Category: Security
-
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
Ransomware gangs turn to Shanya EXE packer to hide EDR killers Several ransomware groups have been spotted using a packer-as-a-service (PaaS) platform named Shanya to assist in EDR (endpoint detection and response) killing operations. […] Bill Toulas Go to bleepingcomputer
-
Malicious VSCode extensions on Microsoft’s registry drop infostealers
Malicious VSCode extensions on Microsoft’s registry drop infostealers Two malicious extensions on Microsoft’s Visual Studio Code Marketplace infect developers’ machines with information-stealing malware that can take screenshots, steal credentials, and hijack browser sessions. […] Bill Toulas Go to bleepingcomputer
-
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024 A new report by the Financial Crimes Enforcement Network (FinCEN) shows that ransomware activity peaked in 2023 before falling in 2024, following a series of law enforcement actions targeting the ALPHV/BlackCat and LockBit ransomware gangs. […] Lawrence Abrams Go to bleepingcomputer
-
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment The police in Poland arrested three Ukrainian nationals for allegedly attempting to damage IT systems in the country using hacking equipment and for obtaining “computer data of particular importance to national defense.” […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds new security layer for Gemini AI agentic browsing
Google Chrome adds new security layer for Gemini AI agentic browsing Google Chrome is introducing a new security architecture designed to protect upcoming agentic AI browsing features powered by Gemini. […] Bill Toulas Go to bleepingcomputer
-
Portugal updates cybercrime law to exempt security researchers
Portugal updates cybercrime law to exempt security researchers Portugal has modified its cybercrime law to establish a legal safe harbor for good-faith security research and to make hacking non-punishable under certain strict conditions. […] Bill Toulas Go to bleepingcomputer
-
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors. […] Lawrence Abrams Go to bleepingcomputer
-
New wave of VPN login attempts targets Palo Alto GlobalProtect portals
New wave of VPN login attempts targets Palo Alto GlobalProtect portals A campaign has been observed targeting Palo Alto GlobalProtect portals with login attempts and launching scanning activity against SonicWall SonicOS API endpoints. […] Bill Toulas Go to bleepingcomputer
-
Barts Health NHS discloses data breach after Oracle zero-day hack
Barts Health NHS discloses data breach after Oracle zero-day hack Barts Health NHS Trust has announced that Clop ransomware actors have stolen files from a database by exploiting a vulnerability in its Oracle E-business Suite software. […] Bill Toulas Go to bleepingcomputer
-
FBI warns of virtual kidnapping scams using altered social media photos
FBI warns of virtual kidnapping scams using altered social media photos The FBI warns of criminals altering images shared on social media and using them as fake proof of life photos in virtual kidnapping ransom scams. […] Sergiu Gatlan Go to bleepingcomputer
-
A Practical Guide to Continuous Attack Surface Visibility
A Practical Guide to Continuous Attack Surface Visibility Passive scan data goes stale fast as cloud assets shift daily, leaving teams blind to real exposures. Sprocket Security shows how continuous, automated recon gives accurate, up-to-date attack surface visibility. […] Sponsored by Sprocket Security Go to bleepingcomputer
-
EU fines X $140 million over deceptive blue checkmarks
EU fines X $140 million over deceptive blue checkmarks The European Commission has fined X €120 million ($140 million) for violating transparency obligations under the Digital Services Act (DSA). […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare blames today’s outage on React2Shell mitigations
Cloudflare blames today’s outage on React2Shell mitigations Cloudflare has blamed today’s outage on the emergency patching of a critical React remote code execution vulnerability, which is now actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create rogue users. […] Bill Toulas Go to bleepingcomputer
-
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices The UK’s National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. […] Bill Toulas Go to bleepingcomputer
-
Predator spyware uses new infection vector for zero-click attacks
Predator spyware uses new infection vector for zero-click attacks The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed “Aladdin” that compromised specific targets when simply viewing a malicious advertisement. […] Bill Toulas Go to bleepingcomputer
