Tag: bleepingcomputer
-
Google plans to make Chrome for Android an agentic browser with Gemini
Google plans to make Chrome for Android an agentic browser with Gemini Google appears to be testing a new feature that integrates Gemini into Chrome for Android, allowing you to use agentic browser capabilities on your mobile device. […] Mayank Parmar Go to bleepingcomputer
-
Monroe University says 2024 data breach affects 320,000 people
Monroe University says 2024 data breach affects 320,000 people Monroe University revealed that threat actors stole the personal, financial, and health information of over 320,000 people after breaching its systems in a December 2024 cyberattack. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows 365 update blocks access to Cloud PC sessions
Microsoft: Windows 365 update blocks access to Cloud PC sessions Microsoft confirmed that a recent Windows 365 update is blocking customers from accessing their Microsoft 365 Cloud PC sessions. […] Sergiu Gatlan Go to bleepingcomputer
-
Ukraine’s army targeted in new charity-themed malware campaign
Ukraine’s army targeted in new charity-themed malware campaign Officials of Ukraine’s Defense Forces were targeted in a charity-themed campaign between October and December 2025 that delivered backdoor malware called PluggyApe. […] Bill Toulas Go to bleepingcomputer
-
New VoidLink malware framework targets Linux cloud servers
New VoidLink malware framework targets Linux cloud servers A newly discovered advanced cloud-native Linux malware framework named VoidLink focuses on cloud environments, providing attackers with custom loaders, implants, rootkits, and plugins designed for modern infrastructures. […] Bill Toulas Go to bleepingcomputer
-
Central Maine Healthcare breach exposed data of over 145,000 people
Central Maine Healthcare breach exposed data of over 145,000 people A data breach last year at Central Maine Healthcare (CMH) exposed sensitive information of more than 145,000 individuals. […] Bill Toulas Go to bleepingcomputer
-
Hacker gets seven years for breaching Rotterdam and Antwerp ports
Hacker gets seven years for breaching Rotterdam and Antwerp ports The Amsterdam Court of Appeal sentenced a 44-year-old Dutch national to seven years in prison for multiple crimes, including computer hacking and attempted extortion. […] Bill Toulas Go to bleepingcomputer
-
Facebook login thieves now using browser-in-browser trick
Facebook login thieves now using browser-in-browser trick Hackers over the past six months have relied increasingly more on the browser-in-the-browser (BitB) method to trick users into providing Facebook account credentials. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks
CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks CISA has ordered government agencies to secure their systems against a high-severity Gogs vulnerability that was exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
‘Bad actor’ hijacks Apex Legends characters in live matches
‘Bad actor’ hijacks Apex Legends characters in live matches Apex Legends players over the weekend experienced disruptions during live matches as threat actors hijacked their characters, disconnected them, and changed their nicknames. […] Bill Toulas Go to bleepingcomputer
-
University of Hawaii Cancer Center hit by ransomware attack
University of Hawaii Cancer Center hit by ransomware attack University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers. […] Sergiu Gatlan Go to bleepingcomputer
-
Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools Anthropic is bringing Claude for healthcare, following a similar move by OpenAI for ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
Instagram denies breach amid claims of 17 million account data leak
Instagram denies breach amid claims of 17 million account data leak Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online. […] Lawrence Abrams Go to bleepingcomputer
-
California bans data broker reselling health data of millions
California bans data broker reselling health data of millions The California Privacy Protection Agency (CalPrivacy) has taken action against the Datamasters marketing firm that sold the health and personal data of millions of users without being registered as a data broker. […] Bill Toulas Go to bleepingcomputer
-
Microsoft is retiring ‘Send to Kindle’ in Word
Microsoft is retiring ‘Send to Kindle’ in Word Microsoft is retiring a feature that allowed you to send your documents to Kindle straight from Microsoft Word. […] Mayank Parmar Go to bleepingcomputer
-
BreachForums hacking forum database leaked, exposing 324,000 accounts
BreachForums hacking forum database leaked, exposing 324,000 accounts The latest incarnation of the notorious BreachForums hacking forum has suffered a data breach, with its user database table leaked online. […] Lawrence Abrams Go to bleepingcomputer
-
Spain arrests 34 suspects linked to Black Axe cyber crime
Spain arrests 34 suspects linked to Black Axe cyber crime Authorities in Spain have arrested 34 individuals allegedly part of a criminal network involved in cyber fraud and believed to be connected to the Black Axe group responsible for illicit activities across Europe. […] Bill Toulas Go to bleepingcomputer
