Tag: bleepingcomputer
-
Cyberattack takes down Ukrainian state railway’s online services
Cyberattack takes down Ukrainian state railway’s online services Ukrzaliznytsia, Ukraine’s national railway operator, has been hit by a massive cyberattack that disrupted online services for buying tickets both through mobile apps and the website. […] Bill Toulas Go to bleepingcomputer
-
DrayTek routers worldwide go into reboot loops over weekend
DrayTek routers worldwide go into reboot loops over weekend Many Internet service providers (ISPs) worldwide are alerting customers of an outage that started Saturday night and triggered DrayTek router connectivity problems. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese Weaver Ant hackers spied on telco network for 4 years
Chinese Weaver Ant hackers spied on telco network for 4 years A China-linked advanced threat group named Weaver Ant spent more than four years in the network of a telecommunications services provider, hiding traffic and infrastructure with the help of compromised Zyxel CPE routers. […] Bill Toulas Go to bleepingcomputer
-
Google Gemini’s Astra (screen sharing) rolls out on Android for some users
Google Gemini’s Astra (screen sharing) rolls out on Android for some users At MWC 2025, Google confirmed it was working on screen and video share capabilities for Gemini Live, codenamed “Project Astra”. At that time, Google promised that the feature would begin rolling out soon, and now some users have spotted it in the wild.…
-
FBI warnings are true—fake file converters do push malware
FBI warnings are true—fake file converters do push malware The FBI is warning that fake online document converters are being used to steal people’s information and, in worst-case scenarios, lead to ransomware attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Cloudflare now blocks all unencrypted traffic to its API endpoints
Cloudflare now blocks all unencrypted traffic to its API endpoints Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Trusted Signing service abused to code-sign malware
Microsoft Trusted Signing service abused to code-sign malware Cybercriminals are abusing Microsoft’s Trusted Signing platform to code-sign malware executables with short-lived three-day certificates. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Trust Signing service abused to code-sign malware
Microsoft Trust Signing service abused to code-sign malware Cybercriminals are abusing Microsoft’s Trusted Signing platform to code-sign malware executables with short-lived three-day certificates. […] Lawrence Abrams Go to bleepingcomputer
-
Coinbase was primary target of recent GitHub Actions breaches
Coinbase was primary target of recent GitHub Actions breaches Researchers have determined that Coinbase was the primary target in a recent GitHub Actions cascading supply chain attack that compromised secrets in hundreds of repositories. […] Lawrence Abrams Go to bleepingcomputer
-
Oracle denies breach after hacker claims theft of 6 million data records
Oracle denies breach after hacker claims theft of 6 million data records Oracle denies it was breached after a threat actor claimed to be selling 6 million data records allegedly stolen from the company’s Oracle Cloud federated SSO login servers […] Sergiu Gatlan Go to bleepingcomputer
-
Fake Semrush ads used to steal SEO professionals’ Google accounts
Fake Semrush ads used to steal SEO professionals’ Google accounts A new phishing campaign is targeting SEO professionals with malicious Semrush Google Ads that aim to steal their Google account credentials. […] Bill Toulas Go to bleepingcomputer
-
US removes sanctions against Tornado Cash crypto mixer
US removes sanctions against Tornado Cash crypto mixer The U.S. Department of Treasury announced today that it has removed sanctions against the Tornado Cash cryptocurrency mixer, which North Korean Lazarus hackers used to launder hundreds of millions stolen in multiple crypto heists. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Exchange Online bug mistakenly quarantines user emails
Microsoft: Exchange Online bug mistakenly quarantines user emails Microsoft is investigating an Exchange Online bug causing anti-spam systems to mistakenly quarantine some users’ emails. […] Sergiu Gatlan Go to bleepingcomputer
-
Veeam RCE bug lets domain users hack backup servers, patch now
Veeam RCE bug lets domain users hack backup servers, patch now Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations. […] Lawrence Abrams Go to bleepingcomputer
-
CISA tags NAKIVO backup flaw as actively exploited in attacks
