Tag: bleepingcomputer
-
ConnectWise rotating code signing certificates over security concerns
ConnectWise rotating code signing certificates over security concerns ConnectWise is warning customers that it is rotating the digital code signing certificates used to sign ScreenConnect, ConnectWise Automate, and ConnectWise RMM executables over security concerns. […] Bill Toulas Go to bleepingcomputer
-
New Secure Boot flaw lets attackers install bootkit malware, patch now
New Secure Boot flaw lets attackers install bootkit malware, patch now Security researchers have disclosed a new Secure Boot bypass tracked as CVE-2025-3052 that can be used to turn off security on PCs and servers and install bootkit malware. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Windows 10 KB5060533 cumulative update released with 7 changes, fixes Microsoft has released the KB5060533 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including bringing seconds back to the time shown in the Calendar flyout. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws Today is Microsoft’s June 2025 Patch Tuesday, which includes security updates for 66 flaws, including one actively exploited vulnerability and another that was publicly disclosed. […] Lawrence Abrams Go to bleepingcomputer
-
Stolen Ticketmaster data from Snowflake attacks briefly for sale again
Stolen Ticketmaster data from Snowflake attacks briefly for sale again The Arkana Security extortion gang briefly listed over the weekend what appeared to be newly stolen Ticketmaster data but is instead the data stolen during the 2024 Snowflake data theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Over 84,000 Roundcube instances vulnerable to actively exploited flaw
Over 84,000 Roundcube instances vulnerable to actively exploited flaw Over 84,000 instances of the Roundcube webmail software are vulnerable to CVE-2025-49113, a critical remote code execution (RCE) vulnerability with a publicly available exploit. […] Bill Toulas Go to bleepingcomputer
-
Google patched bug leaking phone numbers tied to accounts
Google patched bug leaking phone numbers tied to accounts A vulnerability allowed researchers to brute-force any Google account’s recovery phone number simply by knowing a their profile name and an easily retrieved partial phone number, creating a massive risk for phishing and SIM-swapping attacks. […] Bill Toulas Go to bleepingcomputer
-
SentinelOne shares new details on China-linked breach attempt
SentinelOne shares new details on China-linked breach attempt SentinelOne has shared more details on an attempted supply chain attack by Chinese hackers through an IT services and logistics firm that manages hardware logistics for the cybersecurity firm. […] Bill Toulas Go to bleepingcomputer
-
Linux Foundation unveils decentralized WordPress plugin manager
Linux Foundation unveils decentralized WordPress plugin manager A collective of former WordPress developers and contributors backed by the Linux Foundation has launched the FAIR Package Manager, a new and independent distribution system for trusted WordPress plugins and themes. […] Sergiu Gatlan Go to bleepingcomputer
-
New Mirai botnet infect TBK DVR devices via command injection flaw
New Mirai botnet infect TBK DVR devices via command injection flaw A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. […] Bill Toulas Go to bleepingcomputer
-
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads
Supply chain attack hits Gluestack NPM packages with 960K weekly downloads A significant supply chain attack hit NPM after 15 popular Gluestack packages with over 950,000 weekly downloads were compromised to include malicious code that acts as a remote access trojan (RAT). […] Lawrence Abrams Go to bleepingcomputer
-
Malicious npm packages posing as utilities delete project directories
Malicious npm packages posing as utilities delete project directories Two malicious packages have been discovered in the npm JavaScript package index, which masquerades as useful utilities but, in reality, are destructive data wipers that delete entire application directories. […] Bill Toulas Go to bleepingcomputer
-
Microsoft shares script to restore inetpub folder you shouldn’t delete
Microsoft shares script to restore inetpub folder you shouldn’t delete Microsoft has released a PowerShell script to help restore an empty ‘inetpub’ folder created by the April 2025 Windows security updates if deleted. As Microsoft previously warned, this folder helps mitigate a high-severity Windows Process Activation privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Tax resolution firm Optima Tax Relief hit by ransomware, data leaked
