Tag: bleepingcomputer
-
Leaks hint at Operator-like tool in ChatGPT ahead of GPT-5 launch
Leaks hint at Operator-like tool in ChatGPT ahead of GPT-5 launch A few new code references in the ChatGPT web app and Android point to an Operator-like tool in GPT’s chain of thoughts. […] Mayank Parmar Go to bleepingcomputer
-
xAI prepares Grok 4 Code as it plans to take on Claude and Gemini
xAI prepares Grok 4 Code as it plans to take on Claude and Gemini xAI is preparing the rollout of Grok 4, which replaces Grok 3 as the new state-of-the-art model. […] Mayank Parmar Go to bleepingcomputer
-
Police dismantles investment fraud ring stealing €10 million
Police dismantles investment fraud ring stealing €10 million The Spanish police have dismantled a large-scale investment fraud operation based in the country, which has caused cumulative damages exceeding €10 million ($11.8M). […] Bill Toulas Go to bleepingcomputer
-
Grafana releases critical security update for Image Renderer plugin
Grafana releases critical security update for Image Renderer plugin Grafana Labs has addressed four Chromium vulnerabilities in critical security updates for the Grafana Image Renderer plugin and Synthetic Monitoring Agent. […] Bill Toulas Go to bleepingcomputer
-
IdeaLab confirms data stolen in ransomware attack last year
IdeaLab confirms data stolen in ransomware attack last year IdeaLab is notifying individuals impacted by a data breach incident last October when hackers accessed sensitive information. […] Bill Toulas Go to bleepingcomputer
-
Microsoft asks users to ignore Windows Firewall config errors
Microsoft asks users to ignore Windows Firewall config errors Microsoft asked customers this week to disregard incorrect Windows Firewall errors that appear after rebooting their systems following the installation of the June 2025 preview update. […] Sergiu Gatlan Go to bleepingcomputer
-
NimDoor crypto-theft macOS malware revives itself when killed
NimDoor crypto-theft macOS malware revives itself when killed North Korean state-backed hackers have been using a new family of macOS malware called NimDoor in a campaign that targets web3 and cryptocurrency organizations. […] Bill Toulas Go to bleepingcomputer
-
DOJ investigates ex-ransomware negotiator over extortion kickbacks
DOJ investigates ex-ransomware negotiator over extortion kickbacks An ex-ransomware negotiator is under criminal investigation by the Department of Justice for allegedly working with ransomware gangs to profit from extortion payment deals. […] Lawrence Abrams Go to bleepingcomputer
-
Spain arrests hackers who targeted politicians and journalists
Spain arrests hackers who targeted politicians and journalists The Spanish police have arrested two individuals in the province of Las Palmas for their alleged involvement in cybercriminal activity, including data theft from the country’s government. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns that Unified CM has hardcoded root SSH credentials
Cisco warns that Unified CM has hardcoded root SSH credentials Cisco has removed a backdoor account from its Unified Communications Manager (Unified CM), which would have allowed remote attackers to log in to unpatched devices with root privileges. […] Sergiu Gatlan Go to bleepingcomputer
-
Qantas discloses cyberattack amid Scattered Spider aviation breaches
Qantas discloses cyberattack amid Scattered Spider aviation breaches Australian airline Qantas disclosed that it detected a cyberattack on Monday after threat actors gained access to a third-party platform containing customer data. […] Lawrence Abrams Go to bleepingcomputer
-
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks
AT&T rolls out “Wireless Lock” feature to block SIM swap attacks AT&T has launched a new security feature called “Wireless Lock” that protects customers from SIM swapping attacks by preventing changes to their account information and the porting of phone numbers while the feature is enabled. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft open-sources VS Code Copilot Chat extension on GitHub
Microsoft open-sources VS Code Copilot Chat extension on GitHub Microsoft has released the source code for the GitHub Copilot Chat extension for VS Code under the MIT license. […] Bill Toulas Go to bleepingcomputer
-
Kelly Benefits says 2024 data breach impacts 550,000 customers
Kelly Benefits says 2024 data breach impacts 550,000 customers Kelly & Associates Insurance Group (dba Kelly Benefits) is informing more than half a million people of a data breach that compromised their personal information. […] Bill Toulas Go to bleepingcomputer
-
Aeza Group sanctioned for hosting ransomware, infostealer servers
