Tag: bleepingcomputer
-
Lovense sex toy app flaw leaks private user email addresses
Lovense sex toy app flaw leaks private user email addresses The connected sex toy platform Lovense is vulnerable to a zero-day flaw that allows an attacker to get access to a member’s email address simply by knowing their username, putting them at risk of doxxing and harassment. […] Lawrence Abrams Go to bleepingcomputer
-
Tea app leak worsens with second database exposing user chats
Tea app leak worsens with second database exposing user chats The Tea app data breach has grown into an even larger leak, with the stolen data now shared on hacking forums and a second database discovered that allegedly contains 1.1 million private messages exchanged between the app’s members. […] Lawrence Abrams Go to bleepingcomputer
-
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution A vulnerability in Google’s Gemini CLI allowed attackers to silently execute malicious commands and exfiltrate data from developers’ computers using allowlisted programs. […] Bill Toulas Go to bleepingcomputer
-
Endgame Gear mouse config tool infected users with malware
Endgame Gear mouse config tool infected users with malware Gaming peripherals maker Endgame Gear is warning that malware was hidden in its configuration tool for the OP1w 4k v2 mouse hosted on the official website between June 26 and July 9, 2025. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. […] Sergiu Gatlan Go to bleepingcomputer
-
Scattered Spider is running a VMware ESXi hacking spree
Scattered Spider is running a VMware ESXi hacking spree Scattered Spider hackers have been aggressively targeting virtualized environments by attacking VMware ESXi hypervisors at U.S. companies in the retail, airline, transportation, and insurance sectors. […] Bill Toulas Go to bleepingcomputer
-
Allianz Life confirms data breach impacts majority of 1.4 million customers
Allianz Life confirms data breach impacts majority of 1.4 million customers Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks
Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks More than 200,000 WordPress websites are using a vulnerable version of the Post SMTP plugin that allows hackers to take control of the administrator account. […] Bill Toulas Go to bleepingcomputer
-
Amazon AI coding agent hacked to inject data wiping commands
Amazon AI coding agent hacked to inject data wiping commands A hacker planted data wiping code in a version of Amazon’s generative AI-powered assistant, the Q Developer Extension for Visual Studio Code. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft investigates outage affecting Microsoft 365 admin center Microsoft is investigating an ongoing outage blocking Microsoft 365 administrators with business or enterprise subscriptions from accessing the admin center. […] Sergiu Gatlan Go to bleepingcomputer
-
The role of the cybersecurity PM in incident-driven development
The role of the cybersecurity PM in incident-driven development From PowerShell abuse to USB data theft, modern threats hit fast—and hard.vSee how security-minded PMs are responding with real-time controls, smarter policies, and tools like ThreatLocker Patch Management. […] Sponsored by ThreatLocker Go to bleepingcomputer
-
US sanctions North Korean firm, nationals behind IT worker schemes
US sanctions North Korean firm, nationals behind IT worker schemes The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned three North Korean nationals and a company for supporting fraudulent IT worker schemes that generated illicit revenue for the Democratic People’s Republic of Korea (DPRK) government. […] Bill Toulas Go to…
-
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms Christina Marie Chapman, a 50-year-old woman from Arizona, was sentenced to 102 months in prison after pleading guilty to her involvement in a scheme that enabled North Korean IT workers to infiltrate 309 U.S. companies. […] Sergiu Gatlan Go to bleepingcomputer
-
BlackSuit ransomware extortion sites seized in Operation Checkmate
BlackSuit ransomware extortion sites seized in Operation Checkmate Law enforcement has seized the dark web extortion sites of the BlackSuit ransomware operation, which has targeted and breached the networks of hundreds of organizations worldwide over the past several years. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI confirms ChatGPT Agent is now rolling out for $20 Plus users
OpenAI confirms ChatGPT Agent is now rolling out for $20 Plus users ChatGPT Agent is now rolling out to users with $20 Plus subscription, but OpenAI warns that it will take a few days for the rollout to finish. […] Mayank Parmar Go to bleepingcomputer