Tax resolution firm Optima Tax Relief hit by ransomware, data leaked U.S. tax resolution firm Optima Tax Relief suffered a Chaos ransomware attack, with the threat actors now leaking data stolen from the company. […] Lawrence Abrams Go to bleepingcomputer
-
Kettering Health confirms Interlock ransomware behind cyberattack
Kettering Health confirms Interlock ransomware behind cyberattack Healthcare giant Kettering Health, which manages 14 medical centers in Ohio, confirmed that the Interlock ransomware group breached its network and stole data in a May cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
New PathWiper data wiper malware hits critical infrastructure in Ukraine
New PathWiper data wiper malware hits critical infrastructure in Ukraine A new data wiper malware named ‘PathWiper’ is being used in targeted attacks against critical infrastructure in Ukraine, aimed at disrupting operations in the country. […] Bill Toulas Go to bleepingcomputer
-
Critical Fortinet flaws now exploited in Qilin ransomware attacks
Critical Fortinet flaws now exploited in Qilin ransomware attacks The Qilin ransomware operation has recently joined attacks exploiting two Fortinet vulnerabilities that allow bypassing authentication on vulnerable devices and executing malicious code remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Police arrests 20 suspects for distributing child sexual abuse content
Police arrests 20 suspects for distributing child sexual abuse content Law enforcement authorities from over a dozen countries have arrested 20 suspects in an international operation targeting the production and distribution of child sexual abuse material. […] Sergiu Gatlan Go to bleepingcomputer
-
Google’s upcoming Gemini Kingfall is allegedly a coding beast
Google’s upcoming Gemini Kingfall is allegedly a coding beast Google’s AI advancement is not slowing down, and we might be getting yet another powerful model codenamed “Gemini Kingfall.” […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT prepares o3-pro model for $200 Pro subscribers
ChatGPT prepares o3-pro model for $200 Pro subscribers OpenAI is planning to ship an update to ChatGPT that will turn on the new o3 Pro model, which has more compute to think harder. […] Mayank Parmar Go to bleepingcomputer
-
FBI: BADBOX 2.0 Android malware infects millions of consumer devices
FBI: BADBOX 2.0 Android malware infects millions of consumer devices The FBI is warning that the BADBOX 2.0 malware campaign has infected over 1 million home Internet-connected devices, converting consumer electronics into residential proxies that are used for malicious activity. […] Lawrence Abrams Go to bleepingcomputer
-
Old AT&T data leak repackaged to link SSNs, DOBs to 49M phone numbers
Old AT&T data leak repackaged to link SSNs, DOBs to 49M phone numbers A threat actor has re-released data from a 2021 AT&T breach affecting 70 million customers, this time combining previously separate files to directly link Social Security numbers and birth dates to individual users. […] Lawrence Abrams Go to bleepingcomputer
-
ViLE gang members sentenced for extortion, police portal breach
ViLE gang members sentenced for extortion, police portal breach Two members of a group of cybercriminals named ViLE were sentenced this week for hacking into a federal law enforcement web portal in an extortion scheme. […] Sergiu Gatlan Go to bleepingcomputer
-
Interlock ransomware claims Kettering Health breach, leaks stolen data
Interlock ransomware claims Kettering Health breach, leaks stolen data The Interlock ransomware gang has claimed a recent cyberattack on the Kettering Health healthcare network and leaked data allegedly stolen from breached systems. […] Sergiu Gatlan Go to bleepingcomputer
-
US offers $10M for tips on state hackers tied to RedLine malware
US offers $10M for tips on state hackers tied to RedLine malware The U.S. Department of State has announced a reward of up to $10 million for any information on government-sponsored hackers with ties to the RedLine infostealer malware operation and its suspected creator, Russian national Maxim Alexandrovich Rudometov. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft unveils free EU cybersecurity program for governments
Microsoft unveils free EU cybersecurity program for governments Microsoft announced in Berlin today a new European Security Program that promises to bolster cybersecurity for European governments. […] Bill Toulas Go to bleepingcomputer
-
FBI: Play ransomware breached 900 victims, including critical orgs
FBI: Play ransomware breached 900 victims, including critical orgs In an update to a joint advisory with CISA and the Australian Cyber Security Centre, the FBI said that the Play ransomware gang had breached roughly 900 organizations as of May 2025, three times the number of victims reported in October 2023. […] Sergiu Gatlan Go…
