Tag: bleepingcomputer
-
Microsoft fixes Media Creation Tool broken on some Windows PCs
Microsoft fixes Media Creation Tool broken on some Windows PCs Microsoft has confirmed that the Windows 11 Media Creation Tool (MCT) is working again on Windows 10 22H2 and Windows 11 25H2 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: DNS outage impacts Azure and Microsoft 365 services
Microsoft: DNS outage impacts Azure and Microsoft 365 services Microsoft is suffering an ongoing DNS outage affecting customers worldwide, preventing them from logging into company networks and accessing Microsoft Azure and Microsoft 365 services. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5067036 update rolls out Administrator Protection feature
Windows 11 KB5067036 update rolls out Administrator Protection feature Microsoft has released the KB5067036 preview cumulative update for Windows 11 24H2 and 25H2, which begins the rollout of the Administrator Protection cybersecurity feature and an updated Start Menu. […] Lawrence Abrams Go to bleepingcomputer
-
Python rejects $1.5M grant from U.S. govt. fearing ethical compromise
Python rejects $1.5M grant from U.S. govt. fearing ethical compromise The Python Software Foundation (PSF) has withdrawn its $1.5 million grant proposal to the U.S. National Science Foundation (NSF) due to funding terms forcing a compromise on its commitment to diversity, equity, and inclusion.. […] Bill Toulas Go to bleepingcomputer
-
Advertising giant Dentsu reports data breach at subsidiary Merkle
Advertising giant Dentsu reports data breach at subsidiary Merkle Japanese advertising giant Dentsu has disclosed that its U.S.-based subsidiary Merkle suffered a cybersecurity incident that exposed staff and client data. […] Bill Toulas Go to bleepingcomputer
-
CISA warns of two more actively exploited Dassault vulnerabilities
CISA warns of two more actively exploited Dassault vulnerabilities The Cybersecurity & Infrastructure Security Agency (CISA) warned today that attackers are actively exploiting two vulnerabilities in Dassault Systèmes’ DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution. […] Sergiu Gatlan Go to bleepingcomputer
-
Qilin ransomware abuses WSL to run Linux encryptors in Windows
Qilin ransomware abuses WSL to run Linux encryptors in Windows The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools. […] Lawrence Abrams Go to bleepingcomputer
-
Google disputes false claims of massive Gmail data breach
Google disputes false claims of massive Gmail data breach Google was once again forced to announce that it had not suffered a data breach after numerous news outlets published sensational stories about a fake breach that purportedly exposed 183 million accounts. […] Lawrence Abrams Go to bleepingcomputer
-
X: Re-enroll 2FA security keys by November 10 or get locked out
X: Re-enroll 2FA security keys by November 10 or get locked out X is warning that users must re-enroll their security keys or passkeys for two-factor authentication (2FA) before November 10 or they will be locked out of their accounts until they do so. […] Lawrence Abrams Go to bleepingcomputer
-
Ransomware profits drop as victims stop paying hackers
Ransomware profits drop as victims stop paying hackers The number of victims paying ransomware threat actors has reached a new low, with just 23% of the breached companies giving in to attackers’ demands. […] Bill Toulas Go to bleepingcomputer
-
Windows will soon prompt for memory scans after BSOD crashes
Windows will soon prompt for memory scans after BSOD crashes Microsoft has started testing a new feature that prompts Windows 11 users to run a memory scan when logging in after a blue screen of death (BSOD). […] Sergiu Gatlan Go to bleepingcomputer
-
QNAP warns of critical ASP.NET flaw in its Windows backup software
QNAP warns of critical ASP.NET flaw in its Windows backup software QNAP warned customers to patch a critical ASP.NET Core vulnerability that also impacts the company’s NetBak PC Agent, a Windows utility for backing& up data to a QNAP network-attached storage (NAS) device. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers steal Discord accounts with RedTiger-based infostealer
Hackers steal Discord accounts with RedTiger-based infostealer Attackers are using the open-source red-team tool RedTiger to build an infostealer that collects Discord account data and payment information. […] Bill Toulas Go to bleepingcomputer
-
New CoPhish attack steals OAuth tokens via Copilot Studio agents