-
Ireland recalls almost 13,000 passports over missing ‘IRL’ code
Ireland recalls almost 13,000 passports over missing ‘IRL’ code Ireland’s Department of Foreign Affairs has recalled nearly 13,000 passports after a software update caused a printing defect. The printing error makes the documents non-compliant with international travel standards and potentially unreadable at automated border gates. […] Ax Sharma Go to bleepingcomputer
-
Anthropic: Viral Claude “Banned and reported to authorities” message isn’t real
Anthropic: Viral Claude “Banned and reported to authorities” message isn’t real Anthropic has denied reports of banning legitimate accounts, after a viral post on X claimed the creator of Claude had banned a user. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT tests a new feature to find jobs, improve your resume, and more
ChatGPT tests a new feature to find jobs, improve your resume, and more OpenAI is testing “Jobs,” a new feature that could help you explore roles, improve your resume, and plan your career. This feature is being tested after ChatGPT gained support for the Health dashboard. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft may soon allow IT admins to uninstall Copilot
Microsoft may soon allow IT admins to uninstall Copilot Microsoft is testing a new policy that allows IT administrators to uninstall the AI-powered Copilot digital assistant on managed devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers target misconfigured proxies to access paid LLM services
Hackers target misconfigured proxies to access paid LLM services Threat actors are systematically hunting for misconfigured proxy servers that could provide access to commercial large language model (LLM) services. […] Bill Toulas Go to bleepingcomputer
-
Illinois Department of Human Services data breach affects 700K people
Illinois Department of Human Services data breach affects 700K people The Illinois Department of Human Services (IDHS), one of Illinois’ largest state agencies, accidentally exposed the personal and health data of nearly 700,000 residents due to incorrect privacy settings. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA retires 10 emergency cyber orders in rare bulk closure
CISA retires 10 emergency cyber orders in rare bulk closure The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01. […] Lawrence Abrams Go to bleepingcomputer
-
Gmail’s new AI Inbox uses Gemini, but Google says it won’t train AI on user emails
Gmail’s new AI Inbox uses Gemini, but Google says it won’t train AI on user emails Google says it’s rolling out a new feature called ‘AI Inbox,’ which summarizes all your emails, but the company promises it won’t train its models on your emails. […] Mayank Parmar Go to bleepingcomputer
-
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert. […] Bill Toulas Go to bleepingcomputer
-
New China-linked hackers breach telcos using edge device exploits
New China-linked hackers breach telcos using edge device exploits A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe. […] Bill Toulas Go to bleepingcomputer
-
xAI teases major Grok upgrade, hints at Grok Code CLI
xAI teases major Grok upgrade, hints at Grok Code CLI Elon Musk-backed xAI has been missing in action for a while now, but today, Musk teased a major upgrade for Grok alongside new products. […] Mayank Parmar Go to bleepingcomputer
-
Cisco warns of Identity Service Engine flaw with exploit code
Cisco warns of Identity Service Engine flaw with exploit code Cisco has patched an ISE vulnerability with public proof-of-concept exploit code that can be abused by attackers with admin privileges. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA tags max severity HPE OneView flaw as actively exploited
CISA tags max severity HPE OneView flaw as actively exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a maximum-severity HPE OneView vulnerability as actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI says ChatGPT won’t use your health information to train its models
OpenAI says ChatGPT won’t use your health information to train its models OpenAI is rolling out ChatGPT Health, which is a dedicated space for health conversations. Amidst privacy concerns, OpenAI said it won’t use your health data. […] Mayank Parmar Go to bleepingcomputer
-
New GoBruteforcer attack wave targets crypto, blockchain projects
New GoBruteforcer attack wave targets crypto, blockchain projects A new wave of GoBruteforcer botnet malware attacks is targeting databases of cryptocurrency and blockchain projects on exposed servers believed to be configured using AI-generated examples. […] Bill Toulas Go to bleepingcomputer
-
Critical jsPDF flaw lets hackers steal secrets via generated PDFs
Critical jsPDF flaw lets hackers steal secrets via generated PDFs The jsPDF library for generating PDF documents in JavaScript applications is vulnerable to a critical vulnerability that allows an attacker to steal sensitive data from the local filesystem by including it in generated files. […] Bill Toulas Go to bleepingcomputer
