Tag: bleepingcomputer
-
Anthropic: Claude can now end conversations to prevent harmful uses
Anthropic: Claude can now end conversations to prevent harmful uses OpenAI rival Anthropic says Claude has been updated with a rare new feature that allows the AI model to end conversations when it feels it poses harm or is being abused. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI prepares Chromium-based AI browser to take on Google
OpenAI prepares Chromium-based AI browser to take on Google OpenAI is testing an AI-powered browser that uses Chromium as its underlying engine, and it could debut on macOS first. […] Mayank Parmar Go to bleepingcomputer
-
Leak: ChatGPT cheaper plan costs $4 or £3.50, might release everywhere
Leak: ChatGPT cheaper plan costs $4 or £3.50, might release everywhere OpenAI is working on a cheaper plan called ChatGPT Go, and we previously thought it would be just limited to a few regions like India, but that may not be the case. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI is improving ChatGPT voice mode
OpenAI is improving ChatGPT voice mode ChatGPT’s Voice mode is already pretty good, but OpenAI is working on a new feature that will allow you to control how Voice mode actually works. […] Mayank Parmar Go to bleepingcomputer
-
Researcher to release exploit for full auth bypass on FortiWeb
Researcher to release exploit for full auth bypass on FortiWeb A security researcher has released a partial proof of concept exploit for a vulnerability in the FortiWeb web application firewall that allows a remote attacker to bypass authentication. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to protect against malicious URLs, dangerous file types
Microsoft Teams to protect against malicious URLs, dangerous file types Microsoft recently revealed that it’s currently enhancing protection against dangerous file types and malicious URLs in Teams chats and channels. […] Sergiu Gatlan Go to bleepingcomputer
-
Colt Telecom attack claimed by WarLock ransomware, data up for sale
Colt Telecom attack claimed by WarLock ransomware, data up for sale UK-based telecommunications company Colt Technology Services is dealing with a cyberattack that has caused a multi-day outage of some of the company’s operations, including hosting and porting services, Colt Online and Voice API platforms. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of max severity flaw in Firewall Management Center
Cisco warns of max severity flaw in Firewall Management Center Cisco is warning about a critical remote code execution (RCE) vulnerability in the RADIUS subsystem of its Secure Firewall Management Center (FMC) software. […] Bill Toulas Go to bleepingcomputer
-
Microsoft reminds of Windows 10 support ending in two months
Microsoft reminds of Windows 10 support ending in two months Microsoft has reminded customers that Windows 10 will be retired in two months after all editions of Windows 10, version 22H2 reach their end of servicing on October 14. […] Sergiu Gatlan Go to bleepingcomputer
-
Plex warns users to patch security vulnerability immediately
Plex warns users to patch security vulnerability immediately Plex has notified some of its users on Thursday to urgently update their media servers due to a recently patched security vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
US sanctions Grinex crypto-exchange, successor to Garantex
US sanctions Grinex crypto-exchange, successor to Garantex The U.S. Department of the Treasury has announced sanctions against Grinex, the successor to Russian cryptocurrency exchange Garantex, which was previously sanctioned for helping ransomware gangs launder their money. […] Sergiu Gatlan Go to bleepingcomputer
-
Over $300 million in cybercrime crypto seized in anti-fraud effort
Over $300 million in cybercrime crypto seized in anti-fraud effort More than $300 million worth of cryptocurrency linked to cybercrime and fraud schemes has been frozen due to two separate initiatives involving law enforcement and private companies. […] Bill Toulas Go to bleepingcomputer
-
Crypto24 ransomware hits large orgs with custom EDR evasion tool
Crypto24 ransomware hits large orgs with custom EDR evasion tool The Crypto24 ransomware group has been using custom utilities to evade security solutions on breached networks, exfiltrate data, and encrypt files. […] Bill Toulas Go to bleepingcomputer
-
Pro-Russian hackers blamed for water dam sabotage in Norway
Pro-Russian hackers blamed for water dam sabotage in Norway The Norwegian Police Security Service (PST) says that pro-Russian hackers took control of critical operation systems at a dam and opened outflow valves. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes Windows Server bug causing cluster, VM issues