New CoPhish attack steals OAuth tokens via Copilot Studio agents A new phishing technique dubbed ‘CoPhish’ weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains. […] Bill Toulas Go to bleepingcomputer
-
Hackers launch mass attacks exploiting outdated WordPress plugins
Hackers launch mass attacks exploiting outdated WordPress plugins A widespread exploitation campaign is targeting WordPress websites with GutenKit and Hunk Companion plugins vulnerable to critical-severity, old security issues that can be used to achieve remote code execution (RCE). […] Bill Toulas Go to bleepingcomputer
-
Critical WSUS flaw in Windows Server now exploited in attacks
Critical WSUS flaw in Windows Server now exploited in attacks Attackers are now exploiting a critical-severity Windows Server Update Service (WSUS) vulnerability, which already has publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Amazon: This week’s AWS outage caused by major DNS failure
Amazon: This week’s AWS outage caused by major DNS failure Amazon says a major DNS failure was behind a massive AWS (Amazon Web Services) outage that took down many websites and online services on Monday. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake LastPass death claims used to breach password vaults
Fake LastPass death claims used to breach password vaults LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process. […] Bill Toulas Go to bleepingcomputer
-
How to reduce costs with self-service password resets
How to reduce costs with self-service password resets Password resets account for nearly 40% of IT help desk calls, costing orgs time and money. Specops Software’s uReset lets users securely reset passwords with flexible MFA options like Duo, Okta, and Yubikey while enforcing identity verification to stop misuse. […] Sponsored by Specops Software Go to…
-
Windows Server emergency patches fix WSUS bug with PoC exploit
Windows Server emergency patches fix WSUS bug with PoC exploit Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities. […] Sergiu Gatlan Go to bleepingcomputer
-
Toys “R” Us Canada warns customers’ info leaked in data breach
Toys “R” Us Canada warns customers’ info leaked in data breach Toys “R” Us Canada has sent notices of a data breach to customers informing them of a security incident where threat actors leaked customer records they had previously stolen from its systems. […] Bill Toulas Go to bleepingcomputer
-
HP pulls update that broke Microsoft Entra ID auth on some AI PCs
HP pulls update that broke Microsoft Entra ID auth on some AI PCs HP has pulled an HP OneAgent software update for Windows 11 that mistakenly deleted Microsoft certificates required for some organizations to log in to Microsoft Entra ID, effectively disconnecting them from their company’s cloud environments. […] Lawrence Abrams Go to bleepingcomputer
-
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar Today, Microsoft introduced Mico, a new and more personal avatar for the AI-powered Copilot digital assistant, which the company describes as human-centered. […] Sergiu Gatlan Go to bleepingcomputer
-
Iranian hackers targeted over 100 govt orgs with Phoenix backdoor
Iranian hackers targeted over 100 govt orgs with Phoenix backdoor State-sponsored Iranian hacker group MuddyWater has targeted more than 100 government entities in attacks that deployed version 4 of the Phoenix backdoor. […] Bill Toulas Go to bleepingcomputer
-
Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000
Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000 Security researchers collected $792,750 in cash after exploiting 56 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploiting critical “SessionReaper” flaw in Adobe Magento
Hackers exploiting critical “SessionReaper” flaw in Adobe Magento Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. […] Bill Toulas Go to bleepingcomputer
-
TARmageddon flaw in abandoned Rust library enables RCE attacks
TARmageddon flaw in abandoned Rust library enables RCE attacks A high-severity vulnerability in the now-abandoned async-tar Rust library and its forks can be exploited to gain remote code execution on systems running unpatched software. […] Sergiu Gatlan Go to bleepingcomputer
-
Meta launches new anti-scam tools for WhatsApp and Messenger
Meta launches new anti-scam tools for WhatsApp and Messenger Meta has announced new tools to help WhatsApp and Messenger users protect themselves from potential scams and secure their accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Vidar Stealer 2.0 adds multi-threaded data theft, better evasion