-
Russia blocks FaceTime and Snapchat for alleged use by terrorists
Russia blocks FaceTime and Snapchat for alleged use by terrorists Russian telecommunications watchdog Roskomnadzor has blocked access to Apple’s FaceTime video conferencing platform and the Snapchat instant messaging service, claiming they’re being used to coordinate terrorist attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Marquis data breach impacts over 74 US banks, credit unions
Marquis data breach impacts over 74 US banks, credit unions Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and credit unions across the US. […] Lawrence Abrams Go to bleepingcomputer
-
Critical flaw in WordPress add-on for Elementor exploited in attacks
Critical flaw in WordPress add-on for Elementor exploited in attacks Attackers are exploiting a critical-severity privilege escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor plugin for WordPress, which lets them obtain administrative permissions during the registration process. […] Bill Toulas Go to bleepingcomputer
-
French DIY retail giant Leroy Merlin discloses a data breach
French DIY retail giant Leroy Merlin discloses a data breach Leroy Merlin is sending security breach notifications to customers in France, informing them that their personal data was compromised. […] Bill Toulas Go to bleepingcomputer
-
Freedom Mobile discloses data breach exposing customer data
Freedom Mobile discloses data breach exposing customer data Freedom Mobile, the fourth-largest wireless carrier in Canada, has disclosed a data breach after attackers hacked into its customer account management platform and stole the personal information of an undisclosed number of customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia blocks Roblox over distribution of LGBT “propaganda”
Russia blocks Roblox over distribution of LGBT “propaganda” Roskomnadzor, Russia’s telecommunications watchdog, has blocked access to the Roblox online gaming platform for failing to stop the distribution of what it described as LGBT propaganda and extremist materials. […] Sergiu Gatlan Go to bleepingcomputer
-
Korea arrests suspects selling intimate videos from hacked IP cameras
Korea arrests suspects selling intimate videos from hacked IP cameras The Korean National Police have arrested four individuals suspected of hacking over 120,000 IP cameras across the country and then selling stolen footage to a foreign adult site. […] Bill Toulas Go to bleepingcomputer
-
FTC settlement requires Illuminate to delete unnecessary student data
FTC settlement requires Illuminate to delete unnecessary student data The Federal Trade Commission (FTC) is proposing that education technology provider Illuminate Education to delete unnecessary student data and improve its security to settle allegations related to an incident in 2021 that exposed info of 10 million students. […] Bill Toulas Go to bleepingcomputer
-
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender portal outage disrupts threat hunting alerts
Microsoft Defender portal outage disrupts threat hunting alerts Microsoft is working to mitigate an ongoing incident that has been blocking access to some Defender XDR portal capabilities, including threat hunting alerts. […] Sergiu Gatlan Go to bleepingcomputer
-
Glassworm malware returns in third wave of malicious VS Code packages
Glassworm malware returns in third wave of malicious VS Code packages The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms. […] Bill Toulas Go to bleepingcomputer
-
SmartTube YouTube app for Android TV breached to push malicious update
SmartTube YouTube app for Android TV breached to push malicious update The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer’s signing keys, leading to a malicious update being pushed to users. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Coupang data breach impacts 33.7 million customers
Retail giant Coupang data breach impacts 33.7 million customers South Korea’s largest retailer, Coupang, has suffered a data breach that exposed the personal information of 33.7 million customers. […] Bill Toulas Go to bleepingcomputer
-
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats Hackers impersonate IT pros with deepfakes, fake resumes, and stolen identities, turning hiring pipelines into insider threats. Huntres sLabs explains how stronger vetting and access controls help stop these threats. […] Sponsored by Huntress Labs Go to bleepingcomputer
-
Police takes down Cryptomixer cryptocurrency mixing service
Police takes down Cryptomixer cryptocurrency mixing service Law enforcement officers from Switzerland and Germany have taken down the Cryptomixer cryptocurrency-mixing service, believed to have helped cybercriminals launder stolen funds. […] Sergiu Gatlan Go to bleepingcomputer