-
OpenAI is rolling out GPT-5.2 “Codex-Max” for some users
OpenAI is rolling out GPT-5.2 “Codex-Max” for some users OpenAI is testing a new model for Codex called “GPT-5.2-Codex-Max,” and it’s already rolling out to users with a subscription. […] Mayank Parmar Go to bleepingcomputer
-
Taiwan says China’s attacks on its energy sector increased tenfold
Taiwan says China’s attacks on its energy sector increased tenfold The National Security Bureau in Taiwan says that China’s attacks on the country’s energy sector increased tenfold in 2025 compared to the previous year. […] Bill Toulas Go to bleepingcomputer
-
Microsoft cancels plans to rate limit Exchange Online bulk emails
Microsoft cancels plans to rate limit Exchange Online bulk emails Microsoft announced today that it has canceled plans to impose a daily limit of 2,000 external recipients on Exchange Online bulk email senders. […] Sergiu Gatlan Go to bleepingcomputer
-
Kimwolf Android botnet abuses residential proxies to infect internal devices
Kimwolf Android botnet abuses residential proxies to infect internal devices The Kimwolf botnet, an Android variant of the Aisuru malware, has grown to more than two million hosts, most of them infected by exploiting vulnerabilities in residential proxy networks to target devices on internal networks. […] Bill Toulas Go to bleepingcomputer
-
New D-Link flaw in legacy DSL routers actively exploited in attacks
New D-Link flaw in legacy DSL routers actively exploited in attacks Threat actors are exploiting a recently discovered command injection vulnerability that affects multiple D-Link DSL gateway routers that went out of support years ago. […] Bill Toulas Go to bleepingcomputer
-
Cloud file-sharing sites targeted for corporate data theft attacks
Cloud file-sharing sites targeted for corporate data theft attacks A threat actor known as Zestix has been offering to corporate data stolen from dozens of companies likely after breaching their ShareFile, Nextcloud, and OwnCloud instances. […] Bill Toulas Go to bleepingcomputer
-
ClickFix attack uses fake Windows BSOD screens to push malware
ClickFix attack uses fake Windows BSOD screens to push malware A new ClickFix social engineering campaign is targeting the hospitality sector in Europe, using fake Windows Blue Screen of Death (BSOD) screens to trick users into manually compiling and executing malware on their systems. […] Bill Toulas Go to bleepingcomputer
-
VSCode IDE forks expose users to “recommended extension” attacks
VSCode IDE forks expose users to “recommended extension” attacks Popular AI-powered integrated development environment solutions, such as Cursor, Windsurf, Google Antigravity, and Trae, recommend extensions that are non-existent in the OpenVSX registry, allowing threat actors to claim the namespace and upload malicious extensions. […] Bill Toulas Go to bleepingcomputer
-
US broadband provider Brightspeed investigates breach claims
US broadband provider Brightspeed investigates breach claims Brightspeed, one of the largest fiber broadband companies in the United States, is investigating security breach and data theft claims made by the Crimson Collective extortion gang. […] Sergiu Gatlan Go to bleepingcomputer
-
Ledger customers impacted by third-party Global-e data breach
Ledger customers impacted by third-party Global-e data breach Ledger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e. […] Bill Toulas Go to bleepingcomputer
-
Hackers claim to hack Resecurity, firm says it was a honeypot
Hackers claim to hack Resecurity, firm says it was a honeypot The ShinyHunters hacking group claims it breached the systems of cybersecurity firm Resecurity and stole internal data, while Resecurity says the attackers only accessed a deliberately deployed honeypot containing fake information used to monitor their activity. […] Lawrence Abrams Go to bleepingcomputer
-
Covenant Health says May data breach impacted nearly 478,000 patients
Covenant Health says May data breach impacted nearly 478,000 patients The Covenant Health organization has revised to nearly 500,000 the number of individuals affected by a data breach discovered last May. […] Ionut Ilascu Go to bleepingcomputer
-
Cryptocurrency theft attacks traced to 2022 LastPass breach
Cryptocurrency theft attacks traced to 2022 LastPass breach Blockchain investigation firm TRM Labs says ongoing cryptocurrency thefts have been traced to the 2022 LastPass breach, with attackers draining wallets years after encrypted vaults were stolen and laundering the crypto through Russian exchanges. […] Lawrence Abrams Go to bleepingcomputer
-
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass
Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass Over 10,000 Internet-exposed Fortinet firewalls are still vulnerable to attacks exploiting a five-year-old two-factor authentication (2FA) bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Google is testing a new image AI and it’s going to be its fastest model