Vidar Stealer 2.0 adds multi-threaded data theft, better evasion The operators of Vidar Stealer, one of the most successful malware-as-a-service (MaaS) operations of the past decade, have released a new major version to reflect massive improvements in the malware. […] Bill Toulas Go to bleepingcomputer
-
TP-Link warns of critical command injection flaw in Omada gateways
TP-Link warns of critical command injection flaw in Omada gateways TP-Link has made firmware updates available for a broad range of Omada gateway models to address four vulnerabilities, among which a critical pre-auth OS command injection. […] Bill Toulas Go to bleepingcomputer
-
CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw
CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw CISA has confirmed that an Oracle E-Business Suite flaw tracked as CVE-2025-61884 is being exploited in attacks, adding it to its Known Exploited Vulnerabilities catalog. […] Lawrence Abrams Go to bleepingcomputer
-
Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities The latest releases of Cursor and Windsurf integrated development environments are vulnerable to more than 94 known and patched security issues in the Chromium browser and the V8 JavaScript engine. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit 34 zero-days on first day of Pwn2Own Ireland
Hackers exploit 34 zero-days on first day of Pwn2Own Ireland On the first day of Pwn2Own Ireland 2025, security researchers exploited 34 unique zero-days and collected $522,500 in cash awards. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5070773 emergency update fixes Windows Recovery issues
Windows 11 KB5070773 emergency update fixes Windows Recovery issues Microsoft has released an emergency update to fix the Windows Recovery Environment (WinRE), which became unusable on systems with USB mice and keyboards after installing the October 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: October updates break USB input in Windows Recovery
Microsoft: October updates break USB input in Windows Recovery Microsoft has confirmed that this month’s security updates disable USB mice and keyboards in the Windows Recovery Environment (WinRE), making it unusable. […] Sergiu Gatlan Go to bleepingcomputer
-
DNS0.EU private DNS service shuts down over sustainability issues
DNS0.EU private DNS service shuts down over sustainability issues The DNS0.EU non-profit public DNS service focused on European users announced its immediate shut down due to time and resource constraints. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Muji halts online sales after ransomware attack on supplier
Retail giant Muji halts online sales after ransomware attack on supplier Japanese retail company Muji has taken offline its store due to a logistics outage caused by a ransomware attack at its delivery partner, Askul. […] Bill Toulas Go to bleepingcomputer
-
Over 75,000 WatchGuard security devices vulnerable to critical RCE
Over 75,000 WatchGuard security devices vulnerable to critical RCE Nearly 76,000 WatchGuard Firebox network security appliances are exposed on the public web and still vulnerable to a critical issue (CVE-2025-9242) that could allow a remote attacker to execute code without authentication. […] Bill Toulas Go to bleepingcomputer
-
CISA: High-severity Windows SMB flaw now exploited in attacks
CISA: High-severity Windows SMB flaw now exploited in attacks CISA says threat actors are now actively exploiting a high-severity Windows SMB privilege escalation vulnerability that can let them gain SYSTEM privileges on unpatched systems. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI confirms GPT-6 is not shipping in 2025
OpenAI confirms GPT-6 is not shipping in 2025 OpenAI is not planning to ship GPT-6 this year, but that doesn’t necessarily mean the company will not release new models. […] Mayank Parmar Go to bleepingcomputer
-
Google ads for fake Homebrew, LogMeIn sites push infostealers
Google ads for fake Homebrew, LogMeIn sites push infostealers A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey. […] Bill Toulas Go to bleepingcomputer
-
ConnectWise fixes Automate bug allowing AiTM update attacks
ConnectWise fixes Automate bug allowing AiTM update attacks ConnectWise released a security update to address vulnerabilities, one of them with critical severity, in Automate product that could expose sensitive communications to interception and modification. […] Bill Toulas Go to bleepingcomputer
-
American Airlines subsidiary Envoy confirms Oracle data theft attack
American Airlines subsidiary Envoy confirms Oracle data theft attack Envoy Air, a regional airline carrier owned by American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft lifts more safeguard holds blocking Windows 11 updates