Aeza Group sanctioned for hosting ransomware, infostealer servers The U.S. Department of the Treasury has sanctioned Russian hosting company Aeza Group and four operators for allegedly acting as a bulletproof hosting company for ransomware gangs, infostealer operations, darknet drug markets, and Russian disinformation campaigns. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. warns of Iranian cyber threats on critical infrastructure
U.S. warns of Iranian cyber threats on critical infrastructure U.S. cyber agencies, the FBI, and NSA issued an urgent warning today about potential cyberattacks from Iranian-affiliated hackers targeting U.S. critical infrastructure. […] Lawrence Abrams Go to bleepingcomputer
-
Germany asks Google, Apple to remove DeepSeek AI from app stores
Germany asks Google, Apple to remove DeepSeek AI from app stores The Berlin Commissioner for Data Protection has formally requested Google and Apple to remove the DeepSeek AI application from the application stores due to GDPR violations. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender for Office 365 now blocks email bombing attacks
Microsoft Defender for Office 365 now blocks email bombing attacks Microsoft says its Defender for Office 365 cloud-based email security suite will now automatically detect and block email bombing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Switzerland says government data stolen in ransomware attack
Switzerland says government data stolen in ransomware attack The government in Switzerland is informing that sensitive information from various federal offices has been impacted by a ransomware attack at the third-party organization Radix. […] Bill Toulas Go to bleepingcomputer
-
Hikvision Canada ordered to cease operations over security risks
Hikvision Canada ordered to cease operations over security risks The Canadian government has ordered Hikvision’s subsidiary in the country to cease all operations following a review that determined them to pose a national security risk. […] Bill Toulas Go to bleepingcomputer
-
Google rolls out Veo 3 video generator, try it for free using credits
Google rolls out Veo 3 video generator, try it for free using credits Google is rolling out Veo 3 to everyone using Vertex AI, which is an ML-testing platform provided by Google Cloud. […] Mayank Parmar Go to bleepingcomputer
-
Bluetooth flaws could let hackers spy through your microphone
Bluetooth flaws could let hackers spy through your microphone Vulnerabilities affecting a Bluetooth chipset present in more than two dozen audio devices from ten vendors can be exploited for eavesdropping or stealing sensitive information. […] Ionut Ilascu Go to bleepingcomputer
-
Cloudflare open-sources Orange Meets with End-to-End encryption
Cloudflare open-sources Orange Meets with End-to-End encryption Cloudflare has implemented end-to-end encryption (E2EE) to its video calling app Orange Meets and open-sourced the solution for transparency. […] Bill Toulas Go to bleepingcomputer
-
Let’s Encrypt ends certificate expiry emails to cut costs, boost privacy
Let’s Encrypt ends certificate expiry emails to cut costs, boost privacy Let’s Encrypt has announced it will no longer notify users about imminent certificate expirations via email due to high costs, privacy concerns, and unnecessary complexities. […] Bill Toulas Go to bleepingcomputer
-
Scattered Spider hackers shift focus to aviation, transportation firms
Scattered Spider hackers shift focus to aviation, transportation firms Hackers associated with Scattered Spider tactics have expanded their targeting to the aviation and transportation industries after previously attacking insurance and retail sectors […] Lawrence Abrams Go to bleepingcomputer
-
Russia’s throttling of Cloudflare makes sites inaccessible
Russia’s throttling of Cloudflare makes sites inaccessible Starting June 9, 2025, Russian internet service providers (ISPs) have begun throttling access to websites and services protected by Cloudflare, an American internet giant. […] Bill Toulas Go to bleepingcomputer
-
Citrix Bleed 2 flaw now believed to be exploited in attacks
Citrix Bleed 2 flaw now believed to be exploited in attacks A critical NetScaler ADC and Gateway vulnerability dubbed “Citrix Bleed 2” (CVE-2025-5777) is now likely exploited in attacks, according to cybersecurity firm ReliaQuest, seeing an increase in suspicious sessions on Citrix devices. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Ahold Delhaize says data breach affects 2.2 million people
Retail giant Ahold Delhaize says data breach affects 2.2 million people Ahold Delhaize, one of the world’s largest food retail chains, is notifying over 2.2 million individuals that their personal, financial, and health information was stolen in a November ransomware attack that impacted its U.S. systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5060829 update released with 38 new changes, fixes