-
OpenAI is hopeful GPT-5 will compete a little more
OpenAI is hopeful GPT-5 will compete a little more OpenAI’s next big foundational model is GPT-5, and the AI startup is hoping that the model will compete a little more with rivals. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT rolls out Memory upgrade for free users
ChatGPT rolls out Memory upgrade for free users ChatGPT’s memory feature is now better and capable of referencing past conversations for free accounts. […] Mayank Parmar Go to bleepingcomputer
-
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass
Hewlett Packard Enterprise warns of critical StoreOnce auth bypass Hewlett Packard Enterprise (HPE) has issued a security bulletin to warn about eight vulnerabilities impacting StoreOnce, its disk-based backup and deduplication solution. […] Bill Toulas Go to bleepingcomputer
-
Coinbase breach tied to bribed TaskUs support agents in India
Coinbase breach tied to bribed TaskUs support agents in India A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from outsourcing firm TaskUs, who threat actors bribed to steal data from the crypto exchange. […] Bill Toulas Go to bleepingcomputer
-
Microsoft adds quick machine recovery to Windows 11 settings
Microsoft adds quick machine recovery to Windows 11 settings Microsoft is testing a dedicated page in Windows Settings for quick machine recovery, which will provide users with additional configuration options. […] Sergiu Gatlan Go to bleepingcomputer
-
Cartier discloses data breach amid fashion brand cyberattacks
Cartier discloses data breach amid fashion brand cyberattacks Luxury fashion brand Cartier is warning customers it suffered a data breach that exposed customers’ personal information after its systems were compromised. […] Lawrence Abrams Go to bleepingcomputer
-
The North Face warns customers of April credential stuffing attack
The North Face warns customers of April credential stuffing attack Outdoor apparel retailer The North Face is warning customers that their personal information was stolen in credential stuffing attacks targeting the company’s website in April. […] Bill Toulas Go to bleepingcomputer
-
SentinelOne: Last week’s 7-hour outage caused by software flaw
SentinelOne: Last week’s 7-hour outage caused by software flaw American cybersecurity company SentinelOne revealed over the weekend that a software flaw triggered a seven-hour-long outage on Thursday. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August
Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August Google says it will no longer trust root CA certificates signed by Chunghwa Telecom and Netlock in the Chrome Root Store due to a pattern of compliance failures and failure to make improvements. […] Bill Toulas Go to bleepingcomputer
-
Microsoft and CrowdStrike partner to link hacking group names
Microsoft and CrowdStrike partner to link hacking group names Microsoft and CrowdStrike announced today that they’ve partnered to connect the aliases used for specific threat groups without actually using a single naming standard. […] Sergiu Gatlan Go to bleepingcomputer
-
Exploit details for max severity Cisco IOS XE flaw now public
Exploit details for max severity Cisco IOS XE flaw now public Technical details about a maximum-severity Cisco IOS XE WLC arbitrary file upload flaw tracked as CVE-2025-20188 have been made publicly available, bringing us closer to a working exploit. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting critical flaw in vBulletin forum software
Hackers are exploiting critical flaw in vBulletin forum software Two critical vulnerabilities affecting the open-source forum software vBulletin have been discovered, with one confirmed to be actively exploited in the wild. […] Bill Toulas Go to bleepingcomputer
-
Microsoft now testing Notepad text formatting in Windows 11
Microsoft now testing Notepad text formatting in Windows 11 Microsoft announced today that the Windows 11 Notepad application is getting a text formatting feature supporting Markdown-style input. […] Sergiu Gatlan Go to bleepingcomputer
-
Police takes down AVCheck site used by cybercriminals to scan malware
Police takes down AVCheck site used by cybercriminals to scan malware An international law enforcement operation has taken down AVCheck, a service used by cybercriminals to test whether their malware is detected by commercial antivirus software before deploying it in the wild. […] Bill Toulas Go to bleepingcomputer
-
Germany doxxes Conti ransomware and TrickBot ring leader
Germany doxxes Conti ransomware and TrickBot ring leader The Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) claims that Stern, the leader of the Trickbot and Conti cybercrime gangs, is a 36-year-old Russian named Vitaly Nikolaevich Kovalev. […] Sergiu Gatlan Go to bleepingcomputer