Microsoft lifts more safeguard holds blocking Windows 11 updates Microsoft has removed two more compatibility holds preventing customers from installing Windows 11 24H2 via Windows Update. […] Sergiu Gatlan Go to bleepingcomputer
-
Europol dismantles SIM box operation renting numbers for cybercrime
Europol dismantles SIM box operation renting numbers for cybercrime European law enforcement in an operation codenamed ‘SIMCARTEL’ has dismantled an illegal SIM-box service that enabled more than 3,200 fraud cases and caused at least 4.5 million euros in losses. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes highest-severity ASP.NET Core flaw ever
Microsoft fixes highest-severity ASP.NET Core flaw ever Earlier this week, Microsoft patched a vulnerability that was flagged with the “highest ever” severity rating received by an ASP.NET Core security flaw. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections Microsoft’s October Windows 11 updates have broken the “localhost” functionality, making applications that connect back to 127.0.0.1 over HTTP/2 no longer function properly. […] Lawrence Abrams Go to bleepingcomputer
-
Auction giant Sotheby’s says data breach exposed financial information
Auction giant Sotheby’s says data breach exposed financial information Major international auction house Sotheby’s is notifying individuals of a data breach incident on its systems where threat actors stole sensitive information, including financial details. […] Bill Toulas Go to bleepingcomputer
-
Have I Been Pwned: Prosper data breach impacts 17.6 million accounts
Have I Been Pwned: Prosper data breach impacts 17.6 million accounts Hackers stole the personal information of over 17.6 million people after breaching the systems of financial services company Prosper. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in older, unprotected Cisco networking devices to deploy a Linux rootkit and gain persistent access. […] Bill Toulas Go to bleepingcomputer
-
Microsoft disrupts ransomware attacks targeting Teams users
Microsoft disrupts ransomware attacks targeting Teams users Microsoft has disrupted a wave of Rhysida ransomware attacks in early October by revoking over 200 certificates used to sign malicious Teams installers. […] Sergiu Gatlan Go to bleepingcomputer
-
YouTube is down worldwide with playback error
YouTube is down worldwide with playback error YouTube is currently facing a global outage, with users reporting playback errors on both the website and mobile apps. […] Mayank Parmar Go to bleepingcomputer
-
Capita to pay £14 million for data breach impacting 6.6 million people
Capita to pay £14 million for data breach impacting 6.6 million people The Information Commissioner’s Office (ICO) in the UK has fined Capita, a provider of data-driven business process services, £14 million ($18.7 million) for a data breach incident in 2023 that exposed the personal information of 6.6 million people. […] Bill Toulas Go to bleepingcomputer
-
PowerSchool hacker gets sentenced to four years in prison
PowerSchool hacker gets sentenced to four years in prison 19-year-old college student Matthew D. Lane, from Worcester, Massachusetts, was sentenced to 4 years in prison for orchestrating a cyberattack on PowerSchool in December 2024 that resulted in a massive data breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake LastPass, Bitwarden breach alerts lead to PC hijacks
Fake LastPass, Bitwarden breach alerts lead to PC hijacks An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake emails claiming that the companies were hacked, urging them to download a supposedly more secure desktop version of the password manager. […] Bill Toulas Go to bleepingcomputer
-
F5 releases BIG-IP patches for stolen security vulnerabilities
F5 releases BIG-IP patches for stolen security vulnerabilities Cybersecurity company F5 has released security updates to address BIG-IP vulnerabilities stolen in a breach detected on August 9, 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious crypto-stealing VSCode extensions resurface on OpenVSX
Malicious crypto-stealing VSCode extensions resurface on OpenVSX A threat actor called TigerJack is constantly targeting developers with malicious extensions published on Microsoft’s Visual Code (VSCode) marketplace and OpenVSX registry to steal cryptocurrency and plant backdoors. […] Bill Toulas Go to bleepingcomputer
-
Final Windows 10 Patch Tuesday update rolls out as support ends