Google is testing a new image AI and it’s going to be its fastest model Google is testing a new image AI model called “Nano Banana 2 Flash,” and it’s going to be as good as the Gemini 3 Pro Nano Banana, but it’ll be cheaper. […] Mayank Parmar Go to bleepingcomputer
-
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack
Trust Wallet links $8.5 million crypto theft to Shai-Hulud NPM attack Trust Wallet believes the compromise of its web browser to steal roughly $8.5 million from over 2,500 crypto wallets is likely related to an “industry-wide” Sha1-Hulud attack in November. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI is offering $20 ChatGPT Plus for free to some users
OpenAI is offering $20 ChatGPT Plus for free to some users If you’re already subscribed to ChatGPT Plus, which costs $20, you can request OpenAI to cancel your subscription, and it may offer one month of free usage. […] Mayank Parmar Go to bleepingcomputer
-
The biggest cybersecurity and cyberattack stories of 2025
The biggest cybersecurity and cyberattack stories of 2025 2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course, zero-day flaws exploited in breaches. Some stories, though, were more impactful or popular with our readers than others. This article explores 15 of the biggest cybersecurity stories…
-
New GlassWorm malware wave targets Macs with trojanized crypto wallets
New GlassWorm malware wave targets Macs with trojanized crypto wallets A fourth wave of the “GlassWorm” campaign is targeting macOS developers with malicious VSCode/OpenVSX extensions that deliver trojanized versions of crypto wallet applications. […] Bill Toulas Go to bleepingcomputer
-
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices
NYC mayoral inauguration bans Flipper Zero, Raspberry Pi devices New York City’s 2026 mayoral inauguration of Zohran Mamdani has published a list of banned items for the event, specifically prohibiting the Flipper Zero and Raspberry Pi devices. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers drain $3.9M from Unleash Protocol after multisig hijack
Hackers drain $3.9M from Unleash Protocol after multisig hijack The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals. […] Bill Toulas Go to bleepingcomputer
-
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
RondoDox botnet exploits React2Shell flaw to breach Next.js servers The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. […] Bill Toulas Go to bleepingcomputer
-
IBM warns of critical API Connect auth bypass vulnerability
IBM warns of critical API Connect auth bypass vulnerability IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely. […] Sergiu Gatlan Go to bleepingcomputer
-
Disney will pay $10 million to settle children’s data privacy lawsuit
Disney will pay $10 million to settle children’s data privacy lawsuit Disney has agreed to pay a $10 million civil penalty to settle claims that it violated the Children’s Online Privacy Protection Act by mislabeling videos and allowing data collection for targeted advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
New ErrTraffic service enables ClickFix attacks via fake browser glitches
New ErrTraffic service enables ClickFix attacks via fake browser glitches A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating ‘fake glitches’ on compromised websites to lure users into downloading payloads or following malicious instructions […] Bill Toulas Go to bleepingcomputer
-
European Space Agency confirms breach of “external servers”
European Space Agency confirms breach of “external servers” The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as “unclassified” information on collaborative engineering activities. […] Sergiu Gatlan Go to bleepingcomputer
-
Zoom Stealer browser extensions harvest corporate meeting intelligence
Zoom Stealer browser extensions harvest corporate meeting intelligence A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords. […] Bill Toulas Go to bleepingcomputer
-
US cybersecurity experts plead guilty to BlackCat ransomware attacks
US cybersecurity experts plead guilty to BlackCat ransomware attacks Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese state hackers use rootkit to hide ToneShell malware activity
Chinese state hackers use rootkit to hide ToneShell malware activity A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations. […] Bill Toulas Go to bleepingcomputer
-
Coupang to split $1.17 billion among 33.7 million data breach victims
Coupang to split $1.17 billion among 33.7 million data breach victims Coupang, the largest retailer in South Korea, announced $1.17 billion (1.685 trillion Won) total compensation for the 33.7 million customers whose information was exposed in the data breach discovered last month. […] Bill Toulas Go to bleepingcomputer
-
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads
Hacker arrested for KMSAuto malware campaign with 2.8 million downloads A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software. […] Bill Toulas Go to bleepingcomputer
-
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack
Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack Trust Wallet says attackers who compromised its browser extension right before Christmas have drained approximately $7 million from nearly 3,000 cryptocurrency wallet addresses. […] Sergiu Gatlan Go to bleepingcomputer
-
The Real-World Attacks Behind OWASP Agentic AI Top 10
The Real-World Attacks Behind OWASP Agentic AI Top 10 OWASP’s new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused.…
-
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed A severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web. […] Ionut Ilascu Go to bleepingcomputer
-
Hacker claims to leak WIRED database with 2.3 million records
Hacker claims to leak WIRED database with 2.3 million records A hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while also warning that they plan to release up to 40 million additional records for other Condé Nast properties. […] Lawrence Abrams Go to…
-
Massive Rainbow Six Siege breach gives players billions of credits
Massive Rainbow Six Siege breach gives players billions of credits Ubisoft’s Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players, manipulate in-game moderation feeds, and grant massive amounts of in-game currency and cosmetic items to accounts worldwide. […] Lawrence Abrams Go to bleepingcomputer
-
OpenAI’s ChatGPT ads will allegedly prioritize sponsored content in answers
OpenAI’s ChatGPT ads will allegedly prioritize sponsored content in answers OpenAI is reportedly mulling a new form of ads on ChatGPT called “sponsored content,” which could influence your buying decisions. […] Mayank Parmar Go to bleepingcomputer
-
Fake Grubhub emails promise tenfold return on sent cryptocurrency
Fake Grubhub emails promise tenfold return on sent cryptocurrency Grubhub users received fraudulent messages, apparently from a company email address, promising a tenfold bitcoin payout in return for a transfer to a specified wallet. […] Ionut Ilascu Go to bleepingcomputer
-
Trust Wallet confirms extension hack led to $7 million crypto theft
Trust Wallet confirms extension hack led to $7 million crypto theft Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.…
-
Trust Wallet Chrome extension hack tied to millions in losses
Trust Wallet Chrome extension hack tied to millions in losses Several users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers. […]…
-
ChatGPT’s new formatting blocks make its UI look more like a task tool
ChatGPT’s new formatting blocks make its UI look more like a task tool OpenAI has quietly rolled out ‘formatting blocks,’ which tweak GPT’s layout to match the UI of the task it is supposed to execute. […] Mayank Parmar Go to bleepingcomputer
-
Google will finally allow you to change your @gmail.com address
Google will finally allow you to change your @gmail.com address Google will finally allow you to change your @gmail address or create a new alias, according to a new support document. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI is reportedly testing Claude-like Skills for ChatGPT
OpenAI is reportedly testing Claude-like Skills for ChatGPT OpenAI is testing a new ChatGPT feature called “Skills,” which will be similar to Claude’s feature, also called Skills. […] Mayank Parmar Go to bleepingcomputer
-
Fake MAS Windows activation domain used to spread PowerShell malware
Fake MAS Windows activation domain used to spread PowerShell malware A typosquatted domain impersonating the Microsoft Activation Scripts (MAS) tool was used to distribute malicious PowerShell scripts that infect Windows systems with the ‘Cosmali Loader’. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to let admins block external users via Defender portal
Microsoft Teams to let admins block external users via Defender portal Microsoft announced that security administrators will soon be able to block external users from sending messages, calls, or meeting invitations to members of their organization via Teams. […] Sergiu Gatlan Go to bleepingcomputer
-
MongoDB warns admins to patch severe RCE flaw immediately
MongoDB warns admins to patch severe RCE flaw immediately MongoDB has warned IT admins to immediately patch a high-severity vulnerability that can be exploited in remote code execution (RCE) attacks targeting vulnerable servers. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI seizes domain storing bank credentials stolen from U.S. victims
FBI seizes domain storing bank credentials stolen from U.S. victims The U.S. government has seized the ‘web3adspanels.org’ domain and the associated database used by cybercriminals to host bank login credentials stolen in account takeover attacks. […] Bill Toulas Go to bleepingcomputer
-
WebRAT malware spread via fake vulnerability exploits on GitHub
WebRAT malware spread via fake vulnerability exploits on GitHub The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
Malicious extensions in Chrome Web store steal user credentials
Malicious extensions in Chrome Web store steal user credentials Two Chrome extensions in the Web Store named ‘Phantom Shuttle’ are posing as plugins for a proxy service to hijack user traffic and steal sensitive data. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams strengthens messaging security by default in January