CISA tags NAKIVO backup flaw as actively exploited in attacks CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO’s Backup & Replication software. […] Sergiu Gatlan Go to bleepingcomputer
-
VSCode extensions found downloading early-stage ransomware
VSCode extensions found downloading early-stage ransomware Two malicious VSCode Marketplace extensions were found deploying in-development ransomware from a remote server, exposing critical gaps in Microsoft’s review process. […] Bill Toulas Go to bleepingcomputer
-
Critical Cisco Smart Licensing Utility flaws now exploited in attacks
Critical Cisco Smart Licensing Utility flaws now exploited in attacks Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account. […] Sergiu Gatlan Go to bleepingcomputer
-
RansomHub ransomware uses new Betruger ‘multi-function’ backdoor
RansomHub ransomware uses new Betruger ‘multi-function’ backdoor Security researchers have linked a new backdoor dubbed Betruger, deployed in several recent ransomware attacks, to an affiliate of the RansomHub operation. […] Sergiu Gatlan Go to bleepingcomputer
-
Malware campaign ‘DollyWay’ breached 20,000 WordPress sites
Malware campaign ‘DollyWay’ breached 20,000 WordPress sites A malware operation dubbed ‘DollyWay’ has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2025.1a released with 1 new tool, annual theme refresh
Kali Linux 2025.1a released with 1 new tool, annual theme refresh Kali Linux has released version 2025.1a, the first version of 2025, with one new tool, desktop changes, and a theme refresh. […] Lawrence Abrams Go to bleepingcomputer
-
Pennsylvania education union data breach hit 500,000 people
Pennsylvania education union data breach hit 500,000 people The Pennsylvania State Education Association (PSEA), the largest public-sector union in Pennsylvania, is notifying over half a million individuals that attackers stole their personal information in a July 2024 security breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukrainian military targeted in new Signal spear-phishing attacks
Ukrainian military targeted in new Signal spear-phishing attacks Ukraine’s Computer Emergency Response Team (CERT-UA) is warning about highly targeted attacks employing compromised Signal accounts to send malware to employees of defense industry firms and members of the country’s army forces. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Exchange Online outage affects Outlook web users
Microsoft Exchange Online outage affects Outlook web users Microsoft is investigating an ongoing outage preventing Outlook on the web users from accessing their Exchange Online mailboxes. […] Sergiu Gatlan Go to bleepingcomputer
-
Sperm donation giant California Cryobank warns of a data breach
Sperm donation giant California Cryobank warns of a data breach US sperm donor giant California Cryobank is warning customers it suffered a data breach that exposed customers’ personal information. […] Lawrence Abrams Go to bleepingcomputer
-
GitHub Action hack likely led to another in cascading supply chain attack
GitHub Action hack likely led to another in cascading supply chain attack A cascading supply chain attack that began with the compromise of the “reviewdog/action-setup@v1” GitHub Action is believed to have led to the recent breach of “tj-actions/changed-files” that leaked CI/CD secrets. […] Bill Toulas Go to bleepingcomputer
-
Western Alliance Bank notifies 21,899 customers of data breach
Western Alliance Bank notifies 21,899 customers of data breach Arizona-based Western Alliance Bank is notifying nearly 22,000 customers their personal information was stolen in October after a third-party vendor’s secure file transfer software was breached. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious Android ‘Vapor’ apps on Google Play installed 60 million times
Malicious Android ‘Vapor’ apps on Google Play installed 60 million times Over 300 malicious Android applications downloaded 60 million items from Google Play acted as adware or attempted to steal credentials and credit card information. […] Bill Toulas Go to bleepingcomputer
-
New Windows zero-day exploited by 11 state hacking groups since 2017
New Windows zero-day exploited by 11 state hacking groups since 2017 At least 11 state-backed hacking groups from North Korea, Iran, Russia, and China have been exploiting a new Windows vulnerability in data theft and cyber espionage zero-day attacks since 2017. […] Sergiu Gatlan Go to bleepingcomputer
-
Telegram CEO leaves France temporarily as criminal probe continues