-
New Koske Linux malware hides in cute panda images
New Koske Linux malware hides in cute panda images A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory. […] Bill Toulas Go to bleepingcomputer
-
Hacker sneaks infostealer malware into early access Steam game
Hacker sneaks infostealer malware into early access Steam game A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title. […] Bill Toulas Go to bleepingcomputer
-
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw
Mitel warns of critical MiVoice MX-ONE authentication bypass flaw Mitel Networks has released security updates to patch a critical-severity authentication bypass vulnerability impacting its MiVoice MX-ONE enterprise communications platform. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: SharePoint servers also targeted in ransomware attacks
Microsoft: SharePoint servers also targeted in ransomware attacks A Chinese hacking group is deploying Warlock ransomware on Microsoft SharePoint servers vulnerable to widespread attacks targeting the recently patched ToolShell zero-day exploit chain. […] Sergiu Gatlan Go to bleepingcomputer
-
Brave blocks Windows Recall from screenshotting your browsing activity
Brave blocks Windows Recall from screenshotting your browsing activity Brave Software says its privacy-focused browser will block Microsoft’s Windows Recall from capturing screenshots of Brave windows by default to protect users’ privacy. […] Lawrence Abrams Go to bleepingcomputer
-
Proton launches privacy-respecting encrypted AI assistant Lumo
Proton launches privacy-respecting encrypted AI assistant Lumo Proton has launched a new tool called Lumo, offering a privacy-first AI assistant that does not log user conversations and doesn’t use their prompts for training. […] Bill Toulas Go to bleepingcomputer
-
Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit
Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit Clorox is suing IT giant Cognizant for gross negligence, alleging it enabled a massive August 2023 cyberattack by resetting an employee’s password for a hacker without first verifying their identity. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT is rolling out ‘personality’ toggles to become your assistant
ChatGPT is rolling out ‘personality’ toggles to become your assistant OpenAI is rolling out a new “personality” feature on the ChatGPT web app. This allows you to choose between multiple personalities, such as “Robot.” […] Mayank Parmar Go to bleepingcomputer
-
Lumma infostealer malware returns after law enforcement disruption
Lumma infostealer malware returns after law enforcement disruption The Lumma infostealer malware operation is gradually resuming activities following a massive law enforcement operation in May, which resulted in the seizure of 2,300 domains and parts of its infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Windows 11 KB5062660 update brings new ‘Windows Resilience’ features
Windows 11 KB5062660 update brings new ‘Windows Resilience’ features Microsoft has released the KB5062660 preview cumulative update for Windows 11 24H2 with twenty-nine new features or changes, with many gradually rolling out, such as the new Black Screen of Death and Quick Machine Recovery tool. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 gets new Black Screen of Death, auto recovery tool
Windows 11 gets new Black Screen of Death, auto recovery tool Microsoft is rolling out significant changes to Windows 11 24H2 as part of the Windows Resilience Initiative, designed to reduce downtime and help devices recover from serious failures, as well as an overhaul of the all-too-familiar BSOD crash screens. […] Lawrence Abrams Go to bleepingcomputer
-
Coyote malware abuses Windows accessibility framework for data theft
Coyote malware abuses Windows accessibility framework for data theft A new variant of the banking trojan ‘Coyote’ has begun abusing a Windows accessibility feature, Microsoft’s UI Automation framework, to identify which banking and cryptocurrency exchange sites are accessed on the device for potential credential theft. […] Bill Toulas Go to bleepingcomputer
-
CISA and FBI warn of escalating Interlock ransomware attacks
CISA and FBI warn of escalating Interlock ransomware attacks CISA and the FBI warned on Tuesday of increased Interlock ransomware activity targeting businesses and critical infrastructure organizations in double extortion attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Intel announces end of Clear Linux OS project, archives GitHub repos