Microsoft fixes Windows Server bug causing cluster, VM issues Microsoft has resolved a known issue that triggers Cluster service and VM restart issues after installing July’s Windows Server 2019 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA warns of N-able N-central flaws exploited in zero-day attacks
CISA warns of N-able N-central flaws exploited in zero-day attacks CISA warned on Wednesday that attackers are actively exploiting two security vulnerabilities in N‑able’s N-central remote monitoring and management (RMM) platform. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows 11 24H2 updates failing with 0x80240069 error
Microsoft fixes Windows 11 24H2 updates failing with 0x80240069 error Microsoft has resolved a known issue preventing the August 2025 Windows 11 24H2 cumulative update from being delivered via Windows Server Update Services (WSUS). […] Sergiu Gatlan Go to bleepingcomputer
-
Google Gemini’s Deep Research is finally coming to API
Google Gemini’s Deep Research is finally coming to API Google Gemini’s one of the most powerful features is Deep Research, but up until now, it has been strictly limited to the Gemini interface. This could change soon. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI relaxes GPT-5 rate limit, promises to improve the personality
OpenAI relaxes GPT-5 rate limit, promises to improve the personality OpenAI is slowly addressing all concerns around GPT-5, including rate limits and now its personality, which has been criticized for being less affirmative. […] Mayank Parmar Go to bleepingcomputer
-
Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild
Fortinet warns of FortiSIEM pre-auth RCE flaw with exploit in the wild Fortinet is warning about a remote unauthenticated command injection flaw in FortiSIEM that has in-the-wild exploit code, making it critical for admins to apply the latest security updates. […] Bill Toulas Go to bleepingcomputer
-
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro
Claude gets 1M tokens support via API to take on Gemini 2.5 Pro Claude Sonnet 4 has been upgraded, and it can now remember up to 1 million tokens of context, but only when it’s used via API. This could change in the future. […] Mayank Parmar Go to bleepingcomputer
-
Hackers leak Allianz Life data stolen in Salesforce attacks
Hackers leak Allianz Life data stolen in Salesforce attacks Hackers have released stolen data belonging to US insurance giant Allianz Life, exposing 2.8 million records with sensitive information on business partners and customers in ongoing Salesforce data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT
OpenAI rolls out Gmail, Calendar, and Contacts integration in ChatGPT OpenAI wants ChatGPT to know more about you, including your emails, calendar events in Google Calendar and even your Google contacts to reference everything in a conversation. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT’s new subscription costs less than $5, but it’s not for everyone
ChatGPT’s new subscription costs less than $5, but it’s not for everyone OpenAI has begun updating its pricing page to include a new plan called ‘ChatGPT Go.’ It costs 399 INR (Indian Rupee) or roughly $4.55, but there’s a catch. […] Mayank Parmar Go to bleepingcomputer
-
Docker Hub still hosts dozens of Linux images with the XZ backdoor
Docker Hub still hosts dozens of Linux images with the XZ backdoor The XZ-Utils backdoor, first discovered in March 2024, is still present in at least 35 Linux images on Docker Hub, potentially putting users, organizations, and their data at risk. […] Bill Toulas Go to bleepingcomputer
-
North Korean Kimsuky hackers exposed in alleged data breach
North Korean Kimsuky hackers exposed in alleged data breach The North Korean state-sponsored hackers known as Kimsuky has reportedly suffered a data breach after two hackers, who describe themselves as the opposite of Kimsuky’s values, stole the group’s data and leaked it publicly online. […] Bill Toulas Go to bleepingcomputer
-
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs
Netherlands: Citrix Netscaler flaw CVE-2025-6543 exploited to breach orgs The Netherlands’ National Cyber Security Centre (NCSC) is warning that a critical Citrix NetScaler vulnerability tracked as CVE-2025-6543 was exploited to breach “critical organizations” in the country. […] Bill Toulas Go to bleepingcomputer
-
Details emerge on WinRAR zero-day attacks that infected PCs with malware
Details emerge on WinRAR zero-day attacks that infected PCs with malware Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian ‘RomCom’ hacking group to drop different malware payloads. […] Bill Toulas Go to bleepingcomputer
-
Microsoft tests cloud-based Windows 365 disaster recovery PCs