Telegram CEO leaves France temporarily as criminal probe continues French authorities have allowed Pavel Durov, Telegram’s CEO and founder, to temporarily leave the country while criminal activity on the messaging platform is still under investigation. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: New RAT malware used for crypto theft, reconnaissance
Microsoft: New RAT malware used for crypto theft, reconnaissance Microsoft has discovered a new remote access trojan (RAT) that employs “sophisticated techniques” to avoid detection, maintain persistence, and extract sensitive data. […] Sergiu Gatlan Go to bleepingcomputer
-
OKX suspends DEX aggregator after Lazarus hackers try to launder funds
OKX suspends DEX aggregator after Lazarus hackers try to launder funds OKX Web3 has decided to suspend its DEX aggregator services to implement security upgrades following reports of abuse by the notorious North Korean Lazarus hackers, who recently conducted a $1.5 billion crypto heist. […] Bill Toulas Go to bleepingcomputer
-
Supply chain attack on popular GitHub Action exposes CI/CD secrets
Supply chain attack on popular GitHub Action exposes CI/CD secrets A supply chain attack on the widely used ‘tj-actions/changed-files’ GitHub Action, used by 23,000 repositories, potentially allowed threat actors to steal CI/CD secrets from GitHub Actions build logs. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: March Windows updates mistakenly uninstall Copilot
Microsoft: March Windows updates mistakenly uninstall Copilot Microsoft says the March 2025 Windows cumulative updates automatically and mistakenly remove the AI-powered Copilot digital assistant from some Windows 10 and Windows 11 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts
Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake “Security Alert” issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code. […] Lawrence Abrams Go to bleepingcomputer
-
Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts
Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts Cybercriminals are promoting malicious Microsoft OAuth apps that masquerade as Adobe and DocuSign apps to deliver malware and steal Microsoft 365 accounts credentials. […] Bill Toulas Go to bleepingcomputer
-
New Akira ransomware decryptor cracks encryptions keys using GPUs
New Akira ransomware decryptor cracks encryptions keys using GPUs Security researcher Yohanes Nugroho has released a decryptor for the Linux variant of Akira ransomware, which utilizes GPU power to retrieve the decryption key and unlock files for free. […] Bill Toulas Go to bleepingcomputer
-
Coinbase phishing email tricks users with fake wallet migration
Coinbase phishing email tricks users with fake wallet migration A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers. […] Lawrence Abrams Go to bleepingcomputer
-
Week-long Exchange Online outage causes email failures, delays
Week-long Exchange Online outage causes email failures, delays Microsoft says it partially mitigated a week-long Exchange Online outage causing delays or failures when sending or receiving email messages. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gang creates tool to automate VPN brute-force attacks
Ransomware gang creates tool to automate VPN brute-force attacks The Black Basta ransomware operation created an automated brute-forcing framework dubbed ‘BRUTED’ to breach edge networking devices like firewalls and VPNs. […] Bill Toulas Go to bleepingcomputer
-
Cisco IOS XR vulnerability lets attackers crash BGP on routers
Cisco IOS XR vulnerability lets attackers crash BGP on routers Cisco has patched a denial of service (DoS) vulnerability that lets attackers crash the Border Gateway Protocol (BGP) process on IOS XR routers with a single BGP update message. […] Sergiu Gatlan Go to bleepingcomputer
-
Suspected LockBit ransomware dev extradited to United States
Suspected LockBit ransomware dev extradited to United States A dual Russian-Israeli national, suspected of being a key developer for the LockBit ransomware operation, has been extradited to the United States to face charges. […] Bill Toulas Go to bleepingcomputer
-
Microsoft apologizes for removing VSCode extensions used by millions
Microsoft apologizes for removing VSCode extensions used by millions Microsoft has reinstated the ‘Material Theme – Free’ and ‘Material Theme Icons – Free’ extensions on the Visual Studio Marketplace after finding that the obfuscated code they contained wasn’t actually malicious. […] Bill Toulas Go to bleepingcomputer
-
New SuperBlack ransomware exploits Fortinet auth bypass flaws
New SuperBlack ransomware exploits Fortinet auth bypass flaws A new ransomware operator named ‘Mora_001’ is exploiting two Fortinet vulnerabilities to gain unauthorized access to firewall appliances and deploy a custom ransomware strain dubbed SuperBlack. […] Bill Toulas Go to bleepingcomputer