Intel announces end of Clear Linux OS project, archives GitHub repos The Clear Linux OS team has announced the shutdown of the project, marking the end of its 10-year existence in the open-source ecosystem. […] Bill Toulas Go to bleepingcomputer
-
Ring denies breach after users report suspicious logins
Ring denies breach after users report suspicious logins Ring is warning that a backend update bug is responsible for customers seeing a surge in unauthorized devices logged into their account on May 28th. […] Bill Toulas Go to bleepingcomputer
-
ExpressVPN bug leaked user IPs in Remote Desktop sessions
ExpressVPN bug leaked user IPs in Remote Desktop sessions ExpressVPN has fixed a flaw in its Windows client that caused Remote Desktop Protocol (RDP) traffic to bypass the virtual private network (VPN) tunnel, exposing the users’ real IP addresses. […] Bill Toulas Go to bleepingcomputer
-
Veeam Recovery Orchestrator users locked out after MFA rollout
Veeam Recovery Orchestrator users locked out after MFA rollout Veeam warned customers today that a recently released Recovery Orchestrator version blocks Web UI logins after enabling multi-factor authentication (MFA). […] Sergiu Gatlan Go to bleepingcomputer
-
Dior begins sending data breach notifications to U.S. customers
Dior begins sending data breach notifications to U.S. customers The House of Dior (Dior) is sending data breach notifications to U.S. customers informing them that a May cybersecurity incident compromised their personal information. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available Critical zero-day vulnerabilities in Microsoft SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, have been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. […] Lawrence Abrams Go to bleepingcomputer
-
HPE warns of hardcoded passwords in Aruba access points
HPE warns of hardcoded passwords in Aruba access points Hewlett-Packard Enterprise (HPE) is warning of hardcoded credentials in Aruba Instant On Access Points that allow attackers to bypass normal device authentication and access the web interface. […] Bill Toulas Go to bleepingcomputer
-
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack
Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals. […] Lawrence Abrams Go to bleepingcomputer
-
Popular npm linter packages hijacked via phishing to drop malware
Popular npm linter packages hijacked via phishing to drop malware Popular JavaScript libraries eslint-config-prettier and eslint-plugin-prettier were hijacked this week and turned into malware droppers, in a supply chain attack achieved via targeted phishing and credential theft. […] Ax Sharma Go to bleepingcomputer
-
ChatGPT”s GPT-5-reasoning-alpha model spotted ahead of launch
ChatGPT”s GPT-5-reasoning-alpha model spotted ahead of launch GPT-5 might be just a few days or weeks away, as we’ve spotted references to a new model called gpt-5-reasoning-alpha-2025-07-13. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI, Anthropic, Google may disrupt education market with new AI tools
OpenAI, Anthropic, Google may disrupt education market with new AI tools AI companies could soon disrupt the education market with their new AI-based learning tools for students. […] Mayank Parmar Go to bleepingcomputer
-
New CrushFTP zero-day exploited in attacks to hijack servers
New CrushFTP zero-day exploited in attacks to hijack servers CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. […] Lawrence Abrams Go to bleepingcomputer
-
Arch Linux pulls AUR packages that installed Chaos RAT malware
Arch Linux pulls AUR packages that installed Chaos RAT malware Arch Linux has pulled three malicious packages uploaded to the Arch User Repository (AUR) were used to install the CHAOS remote access trojan (RAT) on Linux devices. […] Lawrence Abrams Go to bleepingcomputer
-
UK ties GRU to stealthy Microsoft 365 credential-stealing malware
UK ties GRU to stealthy Microsoft 365 credential-stealing malware The UK National Cyber Security Centre (NCSC) has formally attributed ‘Authentic Antics’ espionage malware attacks to APT28 (Fancy Bear), threat actor already linked to Russia’s military intelligence service (GRU). […] Bill Toulas Go to bleepingcomputer
-
Microsoft mistakenly tags Windows Firewall error log bug as fixed
Microsoft mistakenly tags Windows Firewall error log bug as fixed Microsoft has mistakenly tagged an ongoing Windows Firewall error message bug as fixed in recent updates, stating that they are still working on a resolution. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI: GPT-5 is coming, “we’ll see” if it creates a shockwave