Final Windows 10 Patch Tuesday update rolls out as support ends In what marks the end of an era, Microsoft has released the Windows 10 KB5066791 cumulative update, the final free update for the operating system as it reaches the end of its support lifecycle. […] Lawrence Abrams Go to bleepingcomputer
-
New Android Pixnapping attack steals MFA codes pixel-by-pixel
New Android Pixnapping attack steals MFA codes pixel-by-pixel A new side-channel attack called Pixnapping enables a malicious Android app with no permissions to extract sensitive data by stealing pixels displayed by applications or websites, and reconstructing them to derive the content. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Exchange 2016 and 2019 have reached end of support
Microsoft: Exchange 2016 and 2019 have reached end of support Microsoft has reminded that Exchange Server 2016 and 2019 reached the end of support and advised IT administrators to upgrade servers to Exchange Server SE or migrate to Exchange Online. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws Today is Microsoft’s October 2025 Patch Tuesday, which includes security updates for 172 flaws, including six zero-day vulnerabilities. Get patching! […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft restricts IE mode access in Edge after zero-day attacks
Microsoft restricts IE mode access in Edge after zero-day attacks Microsoft is restricting access to Internet Explorer mode in Edge browser after learning that hackers are leveraging zero-day exploits in the Chakra JavaScript engine for access to target devices. […] Bill Toulas Go to bleepingcomputer
-
SimonMed says 1.2 million patients impacted in January data breach
SimonMed says 1.2 million patients impacted in January data breach U.S. medical imaging provider SimonMed Imaging is notifying more than 1.2 million individuals of a data breach that exposed their sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Massive multi-country botnet targets RDP services in the US
Massive multi-country botnet targets RDP services in the US A large-scale botnet is targeting Remote Desktop Protocol (RDP) services in the United States from more than 100,000 IP addresses. […] Bill Toulas Go to bleepingcomputer
-
SonicWall VPN accounts breached using stolen creds in widespread attacks
SonicWall VPN accounts breached using stolen creds in widespread attacks Researchers warn that threat actors have compromised more than a hundred SonicWall SSLVPN accounts in a large-scale campaign using stolen, valid credentials. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates outage affecting Microsoft 365 apps
Microsoft investigates outage affecting Microsoft 365 apps Microsoft is investigating an ongoing incident that is preventing some customers from accessing Microsoft 365 applications. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake ‘Inflation Refund’ texts target New Yorkers in new scam
Fake ‘Inflation Refund’ texts target New Yorkers in new scam An ongoing smishing campaign is targeting New Yorkers with text messages posing as the Department of Taxation and Finance, claiming to offer “Inflation Refunds” in an attempt to steal victims’ personal and financial data. […] Lawrence Abrams Go to bleepingcomputer
-
Spain dismantles “GXC Team” cybercrime syndicate, arrests leader
Spain dismantles “GXC Team” cybercrime syndicate, arrests leader Spanish Guardia Civil have dismantled the “GXC Team” cybercrime syndicate and arrested its alleged leader, a 25-year-old Brazilian known as “GoogleXcoder.” […] Bill Toulas Go to bleepingcomputer
-
Windows 11 23H2 Home and Pro reach end of support in 30 days
Windows 11 23H2 Home and Pro reach end of support in 30 days Microsoft has reminded customers again today that systems running Home and Pro editions of Windows 11 23H2 will stop receiving security updates next month. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploiting zero-day in Gladinet file sharing software
Hackers exploiting zero-day in Gladinet file sharing software Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication. […] Bill Toulas Go to bleepingcomputer
-
Cybersecurity For Dummies, 3rd Edition eBook FREE for a Limited Time
Cybersecurity For Dummies, 3rd Edition eBook FREE for a Limited Time In today’s hyper-connected world, cyber threats are more sophisticated and frequent than ever – ransomware, data breaches, and social engineering scams, targeting everyone from individuals to Fortune 500 companies. Right now, you can grab “Cybersecurity For Dummies, 3rd Edition” – a $29.99 value –…
-
Google Chrome to revoke notification access for inactive sites