-
Windows Notepad to get AI text summarization in Windows 11
Windows Notepad to get AI text summarization in Windows 11 Microsoft is now testing an AI-powered text summarization feature in Notepad and a Snipping Tool “Draw & Hold” feature that helps draw perfect shapes. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says button to restore classic Outlook is broken
Microsoft says button to restore classic Outlook is broken Microsoft is investigating a known issue that causes the new Outlook email client to crash when users click the “Go to classic Outlook” button, which should help them switch back to the classic Outlook. […] Sergiu Gatlan Go to bleepingcomputer
-
Juniper patches bug that let Chinese cyberspies backdoor routers
Juniper patches bug that let Chinese cyberspies backdoor routers Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access. […] Sergiu Gatlan Go to bleepingcomputer
-
Facebook discloses FreeType 2 flaw exploited in attacks
Facebook discloses FreeType 2 flaw exploited in attacks Facebook is warning that a FreeType vulnerability in all versions up to 2.13 can lead to arbitrary code execution, with reports that the flaw has been exploited in attacks. […] Bill Toulas Go to bleepingcomputer
-
CISA: Medusa ransomware hit over 300 critical infrastructure orgs
CISA: Medusa ransomware hit over 300 critical infrastructure orgs CISA says the Medusa ransomware operation has impacted over 300 organizations in critical infrastructure sectors in the United States until last month. […] Sergiu Gatlan Go to bleepingcomputer
-
New North Korean Android spyware slips onto Google Play
New North Korean Android spyware slips onto Google Play A new Android spyware named ‘KoSpy’ is linked to North Korean threat actors who have infiltrated Google Play and third-party app store APKPure through at least five malicious apps. […] Bill Toulas Go to bleepingcomputer
-
Garantex crypto exchange admin arrested while on vacation
Garantex crypto exchange admin arrested while on vacation Indian authorities arrested Aleksej Besciokov, the co-founder and one of the administrators of the Russian Garantex crypto-exchange while vacationing with his family in Varkala, India. […] Sergiu Gatlan Go to bleepingcomputer
-
Mozilla warns users to update Firefox before certificate expires
Mozilla warns users to update Firefox before certificate expires Mozilla is warning Firefox users to update their browsers to the latest version to avoid facing disruption and security risks caused by the upcoming expiration of one of the company’s root certificates. […] Bill Toulas Go to bleepingcomputer
-
North Korean Lazarus hackers infect hundreds via npm packages
North Korean Lazarus hackers infect hundreds via npm packages Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in “extremely sophisticated” attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5053606 update fixes broken SSH connections
Windows 10 KB5053606 update fixes broken SSH connections Microsoft has released the KB5053606 cumulative update for Windows 10 22H2 and Windows 10 21H2, which fixes numerous bugs, including one preventing SSH connections. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws Today is Microsoft’s March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5053598 & KB5053602 cumulative updates released
Windows 11 KB5053598 & KB5053602 cumulative updates released Microsoft has released Windows 11 KB5053598 and KB5053602 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
X hit by ‘massive cyberattack’ amid Dark Storm’s DDoS claims
X hit by ‘massive cyberattack’ amid Dark Storm’s DDoS claims The Dark Storm hacktivist group claims to be behind DDoS attacks causing multiple X worldwide outages on Monday, leading the company to enable DDoS protections from Cloudflare. […] Lawrence Abrams Go to bleepingcomputer
-
US govt says Americans lost record $12.5 billion to fraud in 2024
US govt says Americans lost record $12.5 billion to fraud in 2024 The U.S. Federal Trade Commission (FTC) said today that Americans lost a record $12.5 billion to fraud last year, a 25% increase over the previous year. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft shares guidance on upcoming Publisher deprecation
Microsoft shares guidance on upcoming Publisher deprecation Microsoft has published guidance for users of Microsoft Publisher as it will no longer be supported after October 2026 and removed from Microsoft 365. […] Bill Toulas Go to bleepingcomputer
-
FTC will send $25.5 million to victims of tech support scams