Windows 11 KB5060829 update released with 38 new changes, fixes Microsoft has released the KB5060829 preview cumulative update for Windows 11 24H2, which includes 38 changes, including improvements to the taskbar and a new PC-to-PC migration experience. […] Sergiu Gatlan Go to bleepingcomputer
-
Whole Foods supplier UNFI restores core systems after cyberattack
Whole Foods supplier UNFI restores core systems after cyberattack American grocery wholesale giant United Natural Foods (UNFI) reports that it has restored its core systems and brought online the electronic ordering and invoicing systems affected by a cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Hawaiian Airlines discloses cyberattack, flights not affected
Hawaiian Airlines discloses cyberattack, flights not affected Hawaiian Airlines, the tenth-largest commercial airline in the United States, is investigating a cyberattack that has disrupted access to some of its systems. […] Sergiu Gatlan Go to bleepingcomputer
-
FTC approves $126 million in Fortnite refunds over ‘dark patterns’
FTC approves $126 million in Fortnite refunds over ‘dark patterns’ The Federal Trade Commission (FTC) has approved $126,000,000 in refunds to be sent to 969,173 Fortnite players as part of a settlement over allegations that Epic Games tricked users into making unwanted purchases. […] Bill Toulas Go to bleepingcomputer
-
Microsoft confirms Family Safety blocks Google Chrome from launching
Microsoft confirms Family Safety blocks Google Chrome from launching Microsoft has confirmed that its Family Safety parental control service is blocking users from launching Google Chrome and other web browsers on Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks
CISA: AMI MegaRAC bug enabling server hijacks exploited in attacks CISA says a maximum severity vulnerability in AMI’s MegaRAC Baseboard Management Controller (BMC) software, which enables attackers to hijack and brick servers, is currently under active exploitation. […] Sergiu Gatlan Go to bleepingcomputer
-
Hacker ‘IntelBroker’ charged in US for global data theft breaches
Hacker ‘IntelBroker’ charged in US for global data theft breaches A British national known online as “IntelBroker” has been charged by the U.S. for stealing and selling sensitive data from dozens of victims, causing an estimated $25 million in damages. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers turn ScreenConnect into malware using Authenticode stuffing
Hackers turn ScreenConnect into malware using Authenticode stuffing Threat actors are abusing the ConnectWise ScreenConnect installer to build signed remote access malware by modifying hidden settings within the client’s Authenticode signature. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks A sophisticated malicious campaign that researchers call OneClik has been leveraging Microsoft’s ClickOnce software deployment tool and custom Golang backdoors to compromise organizations within the energy, oil, and gas sectors. […] Ionut Ilascu Go to bleepingcomputer
-
Google rolls out text-to-image model Imagen 4 for free
Google rolls out text-to-image model Imagen 4 for free Google confirmed that Imagen 4, which is the company’s state-of-the-art text-to-image, is rolling out for free, but only on AI Studio. […] Mayank Parmar Go to bleepingcomputer
-
Claude catches up to ChatGPT with built-in memory support
Claude catches up to ChatGPT with built-in memory support AI startup Anthorpic is planning to add a memory feature to Claude in a bid to take on ChatGPT, which has an advanced memory feature. […] Mayank Parmar Go to bleepingcomputer
-
Google Cloud donates A2A AI protocol to the Linux Foundation
Google Cloud donates A2A AI protocol to the Linux Foundation Google Cloud has donated its Agent2Agent (A2A) protocol to the Linux Foundation, which has now announced a new community-driven project called the Agent2Agent Project. […] Bill Toulas Go to bleepingcomputer
-
SonicWall warns of trojanized NetExtender stealing VPN logins
SonicWall warns of trojanized NetExtender stealing VPN logins SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials. […] Bill Toulas Go to bleepingcomputer
-
Windows 10 KB5061087 update released with 13 changes and fixes
Windows 10 KB5061087 update released with 13 changes and fixes Microsoft has released the June 2025 non-security preview update for Windows 10, version 22H2, with fixes for bugs preventing the Start Menu from launching and breaking scanning features on USB multi-function printers. […] Sergiu Gatlan Go to bleepingcomputer
-
APT28 hackers use Signal chats to launch new malware attacks on Ukraine