-
Getting Exposure Management Right: Insights from 500 CISOs
Getting Exposure Management Right: Insights from 500 CISOs Pentesting isn’t just about finding flaws — it’s about knowing which ones matter. Pentera’s 2025 State of Pentesting report uncovers which assets attackers target most, where security teams are making progress, and which exposures still fly under the radar. Focus on reducing breach impact, not just breach…
-
Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs
Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs Mozilla has rolled out an emergency Firefox 139.0.1 update after the Tuesday release caused graphical artifacts on PCs with NVIDIA GPUs. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft Authenticator now warns to export passwords before July cutoff
Microsoft Authenticator now warns to export passwords before July cutoff The Microsoft Authenticator app is now issuing notifications warning that the password autofill feature is being deprecated in July, suggesting users move to Microsoft Edge instead. […] Lawrence Abrams Go to bleepingcomputer
-
ConnectWise breached in cyberattack linked to nation-state hackers
ConnectWise breached in cyberattack linked to nation-state hackers IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers. […] Lawrence Abrams Go to bleepingcomputer
-
Threat actors abuse Google Apps Script in evasive phishing attacks
Threat actors abuse Google Apps Script in evasive phishing attacks Threat actors are abusing the trusted Google platform ‘Google Apps Script’ to host phishing pages, making them appear legitimate and eliminating the risk of them getting flagged by security tools. […] Bill Toulas Go to bleepingcomputer
-
Apple Safari exposes users to fullscreen browser-in-the-middle attacks
Apple Safari exposes users to fullscreen browser-in-the-middle attacks A weakness in Apple’s Safari web browser allows threat actors to leverage the fullscreen browser-in-the-middle (BitM) technique to steal account credentials from unsuspecting users. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Windows 11 might fail to start after installing KB5058405
Microsoft: Windows 11 might fail to start after installing KB5058405 Microsoft has confirmed that some Windows 11 systems might fail to start after installing the KB5058405 security update released during this month’s Patch Tuesday. […] Sergiu Gatlan Go to bleepingcomputer
-
Data broker LexisNexis discloses data breach affecting 364,000 people
Data broker LexisNexis discloses data breach affecting 364,000 people Data broker giant LexisNexis Risk Solutions has revealed that unknown attackers stole the personal information of over 364,000 individuals in a December breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5058481 update brings seconds back to calendar flyout
Windows 10 KB5058481 update brings seconds back to calendar flyout Microsoft has released the optional KB5058481 preview cumulative update for Windows 10 22H2 with seven changes, including restoring seconds to the time display in the calendar flyout for those who previously lost it. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5058499 update rolls out new Share and Click to Do features
Windows 11 KB5058499 update rolls out new Share and Click to Do features Microsoft has released the KB5058499 preview cumulative update for Windows 11 24H2 with forty-eight new features or changes, with many gradually rolling out, such as the new Windows Share feature and tje Click to Do Preview. […] Lawrence Abrams Go to bleepingcomputer
-
APT41 malware abuses Google Calendar for stealthy C2 communication
APT41 malware abuses Google Calendar for stealthy C2 communication The Chinese APT41 hacking group uses a new malware named ‘ToughProgress’ that abuses Google Calendar for command-and-control (C2) operations, hiding malicious activity behind a trusted cloud service. […] Bill Toulas Go to bleepingcomputer
-
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack
DragonForce ransomware abuses SimpleHelp in MSP supply chain attack The DragonForce ransomware operation successfully breached a managed service provider and used its SimpleHelp remote monitoring and management (RMM) platform to steal data and deploy encryptors on downstream customers’ systems. […] Lawrence Abrams Go to bleepingcomputer
-
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years
Iranian pleads guilty to RobbinHood ransomware attacks, faces 30 years An Iranian national has pleaded guilty to participating in the Robbinhood ransomware operation, which was used to breach the networks, steal data, and encrypt devices of U.S. cities and organizations in an attempt to extort millions of dollars over a five-year span. […] Lawrence Abrams Go to…