-
Japanese beer giant Asahi says data breach hit 1.5 million people
Japanese beer giant Asahi says data breach hit 1.5 million people Asahi Group Holdings, Japan’s largest beer producer, has finished the investigation into the September cyberattack and found that the incident has impacted up to 1.9 million individuals. […] Bill Toulas Go to bleepingcomputer
-
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison A 44-year-old man was sentenced to seven years and four months in prison for operating an “evil twin” WiFi network to steal the data of unsuspecting travelers at various airports across Australia. […] Bill Toulas Go to bleepingcomputer
-
Public GitLab repositories exposed more than 17,000 secrets
Public GitLab repositories exposed more than 17,000 secrets After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains. […] Bill Toulas Go to bleepingcomputer
-
French Football Federation discloses data breach after cyberattack
French Football Federation discloses data breach after cyberattack The French Football Federation (FFF) disclosed a data breach on Friday after attackers used a compromised account to gain access to administrative management software used by football clubs. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious LLMs empower inexperienced hackers with advanced tools
Malicious LLMs empower inexperienced hackers with advanced tools Unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT are improving their capabilities to generate malicious code, delivering functional scripts for ransomware encryptors and lateral movement. […] Bill Toulas Go to bleepingcomputer
-
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI discloses API customer data breach via Mixpanel vendor hack OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel. […] Ionut Ilascu Go to bleepingcomputer
-
New ShadowV2 botnet malware used AWS outage as a test opportunity
New ShadowV2 botnet malware used AWS outage as a test opportunity A new Mirai-based botnet malware named ‘ShadowV2’ has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025 The NordVPN Black Friday Deal is now live, and you can get the best discount available: 77% off that applies automatically when you follow our link. If you’ve been waiting for the right moment to upgrade your online security, privacy, and streaming freedom, this is…
-
Popular Forge library gets fix for signature verification bypass flaw
Popular Forge library gets fix for signature verification bypass flaw A vulnerability in the ‘node-forge’ package, a popular JavaScript cryptography library, could be exploited to bypass signature verifications by crafting data that appears valid. […] Bill Toulas Go to bleepingcomputer
-
Comcast to pay $1.5M fine for vendor breach affecting 270K customers
Comcast to pay $1.5M fine for vendor breach affecting 270K customers Comcast will pay a $1.5 million fine to settle a Federal Communications Commission investigation into a February 2024 vendor data breach that exposed the personal information of nearly 275,000 customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Multiple London councils’ IT systems disrupted by cyberattack
Multiple London councils’ IT systems disrupted by cyberattack The Royal Borough of Kensington and Chelsea (RBKC) and the Westminster City Council (WCC) announced that they are experiencing service disruptions following a cybersecurity issue. […] Bill Toulas Go to bleepingcomputer
-
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide Risk management company Crisis24 has confirmed its OnSolve CodeRED platform suffered a cyberattack that disrupted emergency notification systems used by state and local governments, police departments, and fire agencies across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals Black Friday 2025 is almost here, and early deals are already live across security software, online courses, system administration tools, antivirus products, and VPN services. These discounts are limited-time offers and vary by provider, so if you see something that fits your needs, it’s best…
-
FBI: Cybercriminals stole $262M by impersonating bank support teams
FBI: Cybercriminals stole $262M by impersonating bank support teams The FBI warns of a surge in account takeover (ATO) fraud schemes and says that cybercriminals impersonating various financial institutions have stolen over $262 million in ATO attacks since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Tor switches to new Counter Galois Onion relay encryption algorithm