Microsoft tests cloud-based Windows 365 disaster recovery PCs Microsoft has announced the limited public preview of Windows 365 Reserve, a service that provides temporary desktop access to pre-configured cloud PCs for employees whose computers have become unavailable due to cyberattacks, hardware issues, or software problems. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI is testing 3,000-per-week limit for GPT-5 Thinking
OpenAI is testing 3,000-per-week limit for GPT-5 Thinking OpenAI has responded to criticism that it shipped GPT-5 with token limits to minimize cost and maximize profit not with words, but rather with a new 3,000-per-week limit. […] Mayank Parmar Go to bleepingcomputer
-
Over 29,000 Exchange servers unpatched against high-severity flaw
Over 29,000 Exchange servers unpatched against high-severity flaw Over 29,000 Exchange servers exposed online remain unpatched against a high-severity vulnerability that can let attackers move laterally in Microsoft cloud environments, potentially leading to complete domain compromise. […] Sergiu Gatlan Go to bleepingcomputer
-
Connex Credit Union data breach impacts 172,000 members
Connex Credit Union data breach impacts 172,000 members Connex, one of Connecticut’s largest credit unions, warned tens of thousands of members that unknown attackers had stolen their personal and financial information after breaching its systems in early June. […] Sergiu Gatlan Go to bleepingcomputer
-
How to restore GPT-4o when you’ve GPT-5
How to restore GPT-4o when you’ve GPT-5 Sam Altman overhyped GPT-5 and the results are underwhelming. Some users are upset with GPT-5’s new personality, but you can restore GPT-4o if you pay for the Plus plan. […] Mayank Parmar Go to bleepingcomputer
-
Google Calendar invites let researchers hijack Gemini to leak user data
Google Calendar invites let researchers hijack Gemini to leak user data Google fixed a bug that allowed maliciously crafted Google Calendar invites to remotely take over Gemini agents running on the target’s device and leak sensitive user data. […] Bill Toulas Go to bleepingcomputer
-
Google confirms data breach exposed potential Google Ads customers’ info
Google confirms data breach exposed potential Google Ads customers’ info Google has confirmed that a recently disclosed data breach of one of its Salesforce CRM instances involved the information of potential Google Ads customers. […] Lawrence Abrams Go to bleepingcomputer
-
60 malicious Ruby gems downloaded 275,000 times steal credentials
60 malicious Ruby gems downloaded 275,000 times steal credentials Sixty malicious Ruby gems containing credential-stealing code have been downloaded over 275,000 times since March 2023, targeting developer accounts. […] Bill Toulas Go to bleepingcomputer
-
OpenAI to fix GPT-5 issues, double rate limits for paid users after outrage
OpenAI to fix GPT-5 issues, double rate limits for paid users after outrage OpenAI’s CEO, Sam Altman, overpromised on GPT-5, and real-life results are underwhelming, but it looks like a new update is rolling out that might address some of the concerns. […] Mayank Parmar Go to bleepingcomputer
-
WinRAR zero-day exploited to plant malware on archive extraction
WinRAR zero-day exploited to plant malware on archive extraction A recently fixed WinRAR vulnerability tracked as CVE-2025-8088 was exploited as a zero-day in phishing attacks to install the RomCom malware. […] Lawrence Abrams Go to bleepingcomputer
-
FTC: older adults lost record $700 million to scammers in 2024
FTC: older adults lost record $700 million to scammers in 2024 Americans aged 60 and older lost a staggering $700 million to online scams in 2024, marking a sharp rise in fraud targeting seniors, according to the Federal Trade Commission. […] Bill Toulas Go to bleepingcomputer
-
U.S. Judiciary confirms breach of court electronic records service
U.S. Judiciary confirms breach of court electronic records service The U.S. Federal Judiciary confirms that it suffered a cyberattack on its electronic case management systems hosting confidential court documents and is strengthening cybersecurity measures. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 apps to soon block file access via FPRPC by default
Microsoft 365 apps to soon block file access via FPRPC by default Microsoft has announced that the Microsoft 365 apps for Windows will start blocking access to files via the insecure FPRPC legacy authentication protocol by default starting late August. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft will kill the Lens PDF scanner app for iOS, Android