OpenAI: GPT-5 is coming, “we’ll see” if it creates a shockwave OpenAI’s next foundational and state-of-the-art model, GPT-5, is still on its way after a delay. OpenAI won’t tell us the release date for now. […] Mayank Parmar Go to bleepingcomputer
-
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks A critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed “CitrixBleed 2,” was actively exploited nearly two weeks before proof-of-concept (PoC) exploits were made public, despite Citrix stating that there was no evidence of attacks. […] Lawrence Abrams Go to bleepingcomputer
-
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Teams voice calls abused to push Matanbuchus malware
Microsoft Teams voice calls abused to push Matanbuchus malware The Matanbuchus malware loader has been seen being distributed through social engineering over Microsoft Teams calls impersonating IT helpdesk. […] Bill Toulas Go to bleepingcomputer
-
Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices
Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices Google has filed a lawsuit against the anonymous operators of the Android BadBox 2.0 malware botnet, accusing them of running a global ad fraud scheme against the company’s advertising platforms. […] Lawrence Abrams Go to bleepingcomputer
-
Co-op confirms data of 6.5 million members stolen in cyberattack
Co-op confirms data of 6.5 million members stolen in cyberattack UK retailer Co-op has confirmed that personal data of 6.5 million members was stolen in the massive cyberattack in April that shut down systems and caused food shortages in its grocery stores. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. Army soldier pleads guilty to extorting 10 tech, telecom firms
U.S. Army soldier pleads guilty to extorting 10 tech, telecom firms A 21-year old former U.S. Army soldier pleaded guilty to charges of hacking and extorting at least ten telecommunications and technology companies in the country. […] Bill Toulas Go to bleepingcomputer
-
Louis Vuitton says regional data breaches tied to same cyberattack
Louis Vuitton says regional data breaches tied to same cyberattack Luxury fashion giant Louis Vuitton confirmed that breaches impacting customers in the UK, South Korea, and Turkey stem from the same security incident, which is believed to be linked to the ShinyHunters extortion group. […] Lawrence Abrams Go to bleepingcomputer
-
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack To quash speculation of a cyberattack or BGP hijack incident causing the recent 1.1.1.1 Resolver service outage, Cloudflare explains in a post mortem that the incident was caused by an internal misconfiguration. […] Bill Toulas Go to bleepingcomputer
-
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances. […] Ionut Ilascu Go to bleepingcomputer
-
Google fixes actively exploited sandbox escape zero day in Chrome
Google fixes actively exploited sandbox escape zero day in Chrome Google has released a security update for Chrome to address half a dozen vulnerabilities, one of them actively exploited by attackers to escape the browser’s sandbox protection. […] Bill Toulas Go to bleepingcomputer
-
OpenAI’s image model gets built-in style feature on ChatGPT
OpenAI’s image model gets built-in style feature on ChatGPT OpenAI’s image gen model, which is available via ChatGPT for free, now lets you easily create AI images even if you’re not familiar with trends or prompt engineering. […] Mayank Parmar Go to bleepingcomputer
-
Abacus dark web drug market goes offline in suspected exit scam
Abacus dark web drug market goes offline in suspected exit scam Abacus Market, the largest Western darknet marketplace supporting Bitcoin payments, has shut down its public infrastructure in a move suspected to be an exit scam. […] Bill Toulas Go to bleepingcomputer
-
Windows KB5064489 emergency update fixes Azure VM launch issues
Windows KB5064489 emergency update fixes Azure VM launch issues Microsoft has released an emergency update to fix a bug that prevents Azure virtual machines from launching when the Trusted Launch setting is disabled and Virtualization-Based Security (VBS) is enabled. […] Lawrence Abrams Go to bleepingcomputer
-
North Korean XORIndex malware hidden in 67 malicious npm packages
North Korean XORIndex malware hidden in 67 malicious npm packages North Korean threat actors planted 67 malicious packages in the Node Package Manager (npm) online repository to deliver a new malware loader called XORIndex to developer systems. […] Bill Toulas Go to bleepingcomputer