Microsoft Teams strengthens messaging security by default in January Microsoft Teams will automatically enable messaging safety features by default in January to strengthen defenses against content tagged as malicious. […] Sergiu Gatlan Go to bleepingcomputer
-
Cyberattack knocks offline France’s postal, banking services
Cyberattack knocks offline France’s postal, banking services The French national postal service’s online services were knocked offline by “a major network incident” on Monday, disrupting digital banking and other services for millions. […] Sergiu Gatlan Go to bleepingcomputer
-
Italy fines Apple $116 million over App Store privacy policy issues
Italy fines Apple $116 million over App Store privacy policy issues Italy’s competition authority (AGCM) has fined Apple €98.6 million ($116 million) for using the App Tracking Transparency (ATT) privacy framework to abuse its dominant market position in mobile app advertising. […] Sergiu Gatlan Go to bleepingcomputer
-
Baker University says 2024 data breach impacts 53,000 people
Baker University says 2024 data breach impacts 53,000 people Baker University has disclosed a data breach after attackers gained access to its network one year ago and stole the personal, health, and financial information of over 53,000 individuals. […] Sergiu Gatlan Go to bleepingcomputer
-
Nissan says thousands of customers exposed in Red Hat breach
Nissan says thousands of customers exposed in Red Hat breach Nissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September. […] Bill Toulas Go to bleepingcomputer
-
New MacSync malware dropper evades macOS Gatekeeper checks
New MacSync malware dropper evades macOS Gatekeeper checks The latest variant of the MacSync information stealer targeting macOS systems is delivered through a digitally signed, notarized Swift application. […] Bill Toulas Go to bleepingcomputer
-
Interpol-led action decrypts 6 ransomware strains, arrests hundreds
Interpol-led action decrypts 6 ransomware strains, arrests hundreds An Interpol-coordinated initiative called Operation Sentinel led to the arrest of 574 individuals and the recovery of $3 million linked to business email compromise, extortion, and ransomware incidents. […] Bill Toulas Go to bleepingcomputer
-
Malicious npm package steals WhatsApp accounts and messages
Malicious npm package steals WhatsApp accounts and messages A malicious package in the Node Package Manager (NPM) registry poses as a legitimate WhatsApp Web API library to steal WhatsApp messages, collect contacts, and gain access to the account. […] Bill Toulas Go to bleepingcomputer
-
Ukrainian hacker admits affiliate role in Nefilim ransomware gang
Ukrainian hacker admits affiliate role in Nefilim ransomware gang A Ukrainian national pleaded guilty on Friday to conducting Nefilim ransomware attacks that targeted high-revenue businesses across the United States and other countries. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical RCE flaw impacts over 115,000 WatchGuard firewalls
Critical RCE flaw impacts over 115,000 WatchGuard firewalls Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Docker Hardened Images now open source and available for free
Docker Hardened Images now open source and available for free More than a 1,000 Docker Hardened Images (DHI) are now freely available and open source for software builders, under the Apache 2.0 license. […] Bill Toulas Go to bleepingcomputer
-
RansomHouse upgrades encryption with multi-layered data processing
RansomHouse upgrades encryption with multi-layered data processing The RansomHouse ransomware-as-a-service (RaaS) has recently upgraded its encryptor, switching from a relatively simple single-phase linear technique to a more complex, multi-layered method. […] Bill Toulas Go to bleepingcomputer
-
Microsoft confirms Teams is down and messages are delayed
Microsoft confirms Teams is down and messages are delayed Microsoft Teams is experiencing issues, with thousands reporting problems sending messages, including delays. […] Mayank Parmar Go to bleepingcomputer
-
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform The Nigerian police have arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing-as-a-service. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 accounts targeted in wave of OAuth phishing attacks
Microsoft 365 accounts targeted in wave of OAuth phishing attacks Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. […] Bill Toulas Go to bleepingcomputer
-
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. […] Bill Toulas Go to bleepingcomputer
-
Over 25,000 FortiCloud SSO devices exposed to remote attacks
Over 25,000 FortiCloud SSO devices exposed to remote attacks Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
FTC: Instacart to refund $60M over deceptive subscription tactics
FTC: Instacart to refund $60M over deceptive subscription tactics Grocery delivery service Instacart will refund $60 million to settle FTC claims that it misled customers with false advertising and unlawfully enrolled them in paid subscriptions. […] Sergiu Gatlan Go to bleepingcomputer