Microsoft will kill the Lens PDF scanner app for iOS, Android Microsoft announced that it will phase out the Microsoft Lens PDF scanner app for Android and iOS devices starting September 15, 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Columbia University data breach impacts nearly 870,000 individuals
Columbia University data breach impacts nearly 870,000 individuals An unknown threat actor has stolen the sensitive personal, financial, and health information of nearly 870,000 Columbia University current and former students and employees after breaching the university’s network in May. […] Sergiu Gatlan Go to bleepingcomputer
-
Royal and BlackSuit ransomware gangs hit over 450 US companies
Royal and BlackSuit ransomware gangs hit over 450 US companies The U.S. Department of Homeland Security (DHS) says the cybercrime gang behind the Royal and BlackSuit ransomware operations had breached hundreds of U.S. companies before their infrastructure was dismantled last month. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake WhatsApp developer libraries hide destructive data-wiping code
Fake WhatsApp developer libraries hide destructive data-wiping code Two malicious NPM packages posing as WhatsApp development tools have been discovered deploying destructive data-wiping code that recursively deletes files on a developer’s computers. […] Bill Toulas Go to bleepingcomputer
-
CISA orders fed agencies to patch new Exchange flaw by Monday
CISA orders fed agencies to patch new Exchange flaw by Monday CISA has issued an emergency directive ordering all Federal Civilian Executive Branch (FCEB) agencies to mitigate a critical Microsoft Exchange hybrid vulnerability tracked as CVE-2025-53786 by Monday morning at 9:00 AM ET. […] Lawrence Abrams Go to bleepingcomputer
-
Air France and KLM disclose data breaches impacting customers
Air France and KLM disclose data breaches impacting customers Air France and KLM announced on Wednesday that attackers had breached a customer service platform and stolen the data of an undisclosed number of customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft warns of high-severity flaw in hybrid Exchange deployments
Microsoft warns of high-severity flaw in hybrid Exchange deployments Microsoft has warned customers to mitigate a high-severity vulnerability in Exchange Server hybrid deployments that could allow attackers to escalate privileges in Exchange Online cloud environments undetected. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft accidentally confirms GPT-5, GPT-5-Mini, GPT-5-Nano ahead of launch
Microsoft accidentally confirms GPT-5, GPT-5-Mini, GPT-5-Nano ahead of launch OpenAI is hosting a live stream at 10AM PT to announce GPT-5, but Microsoft has already confirmed the details. […] Mayank Parmar Go to bleepingcomputer
-
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools and EDRs running on target machines. […] Bill Toulas Go to bleepingcomputer
-
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations A new post-exploitation command-and-control (C2) evasion method called ‘Ghost Calls’ abuses TURN servers used by conferencing apps like Zoom and Microsoft Teams to tunnel traffic through trusted infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Trend Micro warns of Apex One zero-day exploited in attacks
Trend Micro warns of Apex One zero-day exploited in attacks Trend Micro has warned customers to immediately secure their systems against an actively exploited remote code execution vulnerability in its Apex One endpoint security platform. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft pays record $17 million in bounties over the last 12 months
Microsoft pays record $17 million in bounties over the last 12 months Microsoft paid a record $17 million this year to 344 security researchers across 59 countries through its bug bounty program. […] Sergiu Gatlan Go to bleepingcomputer
-
Pandora confirms data breach amid ongoing Salesforce data theft attacks
Pandora confirms data breach amid ongoing Salesforce data theft attacks Danish jewelry giant Pandora has disclosed a data breach after its customer information was stolen in the ongoing Salesforce data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
PBS confirms data breach after employee info leaked on Discord servers
PBS confirms data breach after employee info leaked on Discord servers PBS has suffered a data breach exposing the corporate contact information of its employees and those of its affiliates, BleepingComputer has learned. […] Lawrence Abrams Go to bleepingcomputer
-
Adobe issues emergency fixes for AEM Forms zero-days after PoCs released
Adobe issues emergency fixes for AEM Forms zero-days after PoCs released Adobe released emergency updates for two zero-day flaws in Adobe Experience Manager (AEM) Forms on JEE after a PoC exploit chain was disclosed that can be used for unauthenticated, remote code execution on vulnerable instances. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft increases Zero Day Quest prize pool to $5 million