APT28 hackers use Signal chats to launch new malware attacks on Ukraine The Russian state-sponsored threat group APT28 is using Signal chats to target government targets in Ukraine with two previously undocumented malware families named BeardShell and SlimAgent. […] Bill Toulas Go to bleepingcomputer
-
Malware on Google Play, Apple App Store stole your photos—and crypto
Malware on Google Play, Apple App Store stole your photos—and crypto A new mobile crypto-stealing malware called SparkKitty was found in apps on Google Play and the Apple App Store, targeting Android and iOS devices. […] Bill Toulas Go to bleepingcomputer
-
US Homeland Security warns of escalating Iranian cyberattack risks
US Homeland Security warns of escalating Iranian cyberattack risks The U.S. Department of Homeland Security (DHS) warned over the weekend of escalating cyberattack risks by Iran-backed hacking groups and pro-Iranian hacktivists. […] Sergiu Gatlan Go to bleepingcomputer
-
Canada says Salt Typhoon hacked telecom firm via Cisco flaw
Canada says Salt Typhoon hacked telecom firm via Cisco flaw The Canadian Centre for Cyber Security and the FBI confirm that the Chinese state-sponsored ‘Salt Typhoon’ hacking group is also targeting Canadian telecommunication firms, breaching a telecom provider in February. […] Bill Toulas Go to bleepingcomputer
-
Revil ransomware members released after time served on carding charges
Revil ransomware members released after time served on carding charges Four REvil ransomware members arrested in January 2022 were released by Russia on time served after they pleaded guilty to carding and malware distribution charges. […] Sergiu Gatlan Go to bleepingcomputer
-
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup
CoinMarketCap briefly hacked to drain crypto wallets via fake Web3 popup CoinMarketCap, the popular cryptocurrency price tracking site, suffered a website supply chain attack that exposed site visitors to a wallet drainer campaign to steal visitors’ crypto. […] Lawrence Abrams Go to bleepingcomputer
-
Oxford City Council suffers breach exposing two decades of data
Oxford City Council suffers breach exposing two decades of data Oxford City Council warns it suffered a data breach where attackers accessed personally identifiable information from legacy systems. […] Bill Toulas Go to bleepingcomputer
-
Windows Snipping Tool now lets you create animated GIF recordings
Windows Snipping Tool now lets you create animated GIF recordings Microsoft announced that the Windows screenshot and screencast Snipping Tool utility is getting support for exporting animated GIF recordings. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian hackers bypass Gmail MFA using stolen app passwords
Russian hackers bypass Gmail MFA using stolen app passwords Russian hackers bypass multi-factor authentication and access Gmail accounts by leveraging app-specific passwords in advanced social engineering attacks that impersonate U.S. Department of State officials. […] Ionut Ilascu Go to bleepingcomputer
-
WordPress Motors theme flaw mass-exploited to hijack admin accounts
WordPress Motors theme flaw mass-exploited to hijack admin accounts Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme “Motors” to hijack administrator accounts and gain complete control of a targeted site. […] Bill Toulas Go to bleepingcomputer
-
BitoPro exchange links Lazarus hackers to $11 million crypto heist
BitoPro exchange links Lazarus hackers to $11 million crypto heist The Taiwanese cryptocurrency exchange BitoPro claims the North Korean hacking group Lazarus is behind a cyberattack that led to the theft of $11,000,000 worth of cryptocurrency on May 8, 2025. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates OneDrive bug that breaks file search
Microsoft investigates OneDrive bug that breaks file search Microsoft is investigating a known OneDrive issue that is causing searches to appear blank for some users or return no results even when searching for files they know they’ve already uploaded. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider
Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider Cloudflare says it mitigated a record-breaking distributed denial of service (DDoS) attack in May 2025 that peaked at 7.3 Tbps, targeting a hosting provider. […] Bill Toulas Go to bleepingcomputer
-
Aflac discloses breach amidst Scattered Spider insurance attacks
Aflac discloses breach amidst Scattered Spider insurance attacks On Friday, American insurance giant Aflac disclosed that its systems were breached in a broader campaign targeting insurance companies across the United States by attackers who may have stolen personal and health information. […] Sergiu Gatlan Go to bleepingcomputer
-
Can users reset their own passwords without sacrificing security?