Tor switches to new Counter Galois Onion relay encryption algorithm Tor has announced improved encryption and security for the circuit traffic by replacing the old tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO). […] Bill Toulas Go to bleepingcomputer
-
Malicious Blender model files deliver StealC infostealing malware
Malicious Blender model files deliver StealC infostealing malware A Russian-linked campaign delivers the StealC V2 information stealer malware through malicious Blender files uploaded to 3D model marketplaces like CGTrader. […] Bill Toulas Go to bleepingcomputer
-
ClickFix attack uses fake Windows Update screen to push malware
ClickFix attack uses fake Windows Update screen to push malware New ClickFix attack variants have been observed where threat actors trick users with a realistic-looking Windows Update animation in a full-screen browser page and hide the malicious code inside images. […] Bill Toulas Go to bleepingcomputer
-
Real-estate finance services giant SitusAMC breach exposes client data
Real-estate finance services giant SitusAMC breach exposes client data SitusAMC, a company that provides back-end services for top banks and lenders, disclosed on Saturday a data breach it had discovered earlier this month that impacted customer data. […] Bill Toulas Go to bleepingcomputer
-
SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching
SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching Hybrid work exposes the limits of SCCM and WSUS, with remote devices often missing updates and WSUS now deprecated. Action1’s cloud-native patching keeps devices updated from any location, strengthening compliance and security. […] Sponsored by Action1 Go to bleepingcomputer
-
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign. […] Bill Toulas Go to bleepingcomputer
-
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop
Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop Google has added interoperability support between Android Quick Share and Apple AirDrop, to let users share files between Pixel devices and iPhones. […] Bill Toulas Go to bleepingcomputer
-
Enterprise password security and secrets management with Passwork 7
Enterprise password security and secrets management with Passwork 7 Passwork 7 unifies enterprise password and secrets management in a self-hosted platform. Organizations can automate credential workflows and test the full system with a free trial and up to 50% Black Friday savings. […] Sponsored by Passwork Go to bleepingcomputer
-
Iberia discloses customer data leak after vendor security breach
Iberia discloses customer data leak after vendor security breach Spanish flag carrier Iberia has begun notifying customers of a data security incident stemming from a compromise at one of its suppliers. The disclosure comes days after a threat actor claimed on hacker forums to have access to 77 GB of data allegedly stolen from the…
-
New Costco Gold Star Members also get a $40 Digital Costco Shop Card
New Costco Gold Star Members also get a $40 Digital Costco Shop Card The holidays can be hard on any budget, but there may be a way to make it a little easier. Instead of dashing through the snow all around town, get all your shopping done under one roof at Costco. Right now, you…
-
WhatsApp API flaw let researchers scrape 3.5 billion accounts
WhatsApp API flaw let researchers scrape 3.5 billion accounts Researchers compiled a list of 3.5 billion WhatsApp mobile phone numbers and associated personal information by abusing a contact-discovery API that lacked rate limiting. […] Lawrence Abrams Go to bleepingcomputer
-
Cox Enterprises discloses Oracle E-Business Suite data breach
Cox Enterprises discloses Oracle E-Business Suite data breach Cox Enterprises is notifying impacted individuals of a data breach that exposed their personal data to hackers who breached the company network after exploiting a zero-day flaw in Oracle E-Business Suite. […] Bill Toulas Go to bleepingcomputer
-
Piecing Together the Puzzle: A Qilin Ransomware Investigation
Piecing Together the Puzzle: A Qilin Ransomware Investigation Huntress analysts reconstructed a Qilin ransomware attack from a single endpoint, using limited logs to reveal rogue ScreenConnect access, failed infostealer attempts, and the ransomware execution path. The investigation shows how validating multiple data sources can uncover activity even when visibility is reduced to a “pinhole.” […]…
-
CISA warns Oracle Identity Manager RCE flaw is being actively exploited
CISA warns Oracle Identity Manager RCE flaw is being actively exploited The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning government agencies to patch an Oracle Identity Manager tracked as CVE-2025-61757 that has been exploited in attacks, potentially as a zero-day. […] Lawrence Abrams Go to bleepingcomputer