-
Not Every CVE Deserves a Fire Drill: Focus on What’s Exploitable
Not Every CVE Deserves a Fire Drill: Focus on What’s Exploitable Not every “critical” vulnerability is a critical risk. Picus Exposure Validation cuts through the noise by testing what’s actually exploitable in your environment — so you can patch what matters. […] Sponsored by Picus Security Go to bleepingcomputer
-
MATLAB dev confirms ransomware attack behind service outage
MATLAB dev confirms ransomware attack behind service outage MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. […] Sergiu Gatlan Go to bleepingcomputer
-
Russian Laundry Bear cyberspies linked to Dutch Police hack
Russian Laundry Bear cyberspies linked to Dutch Police hack A previously unknown Russian-backed cyberespionage group now tracked as Laundry Bear has been linked to a September 2024 Dutch police security breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows Server emergency update fixes Hyper-V VM freezes, restart issues
Windows Server emergency update fixes Hyper-V VM freezes, restart issues Microsoft has released an emergency update to address a known issue causing some Hyper-V virtual machines with Windows Server 2022 to freeze or restart unexpectedly. […] Sergiu Gatlan Go to bleepingcomputer
-
Adidas warns of data breach after customer service provider hack
Adidas warns of data breach after customer service provider hack German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and stole some customers’ data. […] Sergiu Gatlan Go to bleepingcomputer
-
Google claims users find ads in AI search ‘helpful’
Google claims users find ads in AI search ‘helpful’ Google AI mode and AI Overviews now have ads, which, according to the search engine giant, are “helpful.” […] Mayank Parmar Go to bleepingcomputer
-
OpenAI plans to ship an interesting ChatGPT product by 2026
OpenAI plans to ship an interesting ChatGPT product by 2026 OpenAI is planning to ship a new ChatGPT-powered product by 2026, but we aren’t looking at yet another model. […] Mayank Parmar Go to bleepingcomputer
-
Vibe coding company says Claude 4 reduced syntax errors by 25%
Vibe coding company says Claude 4 reduced syntax errors by 25% Lovable, which is a Vibe coding company, announced that Claude 4 has reduced its errors by 25% and made it faster by 40%. […] Mayank Parmar Go to bleepingcomputer
-
Leak suggests xAI is getting ready to ship Grok 3.5
Leak suggests xAI is getting ready to ship Grok 3.5 xAI, founded by Elon Musk, is preparing to launch Grok 3.5, the company’s next state-of-the-art AI model. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT Deep Research can now pull data from Dropbox and Box
ChatGPT Deep Research can now pull data from Dropbox and Box You can now connect your Box and Dropbox accounts to Deep Research on ChatGPT and pull data, which will be used by the AI to conduct research. […] Mayank Parmar Go to bleepingcomputer
-
Researchers claim ChatGPT o3 bypassed shutdown in controlled test
Researchers claim ChatGPT o3 bypassed shutdown in controlled test A new report claims that OpenAI’s o3 model altered a shutdown script to avoid being turned off, even when explicitly instructed to allow shutdown […] Mayank Parmar Go to bleepingcomputer
-
Glitch to end app hosting and user profiles on July 8
Glitch to end app hosting and user profiles on July 8 Glitch has announced it is ending app hosting and user profiles on July 8, 2025, responding to changing market dynamics and extensive abuse problems that have raised operational costs. […] Bill Toulas Go to bleepingcomputer
-
OpenAI confirms Operator Agent is now more accurate with o3
OpenAI confirms Operator Agent is now more accurate with o3 OpenAI says Operator Agent now uses the o3 model, which means it’s now significantly better at reasoning capabilities. […] Mayank Parmar Go to bleepingcomputer
-
Dozens of malicious packages on NPM collect host and network data
Dozens of malicious packages on NPM collect host and network data 60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor. […] Bill Toulas Go to bleepingcomputer
-
Hacker steals $223 million in Cetus Protocol cryptocurrency heist
Hacker steals $223 million in Cetus Protocol cryptocurrency heist The decentralized exchange Cetus Protocol announced that hackers have stolen $223 million in cryptocurrency and is offering a deal to stop all legal action if the funds are returned. […] Bill Toulas Go to bleepingcomputer
-
FBI warns of Luna Moth extortion attacks targeting law firms
FBI warns of Luna Moth extortion attacks targeting law firms The FBI warned that an extortion gang known as the Silent Ransom Group has been targeting U.S. law firms over the last two years in callback phishing and social engineering attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