Can users reset their own passwords without sacrificing security? Self-service password resets (SSPR) reduce helpdesk strain—but without strong security, they can open the door to attackers. Learn why phishing-resistant MFA, context-aware verification, and risk-based detection are critical to secure SSPR implementation. […] Sponsored by Specops Software Go to bleepingcomputer
-
No, the 16 billion credentials leak is not a new data breach
No, the 16 billion credentials leak is not a new data breach News broke today of a “mother of all breaches,” sparking wide media coverage filled with warnings and fear-mongering. However, it appears to be a compilation of previously leaked credentials stolen by infostealers, exposed in data breaches, and via credential stuffing attacks. […] Lawrence Abrams…
-
Godfather Android malware now uses virtualization to hijack banking apps
Godfather Android malware now uses virtualization to hijack banking apps A new version of the Android malware “Godfather” creates isolated virtual environments on mobile devices to steal account data and transactions from legitimate banking apps. […] Bill Toulas Go to bleepingcomputer
-
Webinar: Stolen credentials are the new front door to your network
Webinar: Stolen credentials are the new front door to your network Cybercriminals no longer need zero-days to breach your systems—these days, they just log in. Join BleepingComputer, SC Media, and Specops Software’s Darren Siegel on July 9 at 2:00 PM ET for a live webinar on how attackers are using stolen credentials to infiltrate networks…
-
OpenAI’s Sam Altman discusses GPT-5 release date
OpenAI’s Sam Altman discusses GPT-5 release date ChatGPT’s next big upgrade, or the new foundational model “GPT-5,” is still being prepared for a release in the summer, but OpenAI won’t share the specifics. […] Mayank Parmar Go to bleepingcomputer
-
US recovers $225 million of crypto stolen in investment scams
US recovers $225 million of crypto stolen in investment scams The U.S. Department of Justice has seized more than $225 million in cryptocurrency linked to investment fraud and money laundering operations, the largest crypto seizure in the history of the U.S. Secret Service. […] Bill Toulas Go to bleepingcomputer
-
Krispy Kreme says November data breach impacts over 160,000 people
Krispy Kreme says November data breach impacts over 160,000 people U.S. doughnut chain Krispy Kreme confirmed that attackers stole the personal information of over 160,000 individuals in a November 2024 cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Ryuk ransomware’s initial access expert extradited to the U.S.
Ryuk ransomware’s initial access expert extradited to the U.S. A member of the notorious Ryuk ransomware operation who specialized in gaining initial access to corporate networks has been extradited to the United States. […] Bill Toulas Go to bleepingcomputer
-
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto
Pro-Israel hackers hit Iran’s Nobitex exchange, burn $90M in crypto The pro-Israel “Predatory Sparrow” hacking group claims to have stolen over $90 million in cryptocurrency from Nobitex, Iran’s largest crypto exchange, and burned the funds in a politically motivated cyberattack. […] Lawrence Abrams Go to bleepingcomputer
-
North Korean hackers deepfake execs in Zoom call to spread Mac malware
North Korean hackers deepfake execs in Zoom call to spread Mac malware North Korean advanced persistent threat (APT) ‘BlueNoroff’ (aka ‘Sapphire Sleet’ or ‘TA444’) are using deepfake company executives during fake Zoom calls to trick employees into installing custom malware on their computers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 to block file access via legacy auth protocols by default
Microsoft 365 to block file access via legacy auth protocols by default Microsoft has announced that it will soon update security defaults for all Microsoft 365 tenants to block access to SharePoint, OneDrive, and Office files via legacy authentication protocols. […] Sergiu Gatlan Go to bleepingcomputer
-
New Linux udisks flaw lets attackers get root on major Linux distros
New Linux udisks flaw lets attackers get root on major Linux distros Attackers can exploit two newly discovered local privilege escalation (LPE) vulnerabilities to gain root privileges on systems running major Linux distributions. […] Sergiu Gatlan Go to bleepingcomputer
-
Asana warns MCP AI feature exposed customer data to other orgs
Asana warns MCP AI feature exposed customer data to other orgs Work management platform Asana is warning users of its new Model Context Protocol (MCP) feature that a flaw in its implementation potentially led to data exposure from their instances to other users and vice versa. […] Bill Toulas Go to bleepingcomputer
-
Paddle settles for $5 million over facilitating tech support scams