-
Grafana warns of max severity admin spoofing vulnerability
Grafana warns of max severity admin spoofing vulnerability Grafana Labs is warning of a maximum severity vulnerability (CVE-2025-41115) in its Enterprise product that can be exploited to treat new users as administrators or for privilege escalation. […] Bill Toulas Go to bleepingcomputer
-
CrowdStrike catches insider feeding information to hackers
CrowdStrike catches insider feeding information to hackers American cybersecurity firm CrowdStrike has confirmed that an insider shared screenshots taken on internal systems with hackers after they were leaked on Telegram by the Scattered Lapsus$ Hunters threat actors. […] Sergiu Gatlan Go to bleepingcomputer
-
Google exposes BadAudio malware used in APT24 espionage campaigns
Google exposes BadAudio malware used in APT24 espionage campaigns China-linked APT24 hackers have been using a previously undocumented malware called BadAudio in a three-year espionage campaign that recently switched to more sophisticated attack methods. […] Bill Toulas Go to bleepingcomputer
-
Hacker claims to steal 2.3TB data from Italian rail group, Almaviva
Hacker claims to steal 2.3TB data from Italian rail group, Almaviva Data from Italy’s national railway operator, the FS Italiane Group, has been exposed after a threat actor breached the organization’s IT services provider, Almaviva. […] Bill Toulas Go to bleepingcomputer
-
GlobalProtect VPN portals probed with 2.3 million scan sessions
GlobalProtect VPN portals probed with 2.3 million scan sessions A major spike in malicious scanning against Palo Alto Networks GlobalProtect portals has been detected, starting on November 14, 2025. […] Bill Toulas Go to bleepingcomputer
-
Salesforce investigates customer data theft via Gainsight breach
Salesforce investigates customer data theft via Gainsight breach Salesforce says it revoked refresh tokens linked to Gainsight-published applications while investigating a new wave of data theft attacks targeting customers. […] Sergiu Gatlan Go to bleepingcomputer
-
New SonicWall SonicOS flaw allows hackers to crash firewalls
New SonicWall SonicOS flaw allows hackers to crash firewalls American cybersecurity company SonicWall urged customers today to patch a high-severity SonicOS SSLVPN security flaw that can allow attackers to crash vulnerable firewalls. […] Sergiu Gatlan Go to bleepingcomputer
-
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
Multi-threat Android malware Sturnus steals Signal, WhatsApp messages A new Android banking trojan named Sturnus can capture communication from end-to-end encrypted messaging platforms like Signal, WhatsApp, and Telegram, as well as take complete control of the device. […] Bill Toulas Go to bleepingcomputer
-
Sneaky2FA PhaaS kit now uses redteamers’ Browser-in-the-Browser attack
Sneaky2FA PhaaS kit now uses redteamers’ Browser-in-the-Browser attack Sneaky2FA, a popular among cybercriminals phishing-as-a-service (PhaaS) kit, has added Browser-in-the-Browser (BitB) capabilities, giving “customers” the option to launch highly deceptive attacks. […] Bill Toulas Go to bleepingcomputer
-
New ShadowRay attacks convert Ray clusters into crypto miners
New ShadowRay attacks convert Ray clusters into crypto miners A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools
Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools Microsoft announced two new Windows 11 recovery features today at the Ignite developer conference, called Cloud Rebuild and Point-in-Time Restore (PITR), that aim to reduce downtime and make it easier to recover from system failures or faulty updates. […] Lawrence Abrams Go to bleepingcomputer
-
Fortinet warns of new FortiWeb zero-day exploited in attacks
Fortinet warns of new FortiWeb zero-day exploited in attacks Today, Fortinet released security updates to patch a new FortiWeb zero-day vulnerability that threat actors are actively exploiting in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to integrate Sysmon directly into Windows 11, Server 2025
Microsoft to integrate Sysmon directly into Windows 11, Server 2025 Microsoft announced today that it will integrate Sysmon natively into Windows 11 and Windows Server 2025 next year, making it unnecessary to deploy the standalone Sysinternals tools. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: Windows 10 KB5072653 OOB update fixes ESU install errors
Microsoft: Windows 10 KB5072653 OOB update fixes ESU install errors Microsoft has released an emergency Windows 10 KB5072653 out-of-band update to resolve ongoing issues with installing the November extended security updates. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious NPM packages abuse Adspect redirects to evade security