Microsoft increases Zero Day Quest prize pool to $5 million Microsoft will offer up to $5 million in bounty awards at this year’s Zero Day Quest hacking contest, which the company describes as the “largest hacking event in history.” […] Sergiu Gatlan Go to bleepingcomputer
-
Fashion giant Chanel hit in wave of Salesforce data theft attacks
Fashion giant Chanel hit in wave of Salesforce data theft attacks French fashion giant Chanel is the latest company to suffer a data breach in an ongoing wave of Salesforce data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Proton fixes Authenticator bug leaking TOTP secrets in logs
Proton fixes Authenticator bug leaking TOTP secrets in logs Proton fixed a bug in its new Authenticator app for iOS that logged users’ sensitive TOTP secrets in plaintext, potentially exposing multi-factor authentication codes if the logs were shared. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: Outdated Office apps lose access to voice features in January
Microsoft: Outdated Office apps lose access to voice features in January Microsoft announced that the transcription, dictation, and read aloud features will stop working in older versions of Office 365 applications in late January 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users
CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users The ClickTok campaign lures victims with fake TikTok shops and drains their crypto wallets. CTM360 exposes how SparkKitty spyware spreads via trojanized apps, phishing pages, and AI-powered scams. […] Sponsored by CTM360 Go to bleepingcomputer
-
Mozilla warns of phishing attacks targeting add-on developers
Mozilla warns of phishing attacks targeting add-on developers Mozilla has warned browser extension developers of an active phishing campaign targeting accounts on its official AMO (addons.mozilla.org) repository. […] Sergiu Gatlan Go to bleepingcomputer
-
Attackers exploit link-wrapping services to steal Microsoft 365 logins
Attackers exploit link-wrapping services to steal Microsoft 365 logins A threat actor has been abusing link wrapping services from reputed technology companies to mask malicious links leading to Microsoft 365 phishing pages that collect login credentials. […] Ionut Ilascu Go to bleepingcomputer
-
OpenAI prepares new open weight models along with GPT-5
OpenAI prepares new open weight models along with GPT-5 OpenAI isn’t just working on GPT-5. It looks like OpenAI is also preparing to release new open-source weights, living up to its name, OpenAI.’ […] Mayank Parmar Go to bleepingcomputer
-
Anthropic says OpenAI engineers using Claude Code ahead of GPT-5 launch
Anthropic says OpenAI engineers using Claude Code ahead of GPT-5 launch Anthropic says it has revoked OpenAI’s access to the Claude API after ChatGPT’s engineers were found using Claude’s coding tools. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI may be testing a cheaper paid plan for ChatGPT
OpenAI may be testing a cheaper paid plan for ChatGPT OpenAI is reportedly working on a new plan called ‘Go,’ which would be cheaper than the existing $20 Plus subscription. […] Mayank Parmar Go to bleepingcomputer
-
SonicWall firewall devices hit in surge of Akira ransomware attacks
SonicWall firewall devices hit in surge of Akira ransomware attacks SonicWall firewall devices have been increasingly targeted since late July in a surge of Akira ransomware attacks, potentially exploiting a previously unknown security vulnerability, according to cybersecurity company Arctic Wolf. […] Sergiu Gatlan Go to bleepingcomputer
-
Pi-hole discloses data breach triggered by WordPress plugin flaw
Pi-hole discloses data breach triggered by WordPress plugin flaw Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed through a security vulnerability in the GiveWP WordPress donation plugin. […] Sergiu Gatlan Go to bleepingcomputer
-
Kali Linux can now run in Apple containers on macOS systems
Kali Linux can now run in Apple containers on macOS systems Cybersecurity professionals and researchers can now launch Kali Linux in a virtualized container on macOS Sequoia using Apple’s new containerization framework. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft to disable Excel workbook links to blocked file types
Microsoft to disable Excel workbook links to blocked file types Microsoft has announced that it will start disabling external workbook links to blocked file types by default between October 2025 and July 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft now pays up to $40,000 for some .NET vulnerabilities