FTC will send $25.5 million to victims of tech support scams Later this week, the Federal Trade Commission (FTC) will start distributing over $25.5 million in refunds to those misled by tech support companies Restoro and Reimage’s scare tactics. […] Sergiu Gatlan Go to bleepingcomputer
-
Swiss critical sector faces new 24-hour cyberattack reporting rule
Swiss critical sector faces new 24-hour cyberattack reporting rule Switzerland’s National Cybersecurity Centre (NCSC) has announced a new reporting obligation for critical infrastructure organizations in the country, requiring them to report cyberattacks to the agency within 24 hours of their discovery. […] Bill Toulas Go to bleepingcomputer
-
US cities warn of wave of unpaid parking phishing texts
US cities warn of wave of unpaid parking phishing texts US cities are warning of an ongoing mobile phishing campaign pretending to be texts from the city’s parking violation departments about unpaid parking invoices, that if unpaid, will incur an additional $35 fine per day. […] Lawrence Abrams Go to bleepingcomputer
-
New Chirp tool uses audio tones to transfer data between devices
New Chirp tool uses audio tones to transfer data between devices A new open-source tool named ‘Chirp’ transmits data, such as text messages, between computers (and smartphones) through different audio tones. […] Bill Toulas Go to bleepingcomputer
-
Developer guilty of using kill switch to sabotage employer’s systems
Developer guilty of using kill switch to sabotage employer’s systems A software developer has been found guilty of sabotaging his ex-employer’s systems by running custom malware and installing a “kill switch” after being demoted at the company. […] Lawrence Abrams Go to bleepingcomputer
-
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
Undocumented “backdoor” found in Bluetooth chip used by a billion devices The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented “backdoor” that could be leveraged for attacks. […] Bill Toulas Go to bleepingcomputer
-
YouTubers extorted via copyright strikes to spread malware
YouTubers extorted via copyright strikes to spread malware Cybercriminals are sending bogus copyright claims to YouTubers to coerce them into promoting malware and cryptocurrency miners on their videos. […] Bill Toulas Go to bleepingcomputer
-
US seizes $23 million in crypto stolen via password manager breach
US seizes $23 million in crypto stolen via password manager breach U.S. authorities have seized over $23 million in cryptocurrency linked to the theft of $150 million from a Ripple crypto wallet in January 2024. Investigators believe hackers who breached LastPass in 2022 were behind the attack. […] Sergiu Gatlan Go to bleepingcomputer
-
Unpatched Edimax IP camera flaw actively exploited in botnet attacks
Unpatched Edimax IP camera flaw actively exploited in botnet attacks A critical command injection vulnerability impacting the Edimax IC-7100 IP camera is currently being exploited by botnet malware to compromise devices. […] Bill Toulas Go to bleepingcomputer
-
Employee charged with stealing unreleased movies, sharing them online
Employee charged with stealing unreleased movies, sharing them online A Memphis man was arrested and charged with stealing DVDs and Blu-ray discs of unreleased movies and sharing ripped digital copies online before their release. […] Sergiu Gatlan Go to bleepingcomputer
-
US charges Garantex admins with money laundering, sanctions violations
US charges Garantex admins with money laundering, sanctions violations The administrators of the Russian Garantex crypto-exchange have been charged in the United States with facilitating money laundering for criminal organizations and violating sanctions. […] Sergiu Gatlan Go to bleepingcomputer
-
Data breach at Japanese telecom giant NTT hits 18,000 companies
Data breach at Japanese telecom giant NTT hits 18,000 companies Japanese telecommunication services provider NTT Communications Corporation (NTT) is warning almost 18,000 corporate customers that their information was compromised during a cybersecurity incident. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says malvertising campaign impacted 1 million PCs
Microsoft says malvertising campaign impacted 1 million PCs Microsoft has taken down an undisclosed number of GitHub repositories used in a massive malvertising campaign that impacted almost one million devices worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gang encrypted network from a webcam to bypass EDR
Ransomware gang encrypted network from a webcam to bypass EDR The Akira ransomware gang was spotted using an unsecured webcam to launch encryption attacks on a victim’s network, effectively circumventing Endpoint Detection and Response (EDR), which was blocking the encryptor in Windows. […] Bill Toulas Go to bleepingcomputer
