multi-layered method. […] Bill Toulas Go to bleepingcomputer
-
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform The Nigerian police have arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing-as-a-service. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 accounts targeted in wave of OAuth phishing attacks
Microsoft 365 accounts targeted in wave of OAuth phishing attacks Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. […] Bill Toulas Go to bleepingcomputer
-
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. […] Bill Toulas Go to bleepingcomputer
-
Over 25,000 FortiCloud SSO devices exposed to remote attacks
Over 25,000 FortiCloud SSO devices exposed to remote attacks Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
University of Sydney suffers data breach exposing student and staff info
University of Sydney suffers data breach exposing student and staff info Hackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal information of staff and students. […] Bill Toulas Go to bleepingcomputer
-
Clop ransomware targets Gladinet CentreStack in data theft attacks
Clop ransomware targets Gladinet CentreStack in data theft attacks The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New password spraying attacks target Cisco, PAN VPN gateways
New password spraying attacks target Cisco, PAN VPN gateways An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN. […] Bill Toulas Go to bleepingcomputer
-
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
Zeroday Cloud hacking event awards $320,0000 for 11 zero days The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
France arrests suspect tied to cyberattack on Interior Ministry
France arrests suspect tied to cyberattack on Interior Ministry French authorities arrested a 22-year-old suspect on Tuesday for a cyberattack that targeted France’s Ministry of the Interior earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts Amazon’s AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Access Management (IAM). […] Bill Toulas Go to bleepingcomputer
-
WhatsApp device linking abused in account hijacking attacks
WhatsApp device linking abused in account hijacking attacks Threat actors are abusing the legitimate device-linking feature to hijack WhatsApp accounts via pairing codes in a campaign dubbed GhostPairing. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
Cisco warns of unpatched AsyncOS zero-day exploited in attacks Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. […] Sergiu Gatlan Go to bleepingcomputer
-
Cellik Android malware builds malicious versions from Google Play apps
Cellik Android malware builds malicious versions from Google Play apps A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground cybercrime forums offering a robust set of capabilities that include the option to embed it in any app available on the Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
GhostPoster attacks hide malicious JavaScript in Firefox addon logos
GhostPoster attacks hide malicious JavaScript in Firefox addon logos A new campaign dubbed ‘GhostPoster’ is hiding JavaScript code in the image logo of malicious Firefox extensions counting more than 50,000 downloads, to monitor browser activity and plant a backdoor. […] Bill Toulas Go to bleepingcomputer
-
Texas sues TV makers for taking screenshots of what people watch
Texas sues TV makers for taking screenshots of what people watch The Texas Attorney General sued five major television manufacturers, accusing them of illegally collecting their users’ data by secretly recording what they watch using Automated Content Recognition (ACR) technology. […] Sergiu Gatlan Go to bleepingcomputer
-
Amazon disrupts Russian GRU hackers attacking edge network devices
Amazon disrupts Russian GRU hackers attacking edge network devices The Amazon Threat Intelligence team has disrupted active operations attributed to hackers working for the Russian foreign military intelligence agency, the GRU, who targeted customers’ cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit newly patched Fortinet auth bypass flaws
Hackers exploit newly patched Fortinet auth bypass flaws Hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files. […] Bill Toulas Go to bleepingcomputer
-
SoundCloud confirms breach after member data stolen, VPN access disrupted
SoundCloud confirms breach after member data stolen, VPN access disrupted Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database exposing users’ email addresses and profile information. […] Lawrence Abrams Go to bleepingcomputer
-
Google is shutting down its dark web report feature in January
Google is shutting down its dark web report feature in January Google is discontinuing its “dark web report” security tool, stating that it wants to focus on other tools it believes are more helpful. […] Mayank Parmar Go to bleepingcomputer
-
Askul confirms theft of 740k customer records in ransomware attack
Askul confirms theft of 740k customer records in ransomware attack Japanese e-commerce giant Askul Corporation has confirmed that RansomHouse hackers stole around 740,000 customer records in the ransomware attack it suffered in October. […] Bill Toulas Go to bleepingcomputer
-
New SantaStealer malware steals data from browsers, crypto wallets
New SantaStealer malware steals data from browsers, crypto wallets A new malware-as-a-service (MaaS) information stealer named SantaStealer is being advertised on Telegram and hacker forums as operating in memory to avoid file-based detection. […] Bill Toulas Go to bleepingcomputer
-
PornHub extorted after hackers steal Premium member activity data
PornHub extorted after hackers steal Premium member activity data Adult video platform PornHub is being extorted by the ShinyHunters extortion gang after the search and watch history of its Premium members was reportedly stolen in a recent Mixpanel data breach. […] Lawrence Abrams Go to bleepingcomputer
-
Beware: PayPal subscriptions abused to send fake purchase emails