Microsoft now pays up to $40,000 for some .NET vulnerabilities Microsoft has expanded its .NET bug bounty program and increased rewards to $40,000 for some .NET and ASP.NET Core vulnerabilities. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA open-sources Thorium platform for malware, forensic analysis
CISA open-sources Thorium platform for malware, forensic analysis The U.S. Cybersecurity and Infrastructure Security Agency (CISA) today announced the public availability of Thorium, an open-source platform for malware and forensic analysts across the government, public, and private sectors. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks
Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks Microsoft warns that a cyber-espionage group linked to Russia’s Federal Security Service (FSB) is targeting diplomatic missions in Moscow using local internet service providers. […] Sergiu Gatlan Go to bleepingcomputer
-
ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH
ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH A wave of data breaches impacting companies like Qantas, Allianz Life, LVMH, and Adidas has been linked to the ShinyHunters extortion group, which has been using voice phishing attacks to steal data from Salesforce CRM instances. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers target Python devs in phishing attacks using fake PyPI site
Hackers target Python devs in phishing attacks using fake PyPI site The Python Software Foundation warned users this week that threat actors are trying to steal their credentials in phishing attacks using a fake Python Package Index (PyPI) website. […] Sergiu Gatlan Go to bleepingcomputer
-
SafePay ransomware threatens to leak 3.5TB of Ingram Micro data
SafePay ransomware threatens to leak 3.5TB of Ingram Micro data The SafePay ransomware gang is threatening to leak 3.5TB of data belonging to IT giant Ingram Micro, allegedly stolen from the company’s compromised systems earlier this month. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers actively exploit critical RCE in WordPress Alone theme
Hackers actively exploit critical RCE in WordPress Alone theme Threat actors are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in the WordPress theme ‘Alone,’ to achieve remote code execution and perform a full site takeover. […] Bill Toulas Go to bleepingcomputer
-
Hackers plant 4G Raspberry Pi on bank network in failed ATM heist
Hackers plant 4G Raspberry Pi on bank network in failed ATM heist The UNC2891 hacking group, also known as LightBasin, used a 4G-equipped Raspberry Pi hidden in a bank’s network to bypass security defenses in a newly discovered attack. […] Bill Toulas Go to bleepingcomputer
-
Minnesota activates National Guard after St. Paul cyberattack
Minnesota activates National Guard after St. Paul cyberattack Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state’s capital, on Friday. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian airline Aeroflot grounds dozens of flights after cyberattack
Russian airline Aeroflot grounds dozens of flights after cyberattack Aeroflot, Russia’s flag carrier, has suffered a cyberattack that resulted in the cancellation of more than 60 flights and severe delays on additional flights. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware Hackers were spotted exploiting a critical SAP NetWeaver vulnerability tracked as CVE-2025-31324 to deploy the Auto-Color Linux malware in a cyberattack on a U.S.-based chemicals company. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Edge now an ‘AI-powered browser’ with Copilot Mode
Microsoft Edge now an ‘AI-powered browser’ with Copilot Mode Microsoft has introduced Copilot Mode, an experimental feature designed to transform Microsoft Edge into a web browser powered by artificial intelligence (AI). […] Sergiu Gatlan Go to bleepingcomputer
-
French telecom giant Orange discloses cyberattack
French telecom giant Orange discloses cyberattack Orange, a French telecommunications company and one of the world’s largest telecom operators, revealed that it detected a breached system on its network on Friday. […] Sergiu Gatlan Go to bleepingcomputer
-
Lovense sex toy app flaw leaks private user email addresses
Lovense sex toy app flaw leaks private user email addresses The connected sex toy platform Lovense is vulnerable to a zero-day flaw that allows an attacker to get access to a member’s email address simply by knowing their username, putting them at risk of doxxing and harassment. […] Lawrence Abrams Go to bleepingcomputer
-
Tea app leak worsens with second database exposing user chats