-
US seizes domain of Garantex crypto exchange used by ransomware gangs
US seizes domain of Garantex crypto exchange used by ransomware gangs The U.S. Secret Service has seized the domain of the sanctioned Russian cryptocurrency exchange Garantex in collaboration with the Department of Justice’s Criminal Division, the FBI, and Europol. […] Sergiu Gatlan Go to bleepingcomputer
-
Cybercrime ‘crew’ stole $635,000 in Taylor Swift concert tickets
Cybercrime ‘crew’ stole $635,000 in Taylor Swift concert tickets New York prosecutors say that two people working at a third-party contractor for the StubHub online ticket marketplace made $635,000 after almost 1,000 concert tickets and reselling them online. […] Sergiu Gatlan Go to bleepingcomputer
-
Ethereum private key stealer on PyPI downloaded over 1,000 times
Ethereum private key stealer on PyPI downloaded over 1,000 times A malicious Python Package Index (PyPI) package named “set-utils” has been stealing Ethereum private keys through intercepted wallet creation functions and exfiltrating them via the Polygon blockchain. […] Bill Toulas Go to bleepingcomputer
-
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks
Open-source tool ‘Rayhunter’ helps users detect Stingray attacks The Electronic Frontier Foundation (EFF) has released a free, open-source tool named Rayhunter that is designed to detect cell-site simulators (CSS), also known as IMSI catchers or Stingrays. […] Bill Toulas Go to bleepingcomputer
-
Silk Typhoon hackers now target IT supply chains to breach networks
Silk Typhoon hackers now target IT supply chains to breach networks Microsoft warns that Chinese cyber-espionage threat group ‘Silk Typhoon’ has shifted its tactics, now targeting remote management tools and cloud services in supply chain attacks that give them access to downstream customers. […] Bill Toulas Go to bleepingcomputer
-
US charges Chinese hackers linked to critical infrastructure breaches
US charges Chinese hackers linked to critical infrastructure breaches The US Justice Department has charged Chinese state security officers along with APT27 and i-Soon hackers for network breaches and cyberattacks that have targeted victims globally since 2011. […] Sergiu Gatlan Go to bleepingcomputer
-
BadBox malware disrupted on 500K infected Android devices
BadBox malware disrupted on 500K infected Android devices The BadBox Android malware botnet has been disrupted again by removing 24 malicious apps from Google Play and sinkholing communications for half a million infected devices. […] Bill Toulas Go to bleepingcomputer
-
YouTube warns of AI-generated video of its CEO used in phishing attacks
YouTube warns of AI-generated video of its CEO used in phishing attacks YouTube warns that scammers are using an AI-generated video featuring the company’s CEO in phishing attacks to steal creators’ credentials. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake BianLian ransom notes mailed to US CEOs in postal mail scam
Fake BianLian ransom notes mailed to US CEOs in postal mail scam Scammers are impersonating the BianLian ransomware gang in fake ransom notes sent to US companies via snail mail through the United States Postal Service. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware
Microsoft Teams tactics, malware connect Black Basta, Cactus ransomware New research has uncovered further links between the Black Basta and Cactus ransomware gangs, with members of both groups utilizing the same social engineering attacks and the BackConnect proxy malware for post-exploitation access to corporate networks. […] Lawrence Abrams Go to bleepingcomputer
-
New Eleven11bot botnet infects 86,000 devices for DDoS attacks
New Eleven11bot botnet infects 86,000 devices for DDoS attacks A new botnet malware named ‘Eleven11bot’ has infected over 86,000 IoT devices, primarily security cameras and network video recorders (NVRs), to conduct DDoS attacks. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of Webex for BroadWorks flaw exposing credentials
Cisco warns of Webex for BroadWorks flaw exposing credentials Cisco warned customers today of a vulnerability in Webex for BroadWorks that could let unauthenticated attackers access credentials remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Google expands Android AI scam detection to more Pixel devices
Google expands Android AI scam detection to more Pixel devices Google has announced an increased rollout of new AI-powered scam detection features on Android to help protect users from increasingly sophisticated phone and text social engineering scams. […] Bill Toulas Go to bleepingcomputer