Malicious NPM packages abuse Adspect redirects to evade security Seven packages published on the Node Package Manager (npm) registry use the Adspect cloud-based service to separate researchers from potential victims and lead them to malicious locations. […] Bill Toulas Go to bleepingcomputer
-
RondoDox botnet malware now hacks servers using XWiki flaw
RondoDox botnet malware now hacks servers using XWiki flaw The RondoDox botnet malware is now exploiting a critical remote code execution (RCE) flaw in XWiki Platform tracked as CVE-2025-24893. […] Bill Toulas Go to bleepingcomputer
-
Google to flag Android apps with excessive battery use on the Play Store
Google to flag Android apps with excessive battery use on the Play Store Google will start taking action on Android apps in the official Google Play store that have high background activity and cause excessive battery draining. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Windows 10 KB5068781 ESU update may fail with 0x800f0922 errors
Microsoft: Windows 10 KB5068781 ESU update may fail with 0x800f0922 errors Microsoft has confirmed it is investigating a bug causing the Windows 10 KB5068781 extended security update to fail to install with 0x800f0922 errors on devices with corporate licensing. […] Lawrence Abrams Go to bleepingcomputer
-
Decades-old ‘Finger’ protocol abused in ClickFix malware attacks
Decades-old ‘Finger’ protocol abused in ClickFix malware attacks The decades-old “finger” command is making a comeback,, with threat actors using the protocol to retrieve remote commands to execute on Windows devices. […] Lawrence Abrams Go to bleepingcomputer
-
Jaguar Land Rover cyberattack cost the company over $220 million
Jaguar Land Rover cyberattack cost the company over $220 million Jaguar Land Rover (JLR) published its financial results for July 1 to September 30, warning that the cost of a recent cyberattack totaled £196 million ($220 million) in the quarter. […] Bill Toulas Go to bleepingcomputer
-
Logitech confirms data breach after Clop extortion attack
Logitech confirms data breach after Clop extortion attack Hardware accessory giant Logitech has confirmed it suffered a data breach in a cyberattack claimed by the Clop extortion gang, which conducted Oracle E-Business Suite data theft attacks in July. […] Lawrence Abrams Go to bleepingcomputer
-
Five plead guilty to helping North Koreans infiltrate US firms
Five plead guilty to helping North Koreans infiltrate US firms The U.S. Department of Justice announced that five individuals pleaded guilty to aiding North Korea’s illicit revenue generation schemes, including remote IT worker fraud and cryptocurrency theft. […] Bill Toulas Go to bleepingcomputer
-
Anthropic claims of Claude AI-automated cyberattacks met with doubt
Anthropic claims of Claude AI-automated cyberattacks met with doubt Anthropic reports that a Chinese state-sponsored threat group, tracked as GTG-1002, carried out a cyber-espionage operation that was largely automated through the abuse of the company’s Claude Code AI model. […] Bill Toulas Go to bleepingcomputer
-
Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks Fortinet has silently patched a critical zero-day vulnerability in its FortiWeb web application firewall, which is now being widely exploited. […] Sergiu Gatlan Go to bleepingcomputer
-
Checkout.com snubs hackers after data breach, to donate ransom instead
Checkout.com snubs hackers after data breach, to donate ransom instead UK financial technology company Checkout announced that the ShinyHunters threat group has breached one of its legacy cloud storage systems and is now extorting the company for a ransom. […] Bill Toulas Go to bleepingcomputer
-
ASUS warns of critical auth bypass flaw in DSL series routers
ASUS warns of critical auth bypass flaw in DSL series routers ASUS has released new firmware to patch a critical authentication bypass security flaw impacting several DSL series router models. […] Sergiu Gatlan Go to bleepingcomputer
-
DoorDash hit by new data breach in October exposing user information
DoorDash hit by new data breach in October exposing user information DoorDash has disclosed a data breach that hit the food delivery platform this October. Beginning yesterday evening, DoorDash, which serves millions of customers across the U.S., Canada, Australia, and New Zealand, started emailing those impacted by the newly discovered security incident. […] Ax Sharma Go to bleepingcomputer
-
Fortinet FortiWeb flaw with public PoC exploited to create admin users