TikTok videos now push infostealer malware in ClickFix attacks
TikTok videos now push infostealer malware in ClickFix attacks Cybercriminals are using TikTok videos to trick users into infecting themselves with Vidar and StealC information-stealing malware in ClickFix attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 Notepad gets AI-powered text writing capabilities
Windows 11 Notepad gets AI-powered text writing capabilities Microsoft is testing a new AI-powered text generation feature in Notepad that can let Windows Insiders create content based on custom prompts. […] Sergiu Gatlan Go to bleepingcomputer
-
Police takes down 300 servers in ransomware supply-chain crackdown
Police takes down 300 servers in ransomware supply-chain crackdown In the latest phase of Operation Endgame, an international law enforcement operation, national authorities from seven countries seized 300 servers and 650 domains used to launch ransomware attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Claude 4 benchmarks show improvements, but context is still 200K
Claude 4 benchmarks show improvements, but context is still 200K Today, OpenAI rival Anthropic announced Claude 4 models, which are significantly better than Claude 3 in benchmarks, but we’re left disappointed with the same 200,000 context window limit. […] Mayank Parmar Go to bleepingcomputer
-
US indicts leader of Qakbot botnet linked to ransomware attacks
US indicts leader of Qakbot botnet linked to ransomware attacks The U.S. government has indicted Russian national Rustam Rafailevich Gallyamov, the leader of the Qakbot botnet malware operation that compromised over 700,000 computers and enabled ransomware attacks. […] Ionut Ilascu Go to bleepingcomputer
-
Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE
Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE Critical vulnerabilities in Versa Concerto that are still unpatched could allow remote attackers to bypass authentication and execute arbitrary code on affected systems. […] Bill Toulas Go to bleepingcomputer
-
Anthropic web config hints at Claude Sonnet 4 and Opus 4
Anthropic web config hints at Claude Sonnet 4 and Opus 4 Anthropic is secretly working on two new models called Claude Sonnet 4 and Opus 4, which are believed to be the company’s most advanced AI models. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI hints at a big upgrade for ChatGPT Operator Agent
OpenAI hints at a big upgrade for ChatGPT Operator Agent ChatGPT’s Operator, which is still in research preview, will soon become a “very useful tool,” according to Jerry Tworek, VP of Research at OpenAI. […] Mayank Parmar Go to bleepingcomputer
-
Critical Samlify SSO flaw lets attackers log in as admin
Critical Samlify SSO flaw lets attackers log in as admin A critical Samlify authentication bypass vulnerability has been discovered that allows attackers to impersonate admin users by injecting unsigned malicious assertions into legitimately signed SAML responses. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers breach orgs to track aid routes to Ukraine
Russian hackers breach orgs to track aid routes to Ukraine A Russian state-sponsored cyberespionage campaign attributed to APT28 (Fancy Bear/Forest Blizzard) hackers has been targeting and compromising international organizations since 2022 to disrupt aid efforts to Ukraine. […] Ionut Ilascu Go to bleepingcomputer
-
Coinbase says recent data breach impacts 69,461 customers
Coinbase says recent data breach impacts 69,461 customers Coinbase, a cryptocurrency exchange with over 100 million customers, revealed that a recent data breach in which cybercriminals stole customer and corporate data affected 69,461 individuals […] Sergiu Gatlan Go to bleepingcomputer
-
PowerSchool hacker pleads guilty to student data extortion scheme
PowerSchool hacker pleads guilty to student data extortion scheme A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers. […] Lawrence Abrams Go to bleepingcomputer
-
Mobile carrier Cellcom confirms cyberattack behind extended outages
Mobile carrier Cellcom confirms cyberattack behind extended outages Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. […] Lawrence Abrams Go to bleepingcomputer
-
Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks
Premium WordPress ‘Motors’ theme vulnerable to admin takeover attacks A critical privilege escalation vulnerability has been discovered in the premium WordPress theme Motors, which allows unauthenticated attackers to hijack administrator accounts and take complete control of websites. […] Bill Toulas Go to bleepingcomputer
-
VanHelsing ransomware builder leaked on hacking forum