-
UK launches vulnerability research program for external experts
UK launches vulnerability research program for external experts UK’s National Cyber Security Centre (NCSC) has announced a new Vulnerability Research Initiative (VRI) that aims to strengthen relations with external cybersecurity experts. […] Bill Toulas Go to bleepingcomputer
-
Interlock ransomware adopts FileFix method to deliver malware
Interlock ransomware adopts FileFix method to deliver malware Hackers have adopted the new technique called ‘FileFix’ in Interlock ransomware attacks to drop a remote access trojan (RAT) on targeted systems. […] Bill Toulas Go to bleepingcomputer
-
Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot
Gigabyte motherboards vulnerable to UEFI malware bypassing Secure Boot Dozens of Gigabyte motherboard models run on UEFI firmware vulnerable to security issues that allow planting bootkit malware that is invisible to the operating system and can survive reinstalls. […] Bill Toulas Go to bleepingcomputer
-
Malicious VSCode extension in Cursor IDE led to $500K crypto theft
Malicious VSCode extension in Cursor IDE led to $500K crypto theft A fake extension for the Cursor AI IDE code editor infected devices with remote access tools and infostealers, which, in one case, led to the theft of $500,000 in cryptocurrency from a Russian crypto developer. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 10 KB5062554 update breaks emoji panel search feature
Windows 10 KB5062554 update breaks emoji panel search feature The search feature for the Windows 10 emoji panel is broken after installing the KB5062554 cumulative update released Tuesday, making it not possible to look up emojis by name or keyword. […] Lawrence Abrams Go to bleepingcomputer
-
Google Gemini flaw hijacks email summaries for phishing
Google Gemini flaw hijacks email summaries for phishing Google Gemini for Workspace can be exploited to generate email summaries that appear legitimate but include malicious instructions or warnings that direct users to phishing sites without using attachments or direct links. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting critical RCE flaw in Wing FTP Server
Hackers are exploiting critical RCE flaw in Wing FTP Server Hackers have started to exploit a critical remote code execution vulnerability in Wing FTP Server just one day after technical details on the flaw became public. […] Bill Toulas Go to bleepingcomputer
-
‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications
‘123456’ password exposed chats for 64 million McDonald’s job chatbot applications Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applications across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
‘123456’ password exposed chats for 64 million McDonald’s job applicants
‘123456’ password exposed chats for 64 million McDonald’s job applicants Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applicants across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now Proof-of-concept exploits have been released for a critical SQLi vulnerability in Fortinet FortiWeb that can be used to achieve pre-authenticated remote code execution on vulnerable servers. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress Gravity Forms developer hacked to push backdoored plugins
WordPress Gravity Forms developer hacked to push backdoored plugins The popular WordPress plugin Gravity Forms has been compromised in what seems a supply-chain attack where manual installers from the official website were infected with a backdoor. […] Bill Toulas Go to bleepingcomputer
-
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks NVIDIA is warning users to activate System Level Error-Correcting Code mitigation to protect against Rowhammer attacks on graphical processors with GDDR6 memory. […] Bill Toulas Go to bleepingcomputer
-
The zero-day that could’ve compromised every Cursor and Windsurf user
The zero-day that could’ve compromised every Cursor and Windsurf user Learn how one overlooked flaw in OpenVSX discovered by Koi Secureity could’ve let attackers hijack millions of dev machines via an extension supply chain attack. The zero-day threat’s been patched—but the wake-up call is clear: extensions are a new, massive supply chain risk. […] Sponsored…
-
Windows 11 now uses JScript9Legacy engine for improved security
Windows 11 now uses JScript9Legacy engine for improved security Microsoft announced that it has replaced the default scripting engine JScript with the newer and more secure JScript9Legacy on Windows 11 version 24H2 and later. […] Bill Toulas Go to bleepingcomputer