Beware: PayPal subscriptions abused to send fake purchase emails An email scam is abusing abusing PayPal’s “Subscriptions” billing feature to send legitimate PayPal emails that contain fake purchase notifications embedded in the Customer service URL field. […] Lawrence Abrams Go to bleepingcomputer
-
CyberVolk’s ransomware debut stumbles on cryptography weakness
CyberVolk’s ransomware debut stumbles on cryptography weakness The pro-Russia hacktivist group CyberVolk launched a ransomware-as-a-service (RaaS) called VolkLocker that suffered from serious implementation flaws, allowing victims to potentially decrypt files for free. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
Coupang data breach traced to ex-employee who retained system access
Coupang data breach traced to ex-employee who retained system access A data breach at Coupang that exposed the information of 33.7 million customers has been tied to a former employee who retained access to internal systems after leaving the company. […] Bill Toulas Go to bleepingcomputer
-
Fake ‘One Battle After Another’ torrent hides malware in subtitles
Fake ‘One Battle After Another’ torrent hides malware in subtitles A fake torrent for Leonardo DiCaprio’s ‘One Battle After Another’ hides malicious PowerShell malware loaders inside subtitle files that ultimately infect devices with the Agent Tesla RAT malware. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2025.4 released with 3 new tools, desktop updates
Kali Linux 2025.4 released with 3 new tools, desktop updates Kali Linux has released version 2025.4, its final update of the year, introducing three new hacking tools, desktop environment improvements, the preview of Wifipumpkin3 in NetHunter, and enhanced Wayland support. […] Lawrence Abrams Go to bleepingcomputer
-
Shadow spreadsheets: The security gap your tools can’t see
Shadow spreadsheets: The security gap your tools can’t see When official systems can’t support everyday workflows, employees turn to spreadsheets — creating “shadow spreadsheets” that circulate unchecked. Grist shows how these spreadsheets expose sensitive data, create version sprawl, and remove the audit trails security teams depend on. […] Sponsored by Grist Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Geoserver flaw
CISA orders feds to patch actively exploited Geoserver flaw CISA has ordered U.S. federal agencies to patch a critical GeoServer vulnerability now actively exploited in XML External Entity (XXE) injection attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
MITRE shares 2025’s top 25 most dangerous software weaknesses
MITRE shares 2025’s top 25 most dangerous software weaknesses MITRE has shared this year’s top 25 list of the most dangerous software weaknesses behind over 39,000 security vulnerabilities disclosed between June 2024 and June 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
MKVCinemas streaming piracy service with 142M visits shuts down
MKVCinemas streaming piracy service with 142M visits shuts down An anti-piracy coalition has dismantled one of India’s most popular streaming piracy services, which has provided free access to movies and TV shows to millions over the past two years. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet’s CentreStack and Triofox products for secure remote file access and sharing. […] Bill Toulas Go to bleepingcomputer
-
Google fixes eighth Chrome zero-day exploited in attacks in 2025
Google fixes eighth Chrome zero-day exploited in attacks in 2025 Google has released emergency updates to fix another Chrome zero-day vulnerability exploited in the wild, marking the eighth such security flaw patched since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware A new AMOS infostealer campaign is abusing Google search ads to lure users into Grok and ChatGPT conversations that appear to offer “helpful” instructions but ultimately lead to installing the AMOS info-stealing malware on macOS. […] Bill Toulas Go to bleepingcomputer
-
New DroidLock malware locks Android devices and demands a ransom
New DroidLock malware locks Android devices and demands a ransom A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to warn of suspicious traffic with external domains
Microsoft Teams to warn of suspicious traffic with external domains Microsoft is working on a new Teams security feature that will analyze suspicious traffic with external domains to help IT administrators tackle potential security threats. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 10,000 Docker Hub images found leaking credentials, auth keys
Over 10,000 Docker Hub images found leaking credentials, auth keys More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys. […] Bill Toulas Go to bleepingcomputer
-
SAP fixes three critical vulnerabilities across multiple products
SAP fixes three critical vulnerabilities across multiple products SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws. […] Bill Toulas Go to bleepingcomputer
-
Windows PowerShell now warns when running Invoke-WebRequest scripts
Windows PowerShell now warns when running Invoke-WebRequest scripts Microsoft says Windows PowerShell now warns when running scripts that use the Invoke-WebRequest cmdlet to download web content, aiming to prevent potentially risky code from executing. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5071546 extended security update
Microsoft releases Windows 10 KB5071546 extended security update Microsoft has released the KB5071546 extended security update to resolve 57 security vulnerabilities, including three zero-day flaws. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws Microsoft’s December 2025 Patch Tuesday fixes 57 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Fortinet warns of critical FortiCloud SSO login auth bypass flaws
Fortinet warns of critical FortiCloud SSO login auth bypass flaws Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. […] Sergiu Gatlan Go to bleepingcomputer