Google Chrome to revoke notification access for inactive sites Google is updating the Chrome web browser to automatically revoke notification permissions for websites that haven’t been visited recently, to reduce alert overload. […] Sergiu Gatlan Go to bleepingcomputer
-
Apple now offers $2 million for zero-click RCE vulnerabilities
Apple now offers $2 million for zero-click RCE vulnerabilities Apple is announcing a major expansion and redesign of its bug bounty program, doubling maximum payouts, adding new research categories, and introducing a more transparent reward structure. […] Bill Toulas Go to bleepingcomputer
-
FBI takes down BreachForums portal used for Salesforce extortion
FBI takes down BreachForums portal used for Salesforce extortion The FBI has seized last night all domains for the BreachForums hacking forum operated by the ShinyHunters group mostly as a portal for leaking corporate data stolen in attacks from ransomware and extortion gangs. […] Bill Toulas Go to bleepingcomputer
-
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube
New Android spyware ClayRat imitates WhatsApp, TikTok, YouTube A new Android spyware called ClayRat is luring potential victims by posing as popular apps and services like WhatsApp, Google Photos, TikTok, and YouTube. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Hackers target universities in “payroll pirate” attacks
Microsoft: Hackers target universities in “payroll pirate” attacks A cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in “pirate payroll” attacks since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers now use Velociraptor DFIR tool in ransomware attacks
Hackers now use Velociraptor DFIR tool in ransomware attacks Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender mistakenly flags SQL Server as end-of-life
Microsoft Defender mistakenly flags SQL Server as end-of-life Microsoft is working to resolve a known issue that causes its Defender for Endpoint enterprise endpoint security platform to incorrectly tag SQL Server software as end-of-life. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers claim Discord breach exposed data of 5.5 million users
Hackers claim Discord breach exposed data of 5.5 million users Discord says they will not be negotiating with threat actors who claim to have stolen the data of 5.5 million unique users from the company’s Zendesk support system instance, including government IDs and partial payment information for some people. […] Lawrence Abrams Go to bleepingcomputer
-
New FileFix attack uses cache smuggling to evade security software
New FileFix attack uses cache smuggling to evade security software A new variant of the FileFix social engineering attack uses cache smuggling to secretly download a malicious ZIP archive onto a victim’s system and bypassing security software. […] Lawrence Abrams Go to bleepingcomputer
-
Qilin ransomware claims Asahi brewery attack, leaks data
Qilin ransomware claims Asahi brewery attack, leaks data The Qilin ransomware group has claimed responsibility for the attack at Japanese beer maker Asahi, adding the company to its extortion page on the dark web yesterday. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 outage blocks access to Teams, Exchange Online
Microsoft 365 outage blocks access to Teams, Exchange Online Microsoft is working to resolve an ongoing outage preventing users from accessing Microsoft 365 services, including Microsoft Teams, Exchange Online, and the admin center. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft enables Exchange Online auto-archiving by default
Microsoft enables Exchange Online auto-archiving by default Microsoft is enabling threshold-based auto-archiving by default in Exchange Online to prevent email flow issues caused by mailboxes filling up faster than expected. […] Sergiu Gatlan Go to bleepingcomputer
-
Salesforce refuses to pay ransom over widespread data theft attacks
Salesforce refuses to pay ransom over widespread data theft attacks Salesforce has confirmed that it will not negotiate with or pay a ransom to the threat actors behind a massive wave of data theft attacks that impacted the company’s customers this year. […] Lawrence Abrams Go to bleepingcomputer
-
Docker makes Hardened Images Catalog affordable for small businesses
Docker makes Hardened Images Catalog affordable for small businesses The Docker team has announced unlimited access to its Hardened Images catalog to make access to secure software bundles affordable for all development teams at startups and SMBs. […] Bill Toulas Go to bleepingcomputer
-
Google won’t fix new ASCII smuggling attack in Gemini