-
Rubrik rotates authentication keys after log server breach
Rubrik rotates authentication keys after log server breach Rubrik disclosed last month that one of its servers hosting log files was breached, causing the company to rotate potentially leaked authentication keys. […] Lawrence Abrams Go to bleepingcomputer
-
DHS says CISA will not stop monitoring Russian cyber threats
DHS says CISA will not stop monitoring Russian cyber threats The US Cybersecurity and Infrastructure Security Agency says that media reports about it being directed to no longer follow or report on Russian cyber activity are untrue, and its mission remains unchanged. […] Lawrence Abrams Go to bleepingcomputer
-
New Microsoft 365 outage impacts Teams, causes call failures
New Microsoft 365 outage impacts Teams, causes call failures Microsoft is investigating a new Microsoft 365 outage that is affecting Teams customers and causing call failures. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags Windows, Cisco vulnerabilities as actively exploited
CISA tags Windows, Cisco vulnerabilities as actively exploited CISA has warned US federal agencies to secure their systems against attacks exploiting vulnerabilities in Cisco and Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint
New ClickFix attack deploys Havoc C2 via Microsoft Sharepoint A newly uncovered ClickFix phishing campaign is tricking victims into executing malicious PowerShell commands that deploy the Havok post-exploitation framework for remote access to compromised devices. […] Lawrence Abrams Go to bleepingcomputer
-
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows. […] Bill Toulas Go to bleepingcomputer
-
U.S. recovers $31 million stolen in 2021 Uranium Finance hack
U.S. recovers $31 million stolen in 2021 Uranium Finance hack U.S. authorities recovered $31 million in cryptocurrency stolen in 2021 cyberattacks on Uranium Finance, a Binance Smart Chain-based DeFi protocol. […] Bill Toulas Go to bleepingcomputer
-
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data
Qilin ransomware claims attack at Lee Enterprises, leaks stolen data The Qilin ransomware gang has claimed responsibility for the attack at Lee Enterprises that disrupted operations on February 3, leaking samples of data they claim was stolen from the company. […] Bill Toulas Go to bleepingcomputer
-
Police arrests suspects tied to AI-generated CSAM distribution ring
Police arrests suspects tied to AI-generated CSAM distribution ring Law enforcement agencies from 19 countries have arrested 25 suspects linked to a criminal ring that was distributing child sexual abuse material (CSAM) generated using artificial intelligence (AI). […] Sergiu Gatlan Go to bleepingcomputer
-
Serbian police used Cellebrite zero-day hack to unlock Android phones
Serbian police used Cellebrite zero-day hack to unlock Android phones Serbian authorities have reportedly used an Android zero-day exploit chain developed by Cellebrite to unlock the device of a student activist in the country and attempt to install spyware. […] Bill Toulas Go to bleepingcomputer
-
Microsoft confirms it’s killing off Skype in May, after 14 years
Microsoft confirms it’s killing off Skype in May, after 14 years Microsoft has confirmed that the Skype video call and messaging service will be shut down in May, 14 years after replacing the Windows Live Messenger. […] Sergiu Gatlan Go to bleepingcomputer
-
Vo1d malware botnet grows to 1.6 million Android TVs worldwide
Vo1d malware botnet grows to 1.6 million Android TVs worldwide A new variant of the Vo1d malware botnet has grown to 1,590,299 infected Android TV devices across 226 countries, recruiting devices as part of anonymous proxy server networks. […] Bill Toulas Go to bleepingcomputer
-
Privacy tech firms warn France’s encryption and VPN laws threaten privacy
Privacy tech firms warn France’s encryption and VPN laws threaten privacy Privacy-focused email provider Tuta (previously Tutanota) and the VPN Trust Initiative (VTI) are raising concerns over proposed laws in France set to backdoor encrypted messaging systems and restrict internet access. […] Bill Toulas Go to bleepingcomputer
-
Microsoft names cybercriminals behind AI deepfake network
Microsoft names cybercriminals behind AI deepfake network Microsoft has named multiple threat actors part of a cybercrime gang accused of developing malicious tools capable of bypassing generative AI guardrails to generate celebrity deepfakes and other illicit content. […] Sergiu Gatlan Go to bleepingcomputer