-
Russian pro basketball player arrested for alleged role in ransomware attacks
Russian pro basketball player arrested for alleged role in ransomware attacks Russian professional basketball player Daniil Kasatkin was arrested in France at the request of the United States for allegedly acting as a negotiator for a ransomware gang. […] Lawrence Abrams Go to bleepingcomputer
-
PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars
PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars Four vulnerabilities dubbed PerfektBlue and affecting the BlueSDK Bluetooth stack from OpenSynergy can be exploited to achieve remote code execution and potentially allow access to critical elements in vehicles from multiple vendors, including Mercedes-Benz AG, Volkswagen, and Skoda. […] Bill Toulas Go to bleepingcomputer
-
FBI’s CJIS demystified: Best practices for passwords, MFA & access control
FBI’s CJIS demystified: Best practices for passwords, MFA & access control FBI’s Criminal Justice Information Services (CJIS) compliance isn’t optional when handling law enforcement data. From MFA to password hygiene, see how Specops Software helps meet FBI standards while also securing your Windows Active Directory. […] Sponsored by Specops Software Go to bleepingcomputer
-
Four arrested in UK over M&S, Co-op, Harrods cyberattacks
Four arrested in UK over M&S, Co-op, Harrods cyberattacks The UK’s National Crime Agency (NCA) arrested four people suspected of being involved in cyberattacks on major retailers in the country, including Marks & Spencer, Co-op, and Harrods. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Authenticator on iOS moves backups fully to iCloud
Microsoft Authenticator on iOS moves backups fully to iCloud Microsoft is rolling out a new backup system in September for its Authenticator app on iOS, removing the requirement to use a Microsoft personal account to back up TOTP secrets and account names. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft confirms Windows Server Update Services (WSUS) sync is broken
Microsoft confirms Windows Server Update Services (WSUS) sync is broken Microsoft has confirmed a widespread issue in Windows Server Update Services (WSUS) that prevents organizations from syncing with Microsoft Update and deploying the latest Windows updates. […] Lawrence Abrams Go to bleepingcomputer
-
Qantas confirms data breach impacts 5.7 million customers
Qantas confirms data breach impacts 5.7 million customers Australian airline Qantas has confirmed that 5.7 million people have been impacted by a recent data breach, in which threat actors stole customers’ data. […] Lawrence Abrams Go to bleepingcomputer
-
Google reveals details on Android’s Advanced Protection for Chrome
Google reveals details on Android’s Advanced Protection for Chrome Google is sharing more information on how Chrome operates when Android mobile users enable Advanced Protection, highlighting strong security improvements. […] Bill Toulas Go to bleepingcomputer
-
Bitcoin Depot breach exposes data of nearly 27,000 crypto users
Bitcoin Depot breach exposes data of nearly 27,000 crypto users Bitcoin Depot, an operator of Bitcoin ATMs, is notifying customers of a data breach incident that has exposed their sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Samsung announces major security enhancements coming to One UI 8
Samsung announces major security enhancements coming to One UI 8 Samsung has announced multiple data security and privacy enhancements for its upcoming Galaxy smartphones running One UI 8, its custom user interface on top of Android. […] Bill Toulas Go to bleepingcomputer
-
M&S confirms social engineering led to massive ransomware attack
M&S confirms social engineering led to massive ransomware attack M&S confirmed today that the retail outlet’s network was initially breached in a “sophisticated impersonation attack” that ultimately led to a DragonForce ransomware attack. […] Lawrence Abrams Go to bleepingcomputer
-
New Android TapTrap attack fools users with invisible UI trick
New Android TapTrap attack fools users with invisible UI trick A novel tapjacking technique can exploit user interface animations to bypass Android’s permission system and allow access to sensitive data or trick users into performing destructive actions, such as wiping the device. […] Bill Toulas Go to bleepingcomputer
-
Windows 10 KB5062554 cumulative update released with 13 changes, fixes