Fortinet FortiWeb flaw with public PoC exploited to create admin users A Fortinet FortiWeb path traversal vulnerability is being actively exploited to create new administrative users on exposed devices without requiring authentication […] Lawrence Abrams Go to bleepingcomputer
-
Kraken ransomware benchmarks systems for optimal encryption choice
Kraken ransomware benchmarks systems for optimal encryption choice The Kraken ransomware, which targets Windows, Linux/VMware ESXi systems, is testing machines to check how fast it can encrypt data without overloading them. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs
CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs US government agencies are warning that the Akira ransomware operation has been spotted encrypting Nutanix AHV virtual machines in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Google sues to dismantle Chinese phishing platform behind US toll scams
Google sues to dismantle Chinese phishing platform behind US toll scams Google has filed a lawsuit to dismantle the “Lighthouse” phishing-as-a-service platform used by cybercriminals worldwide to steal credit card information through SMS phishing attacks impersonating the U.S. Postal Service and E-ZPass toll systems. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 now supports 3rd-party apps for native passkey management
Windows 11 now supports 3rd-party apps for native passkey management Microsoft announced that passwordless authentication is now easier on Windows 11 through native support for third-party passkey managers, the first ones supported being 1Password and Bitwarden. […] Bill Toulas Go to bleepingcomputer
-
DanaBot malware is back to infecting Windows after 6-month break
DanaBot malware is back to infecting Windows after 6-month break The DanaBot malware has returned with a new version observed in attacks, six-months after law enforcement’s Operation Endgame disrupted its activity in May. […] Bill Toulas Go to bleepingcomputer
-
Extending Zero Trust to AI Agents: “Never Trust, Always Verify” Goes Autonomous
Extending Zero Trust to AI Agents: “Never Trust, Always Verify” Goes Autonomous As AI agents gain autonomy to act, decide, and access data, traditional Zero Trust models fall short. Token Security explains how to extend “never trust, always verify” to agentic AI with scoped access, continuous monitoring, and human accountability. […] Sponsored by Token Security…
-
Rhadamanthys infostealer disrupted as cybercriminals lose server access
Rhadamanthys infostealer disrupted as cybercriminals lose server access The Rhadamanthys infostealer operation has been disrupted, with numerous “customers” of the malware-as-a-service reporting that they no longer have access to their servers. […] Lawrence Abrams Go to bleepingcomputer
-
Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland Synology has addressed a critical-severity remote code execution (RCE) vulnerability in BeeStation products that was demonstrated at the recent Pwn2Own hacking competition. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Triofox antivirus feature to deploy remote access tools
Hackers abuse Triofox antivirus feature to deploy remote access tools Hackers exploited a critical vulnerability and the built-in antivirus feature in Gladinet’s Triofox file-sharing and remote-access platform to achieve remote code execution with SYSTEM privileges. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases KB5068781 — The first Windows 10 extended security update
Microsoft releases KB5068781 — The first Windows 10 extended security update Microsoft has released the KB5068781 update, the first Windows 10 extended security update since the operating system reached end of support last month. […] Lawrence Abrams Go to bleepingcomputer
-
APT37 hackers abuse Google Find Hub in Android data-wiping attacks
APT37 hackers abuse Google Find Hub in Android data-wiping attacks North Korean hackers from the KONNI activity cluster are abusing Google’s Find Hub tool to track their targets’ GPS positions and trigger remote factory resets of Android devices. […] Bill Toulas Go to bleepingcomputer
-
Mozilla Firefox gets new anti-fingerprinting defenses
Mozilla Firefox gets new anti-fingerprinting defenses Mozilla announced a major privacy upgrade in Firefox 145 that reduces even more the number of users vulnerable to digital fingerprinting. […] Bill Toulas Go to bleepingcomputer
-
Quantum Route Redirect PhaaS targets Microsoft 365 users worldwide
Quantum Route Redirect PhaaS targets Microsoft 365 users worldwide A new phishing automation platform named Quantum Route Redirect is using around 1,000 domains to steal Microsoft 365 users’ credentials. […] Bill Toulas Go to bleepingcomputer