Tea app leak worsens with second database exposing user chats The Tea app data breach has grown into an even larger leak, with the stolen data now shared on hacking forums and a second database discovered that allegedly contains 1.1 million private messages exchanged between the app’s members. […] Lawrence Abrams Go to bleepingcomputer
-
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution A vulnerability in Google’s Gemini CLI allowed attackers to silently execute malicious commands and exfiltrate data from developers’ computers using allowlisted programs. […] Bill Toulas Go to bleepingcomputer
-
Endgame Gear mouse config tool infected users with malware
Endgame Gear mouse config tool infected users with malware Gaming peripherals maker Endgame Gear is warning that malware was hidden in its configuration tool for the OP1w 4k v2 mouse hosted on the official website between June 26 and July 9, 2025. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. […] Sergiu Gatlan Go to bleepingcomputer
-
Scattered Spider is running a VMware ESXi hacking spree
Scattered Spider is running a VMware ESXi hacking spree Scattered Spider hackers have been aggressively targeting virtualized environments by attacking VMware ESXi hypervisors at U.S. companies in the retail, airline, transportation, and insurance sectors. […] Bill Toulas Go to bleepingcomputer
-
Allianz Life confirms data breach impacts majority of 1.4 million customers
Allianz Life confirms data breach impacts majority of 1.4 million customers Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks
Post SMTP plugin flaw exposes 200K WordPress sites to hijacking attacks More than 200,000 WordPress websites are using a vulnerable version of the Post SMTP plugin that allows hackers to take control of the administrator account. […] Bill Toulas Go to bleepingcomputer
-
Amazon AI coding agent hacked to inject data wiping commands
Amazon AI coding agent hacked to inject data wiping commands A hacker planted data wiping code in a version of Amazon’s generative AI-powered assistant, the Q Developer Extension for Visual Studio Code. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft investigates outage affecting Microsoft 365 admin center Microsoft is investigating an ongoing outage blocking Microsoft 365 administrators with business or enterprise subscriptions from accessing the admin center. […] Sergiu Gatlan Go to bleepingcomputer
-
The role of the cybersecurity PM in incident-driven development
The role of the cybersecurity PM in incident-driven development From PowerShell abuse to USB data theft, modern threats hit fast—and hard.vSee how security-minded PMs are responding with real-time controls, smarter policies, and tools like ThreatLocker Patch Management. […] Sponsored by ThreatLocker Go to bleepingcomputer
-
US sanctions North Korean firm, nationals behind IT worker schemes
US sanctions North Korean firm, nationals behind IT worker schemes The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned three North Korean nationals and a company for supporting fraudulent IT worker schemes that generated illicit revenue for the Democratic People’s Republic of Korea (DPRK) government. […] Bill Toulas Go to…
-
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms
Woman gets 8 years for aiding North Koreans infiltrate 300 US firms Christina Marie Chapman, a 50-year-old woman from Arizona, was sentenced to 102 months in prison after pleading guilty to her involvement in a scheme that enabled North Korean IT workers to infiltrate 309 U.S. companies. […] Sergiu Gatlan Go to bleepingcomputer
-
BlackSuit ransomware extortion sites seized in Operation Checkmate
BlackSuit ransomware extortion sites seized in Operation Checkmate Law enforcement has seized the dark web extortion sites of the BlackSuit ransomware operation, which has targeted and breached the networks of hundreds of organizations worldwide over the past several years. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI confirms ChatGPT Agent is now rolling out for $20 Plus users
OpenAI confirms ChatGPT Agent is now rolling out for $20 Plus users ChatGPT Agent is now rolling out to users with $20 Plus subscription, but OpenAI warns that it will take a few days for the rollout to finish. […] Mayank Parmar Go to bleepingcomputer
-
New Koske Linux malware hides in cute panda images
New Koske Linux malware hides in cute panda images A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory. […] Bill Toulas Go to bleepingcomputer
-
Hacker sneaks infostealer malware into early access Steam game
Hacker sneaks infostealer malware into early access Steam game A threat actor called EncryptHub has compromised a game on Steam to distribute info-stealing malware to unsuspecting users downloading the title. […] Bill Toulas Go to bleepingcomputer