Paddle settles for $5 million over facilitating tech support scams Paddle.com and its U.S. subsidiary will pay $5 million to settle Federal Trade Commission (FTC) allegations that the company facilitated deceptive tech-support schemes that harmed many U.S. consumers, including older adults. […] Bill Toulas Go to bleepingcomputer
-
Scania confirms insurance claim data breach in extortion attempt
Scania confirms insurance claim data breach in extortion attempt Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its systems and steal insurance claim documents. […] Bill Toulas Go to bleepingcomputer
-
Instagram ‘BMO’ ads use AI deepfakes to scam banking customers
Instagram ‘BMO’ ads use AI deepfakes to scam banking customers Instagram ads impersonating financial institutions like Bank of Montreal (BMO) and EQ Bank (Equitable Bank) are being used to target Canadian consumers with phishing scams and investment fraud. Some ads use AI-powered deepfake videos in an attempt to collect your personal information, while others drive…
-
Hackers switch to targeting U.S. insurance companies
Hackers switch to targeting U.S. insurance companies Threat intelligence researchers are warning of hackers breaching multiple U.S. companies in the insurance industry using all the tactics observed with Scattered Spider activity. […] Ionut Ilascu Go to bleepingcomputer
-
ASUS Armoury Crate bug lets attackers get Windows admin privileges
ASUS Armoury Crate bug lets attackers get Windows admin privileges A high-severity vulnerability in ASUS Armoury Crate software could allow threat actors to escalate their privileges to SYSTEM level on Windows machines. […] Bill Toulas Go to bleepingcomputer
-
Washington Post’s email system hacked, journalists’ accounts compromised
Washington Post’s email system hacked, journalists’ accounts compromised Email accounts of several Washington Post journalists were compromised in a cyberattack believed to have been carried out by a foreign government. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2025.2 released with 13 new tools, car hacking updates
Kali Linux 2025.2 released with 13 new tools, car hacking updates Kali Linux 2025.2, the second release of the year, is now available for download with 13 new tools and an expanded car hacking toolkit. […] Sergiu Gatlan Go to bleepingcomputer
-
Zoomcar discloses security breach impacting 8.4 million users
Zoomcar discloses security breach impacting 8.4 million users Zoomcar Holdings (Zoomcar) has disclosed via an 8-K form filing with the U.S. Securities and Exchange Commission (SEC) a data breach incident impacting 8.4 million users. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: June Windows Server security updates cause DHCP issues
Microsoft: June Windows Server security updates cause DHCP issues Microsoft acknowledged a new issue caused by the June 2025 security updates, causing the DHCP service to freeze on some Windows Server systems. […] Sergiu Gatlan Go to bleepingcomputer
-
ChatGPT’s AI coder Codex now lets you choose the best solution
ChatGPT’s AI coder Codex now lets you choose the best solution ChatGPT’s Codex, which is an AI agent that lets you code and delegate programming tasks, is now testing a new feature that lets you choose the best solution. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT Search gets an upgrade as OpenAI takes aim at Google
ChatGPT Search gets an upgrade as OpenAI takes aim at Google On June 13, OpenAI began rolling out a new ChatGPT Search update to improve quality as the AI startup challenges Google’s dominance. […] Mayank Parmar Go to bleepingcomputer
-
Over 46,000 Grafana instances exposed to account takeover bug
Over 46,000 Grafana instances exposed to account takeover bug More than 46,000 internet-facing Grafana instances remain unpatched and exposed to a client-side open redirect vulnerability that allows executing a malicious plugin and account takeover. […] Bill Toulas Go to bleepingcomputer
-
WestJet investigates cyberattack disrupting internal systems
WestJet investigates cyberattack disrupting internal systems WestJet, Canada’s second-largest airline, is investigating a cyberattack that has disrupted access to some internal systems as it responds to the breach. […] Lawrence Abrams Go to bleepingcomputer
-
Anubis ransomware adds wiper to destroy files beyond recovery
Anubis ransomware adds wiper to destroy files beyond recovery Bill Toulas Go to bleepingcomputer
-
Windows 11 users want these five features back
Windows 11 users want these five features back When Windows 11 was first released, many long-time users felt features they loved had been taken away overnight. Three and a half years later, the same complaints still rise to the top of the Feedback Hub with tens of thousands of votes. […] Mayank Parmar Go to…
-
Google links massive cloud outage to API management issue