Google won’t fix new ASCII smuggling attack in Gemini Google has decided not to fix a new ASCII smuggling attack in Gemini that could be used to trick the AI assistant into providing users with fake information, alter the model’s behavior, and silently poison its data. […] Bill Toulas Go to bleepingcomputer
-
DraftKings warns of account breaches in credential stuffing attacks
DraftKings warns of account breaches in credential stuffing attacks Sports betting giant DraftKings has notified an undisclosed number of customers that their accounts had been hacked in a recent wave of credential stuffing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Clop exploited Oracle zero-day for data theft since early August
Clop exploited Oracle zero-day for data theft since early August The Clop ransomware gang has been exploiting a critical Oracle E-Business Suite (EBS) zero-day bug in data theft attacks since at least early August, according to cybersecurity company CrowdStrike. […] Sergiu Gatlan Go to bleepingcomputer
-
Red Hat data breach escalates as ShinyHunters joins extortion
Red Hat data breach escalates as ShinyHunters joins extortion Enterprise software giant Red Hat is now being extorted by the ShinyHunters gang, with samples of stolen customer engagement reports (CERs) leaked on their data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: Critical GoAnywhere bug exploited in ransomware attacks
Microsoft: Critical GoAnywhere bug exploited in ransomware attacks A cybercrime group, tracked as Storm-1175, has been actively exploiting a maximum severity GoAnywhere MFT vulnerability in Medusa ransomware attacks for nearly a month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Running multiple Office apps causes Copilot issues
Microsoft: Running multiple Office apps causes Copilot issues Microsoft is investigating a bug that causes Copilot issues when multiple Office apps are running simultaneously on the same system. […] Sergiu Gatlan Go to bleepingcomputer
-
Zeroday Cloud hacking contest offers $4.5 million in bounties
Zeroday Cloud hacking contest offers $4.5 million in bounties A new hacking competition called Zeroday Cloud, focused on open-source cloud and AI tools, announced a total prize pool of $4.5 million in bug bounties for researchers that submit exploits for various targets. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT Pulse is coming to the web, but no word on free or Plus roll out
ChatGPT Pulse is coming to the web, but no word on free or Plus roll out OpenAI’s ChatGPT Pulse, which is a tool that gives you personalised updates based on usage patterns, is coming to the web. […] Mayank Parmar Go to bleepingcomputer
-
Oracle patches EBS zero-day exploited in Clop data theft attacks
Oracle patches EBS zero-day exploited in Clop data theft attacks Oracle is warning about a critical E-Business Suite zero-day vulnerability tracked as CVE-2025-61882 that allows attackers to perform unauthenticated remote code execution, with the flaw actively exploited in Clop data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
ParkMobile pays… $1 each for 2021 data breach that hit 22 million
ParkMobile pays… $1 each for 2021 data breach that hit 22 million ParkMobile has finally wrapped up a class action lawsuit over the platform’s 2021 data breach that hit 22 million users. But there’s a catch: victims are receiving compensation in the form of a $1 in-app credit, which they must claim manually. And, it…
-
Hackers exploited Zimbra flaw as zero-day using iCalendar files
Hackers exploited Zimbra flaw as zero-day using iCalendar files Researchers monitoring for larger .ICS calendar attachments found that a flaw in Zimbra Collaboration Suite (ZCS) was used in zero-day attacks at the beginning of the year. […] Bill Toulas Go to bleepingcomputer
-
Leaked Apple iPad Pro M5 benchmark shows massive improvements
Leaked Apple iPad Pro M5 benchmark shows massive improvements A new leaked benchmark shows Apple’s alleged M5 chip on an iPad, and it’s almost as fast as a desktop CPU. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT social could be a thing, as leak shows direct messages support
ChatGPT social could be a thing, as leak shows direct messages support OpenAI doesn’t want ChatGPT to remain just a chatbot for interacting with a large language model. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI rolls out GPT Codex Alpha with early access to new models
OpenAI rolls out GPT Codex Alpha with early access to new models OpenAI’s Codex is already making waves in the vibe coding vertical, and it’s now set to get even better. […] Mayank Parmar Go to bleepingcomputer