Windows 10 KB5062554 cumulative update released with 13 changes, fixes Microsoft has released the KB5062554 cumulative update for Windows 10 22H2 and Windows 10 21H2, with thirteen new fixes or changes. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5062553 & KB5062552 cumulative updates released
Windows 11 KB5062553 & KB5062552 cumulative updates released Microsoft has released Windows 11 KB5062553 and KB5062552 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage
Alleged Chinese hacker tied to Silk Typhoon arrested for cyberespionage A Chinese national was arrested in Milan, Italy, last week for allegedly being linked to the state-sponsored Silk Typhoon hacking group, which responsible for cyberattacks against American organizations and government agencies. […] Lawrence Abrams Go to bleepingcomputer
-
Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now
Public exploits released for Citrix Bleed 2 NetScaler flaw, patch now Researchers have released proof-of-concept (PoC) exploits for a critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed CitrixBleed2, warning that the flaw is easily exploitable and can successfully steal user session tokens. […] Lawrence Abrams Go to bleepingcomputer
-
Employee gets $920 for credentials used in $140 million bank heist
Employee gets $920 for credentials used in $140 million bank heist Hackers stole nearly $140 million from six banks in Brazil by using an employee’s credentials from C&M, a company that offers financial connectivity solutions. […] Bill Toulas Go to bleepingcomputer
-
Atomic macOS infostealer adds backdoor for persistent attacks
Atomic macOS infostealer adds backdoor for persistent attacks Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as ‘AMOS’) that comes with a backdoor, to attackers persistent access to compromised systems. […] Bill Toulas Go to bleepingcomputer
-
Qantas is being extorted in recent data-theft cyberattack
Qantas is being extorted in recent data-theft cyberattack Qantas has confirmed that it is now being extorted by threat actors following a cyberattack that potentially exposed the data for 6 million customers. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI says GPT-5 will unify breakthroughs from different models
OpenAI says GPT-5 will unify breakthroughs from different models OpenAI has again confirmed that it will unify multiple models into one and create GPT-5, which is expected to ship sometime in the summer. […] Mayank Parmar Go to bleepingcomputer
-
Hands on with Windows 11 Notepad’s new markdown support
Hands on with Windows 11 Notepad’s new markdown support Notepad now lets you use markdown text formatting on Windows 11, which means you can write in Notepad just like you could in WordPad. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT is testing disruptive Study Together feature
ChatGPT is testing disruptive Study Together feature OpenAI’s “Study together” mode has been spotted in the wild, and it could help students prepare for exams directly from ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
Ingram Micro outage caused by SafePay ransomware attack
Ingram Micro outage caused by SafePay ransomware attack An ongoing outage at IT giant Ingram Micro is caused by a SafePay ransomware attack that led to the shutdown of internal systems, BleepingComputer has learned. […] Lawrence Abrams Go to bleepingcomputer
-
Google’s AI video maker Veo 3 is now available via $20 Gemini
Google’s AI video maker Veo 3 is now available via $20 Gemini Google says Veo 3, which is the company’s state-of-the-art video generator, is now shipping to everyone using the Gemini app with a $20 subscription. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT Deep Research tests new connectors for more context
ChatGPT Deep Research tests new connectors for more context ChatGPT Deep Research, which is an AI research tool to automate research, is getting support for new connectors (integrations), including Slack. […] Mayank Parmar Go to bleepingcomputer
-
Ingram Micro suffers global outage as internal systems inaccessible
Ingram Micro suffers global outage as internal systems inaccessible IT giant Ingram Micro is experiencing a global outage that is impacting its websites and internal systems, with customers concerned that it may be a cyberattack after the company remains silent on the cause of the issues. […] Lawrence Abrams Go to bleepingcomputer
-
Hacker leaks Telefónica data allegedly stolen in a new breach
Hacker leaks Telefónica data allegedly stolen in a new breach A hacker is threatening to leak 106GB of data allegedly stolen from Spanish telecommunications company Telefónica in a breach that the company did not acknowledge. […] Ionut Ilascu Go to bleepingcomputer