Google links massive cloud outage to API management issue Google says an API management issue is behind Thursday’s massive Google Cloud outage, which disrupted or brought down its services and many other online platforms. […] Sergiu Gatlan Go to bleepingcomputer
-
Discord flaw lets hackers reuse expired invites in malware campaign
Discord flaw lets hackers reuse expired invites in malware campaign Hackers are hijacking expired or deleted Discord invite links to redirect users to malicious sites that deliver remote access trojans and information-stealing malware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices Microsoft is investigating a known issue that triggers Secure Boot errors and prevents Surface Hub v1 devices from starting up. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft confirms auth issues affecting Microsoft 365 users
Microsoft confirms auth issues affecting Microsoft 365 users Microsoft is investigating an ongoing incident that is causing users to experience errors with some Microsoft 365 authentication features. […] Sergiu Gatlan Go to bleepingcomputer
-
Victoria’s Secret restores critical systems after cyberattack
Victoria’s Secret restores critical systems after cyberattack Victoria’s Secret has restored all critical systems impacted by a May 24 security incident that forced it to shut down corporate systems and the e-commerce website. […] Sergiu Gatlan Go to bleepingcomputer
-
Trend Micro fixes critical vulnerabilities in multiple products
Trend Micro fixes critical vulnerabilities in multiple products Trend Micro has released security updates to address multiple critical-severity remote code execution and authentication bypass vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer products. […] Bill Toulas Go to bleepingcomputer
-
Google Cloud and Cloudflare hit by widespread service outages
Google Cloud and Cloudflare hit by widespread service outages Google Cloud and Cloudflare are investigating ongoing outages impacting access to sites and various services across multiple regions. […] Sergiu Gatlan Go to bleepingcomputer
-
Graphite spyware used in Apple iOS zero-click attacks on journalists
Graphite spyware used in Apple iOS zero-click attacks on journalists Forensic investigation has confirmed the use of Paragon’s Graphite spyware platform in zero-click attacks that targeted Apple iOS devices of at least two journalists in Europe. […] Bill Toulas Go to bleepingcomputer
-
Password-spraying attacks target 80,000 Microsoft Entra ID accounts
Password-spraying attacks target 80,000 Microsoft Entra ID accounts Hackers have been using the TeamFiltration pentesting framework to target more than 80,000 Microsoft Entra ID accounts at hundreds of organizations worldwide. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Edge now offers secure password deployment for businesses
Microsoft Edge now offers secure password deployment for businesses Microsoft announced that a new Edge feature allowing employees to share passwords more securely in enterprise environments has reached general availability. […] Sergiu Gatlan Go to bleepingcomputer
-
Fog ransomware attack uses unusual mix of legitimate and open-source tools
Fog ransomware attack uses unusual mix of legitimate and open-source tools Fog ransomware hackers are using an uncommon toolset, which includes open-source pentesting utilities and a legitimate employee monitoring software called Syteca. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT o3 API 80% price drop has no impact on performance
ChatGPT o3 API 80% price drop has no impact on performance ChatGPT o3, which has been available via API, is now 80% cheaper for developers, and there’s no visible impact on performance. […] Mayank Parmar Go to bleepingcomputer
-
SmartAttack uses smartwatches to steal data from air-gapped systems
SmartAttack uses smartwatches to steal data from air-gapped systems A new attack dubbed ‘SmartAttack’ uses smartwatches as a covert ultrasonic signal receiver to exfiltrate data from physically isolated (air-gapped) systems. […] Bill Toulas Go to bleepingcomputer
-
Erie Insurance confirms cyberattack behind business disruptions
Erie Insurance confirms cyberattack behind business disruptions Erie Insurance and Erie Indemnity Company have disclosed that a weekend cyberattack is behind the recent business disruptions and platform outages on its website. […] Lawrence Abrams Go to bleepingcomputer
-
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot
Zero-click AI data leak flaw uncovered in Microsoft 365 Copilot A new attack dubbed ‘EchoLeak’ is the first known zero-click AI vulnerability that enables attackers to exfiltrate sensitive data from Microsoft 365 Copilot from a user’s context without interaction. […] Bill Toulas Go to bleepingcomputer
-
DanaBot malware operators exposed via C2 bug added in 2022
DanaBot malware operators exposed via C2 bug added in 2022 A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action. […] Bill Toulas Go to bleepingcomputer