VanHelsing ransomware builder leaked on hacking forum The VanHelsing ransomware-as-a-service operation published the source code for its affiliate panel, data leak blog, and Windows encryptor builder after an old developer tried to sell it on the RAMP cybercrime forum. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI plans to combine multiple models into GPT-5
OpenAI plans to combine multiple models into GPT-5 OpenAI is planning to combine multiple products (features or models) into its next foundational model, which is called GPT-5. […] Mayank Parmar Go to bleepingcomputer
-
Fake KeePass password manager leads to ESXi ransomware attack
Fake KeePass password manager leads to ESXi ransomware attack Threat actors have been distributing trojanized versions of the KeePass password manager for at least eight months to install Cobalt Strike beacons, steal credentials, and ultimately, deploy ransomware on the breached network. […] Lawrence Abrams Go to bleepingcomputer
-
O2 UK patches bug leaking mobile user location from call metadata
O2 UK patches bug leaking mobile user location from call metadata A flaw in O2 UK’s implementation of VoLTE and WiFi Calling technologies could allow anyone to expose the general location of a person and other identifiers by calling the target. […] Bill Toulas Go to bleepingcomputer
-
Windows 10 emergency updates fix BitLocker recovery issues
Windows 10 emergency updates fix BitLocker recovery issues Microsoft has released out-of-band updates to fix a known issue causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Arla Foods confirms cyberattack disrupts production, causes delays
Arla Foods confirms cyberattack disrupts production, causes delays Arla Foods has confirmed to BleepingComputer that it was targeted by a cyberattack that has disrupted its production operations. […] Bill Toulas Go to bleepingcomputer
-
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender A new tool called ‘Defendnot’ can disable Microsoft Defender on Windows devices by registering a fake antivirus product, even when no real AV is installed. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft confirms May Windows 10 updates trigger BitLocker recovery
Microsoft confirms May Windows 10 updates trigger BitLocker recovery Microsoft has confirmed that some Windows 10 and Windows 10 Enterprise LTSC 2021 systems will boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Israel arrests new suspect behind Nomad Bridge $190M crypto hack
Israel arrests new suspect behind Nomad Bridge $190M crypto hack An American-Israeli national named Osei Morrell has been arrested in Israel for his alleged involvement in exploiting the Nomad bridge smart-contract in August 2022 that allowed hackers to siphon $190 million. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT rolls out Codex, an AI tool for software programming
ChatGPT rolls out Codex, an AI tool for software programming OpenAI is rolling out ‘Codex’ for ChatGPT, which is an AI agent that automates and delegates programming tasks for software engineers. […] Mayank Parmar Go to bleepingcomputer
-
Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own
Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own During the second day of Pwn2Own Berlin 2025, competitors earned $435,000 after exploiting zero-day bugs in multiple products, including Microsoft SharePoint, VMware ESXi, Oracle VirtualBox, Red Hat Enterprise Linux, and Mozilla Firefox. […] Sergiu Gatlan Go to bleepingcomputer
-
Printer maker Procolored offered malware-laced drivers for months
Printer maker Procolored offered malware-laced drivers for months For at least half a year, the official software supplied with Procolored printers included malware in the form of a remote access trojan and a cryptocurrency stealer. […] Bill Toulas Go to bleepingcomputer
-
US charges 12 more suspects linked to $230 million crypto theft
US charges 12 more suspects linked to $230 million crypto theft Twelve more suspects were charged in a RICO conspiracy for their alleged involvement in the theft of over $230 million in cryptocurrency and laundering the funds using crypto exchanges and mixing services. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags recently patched Chrome bug as actively exploited
CISA tags recently patched Chrome bug as actively exploited On Thursday, CISA warned U.S. federal agencies to secure their systems against ongoing attacks exploiting a high-severity vulnerability in the Chrome web browser. […] Sergiu Gatlan Go to bleepingcomputer
-
Leak confirms OpenAI’s ChatGPT will integrate MCP
Leak confirms OpenAI’s ChatGPT will integrate MCP ChatGPT is testing support for Model Context Protocol (MCP), which will allow the AI to connect to third-party services and use them as context. […] Mayank Parmar Go to bleepingcomputer