Tag: bleepingcomputer
-
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform
Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform The Nigerian police have arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing-as-a-service. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 accounts targeted in wave of OAuth phishing attacks
Microsoft 365 accounts targeted in wave of OAuth phishing attacks Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. […] Bill Toulas Go to bleepingcomputer
-
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks that can bypass early-boot memory protections. […] Bill Toulas Go to bleepingcomputer
-
Over 25,000 FortiCloud SSO devices exposed to remote attacks
Over 25,000 FortiCloud SSO devices exposed to remote attacks Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting a critical authentication bypass vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
FTC: Instacart to refund $60M over deceptive subscription tactics
FTC: Instacart to refund $60M over deceptive subscription tactics Grocery delivery service Instacart will refund $60 million to settle FTC claims that it misled customers with false advertising and unlawfully enrolled them in paid subscriptions. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues
Windows 10 OOB update released to fix Message Queuing (MSMQ) issues This month’s extended security update for Windows 11 broke Message Queuing (MSMQ), which is typically used by enterprises to manage background tasks. […] Mayank Parmar Go to bleepingcomputer
-
University of Sydney suffers data breach exposing student and staff info
University of Sydney suffers data breach exposing student and staff info Hackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal information of staff and students. […] Bill Toulas Go to bleepingcomputer
-
Clop ransomware targets Gladinet CentreStack in data theft attacks
Clop ransomware targets Gladinet CentreStack in data theft attacks The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign. […] Sergiu Gatlan Go to bleepingcomputer
-
New password spraying attacks target Cisco, PAN VPN gateways
New password spraying attacks target Cisco, PAN VPN gateways An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN. […] Bill Toulas Go to bleepingcomputer
-
France arrests suspect tied to cyberattack on Interior Ministry
France arrests suspect tied to cyberattack on Interior Ministry French authorities arrested a 22-year-old suspect on Tuesday for a cyberattack that targeted France’s Ministry of the Interior earlier this month. […] Lawrence Abrams Go to bleepingcomputer
-
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
Zeroday Cloud hacking event awards $320,0000 for 11 zero days The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
Amazon: Ongoing cryptomining campaign uses hacked AWS accounts Amazon’s AWS GuardDuty security team is warning of an ongoing crypto-mining campaign that targets its Elastic Compute Cloud (EC2) and Elastic Container Service (ECS) using compromised credentials for Identity and Access Management (IAM). […] Bill Toulas Go to bleepingcomputer
-
WhatsApp device linking abused in account hijacking attacks
WhatsApp device linking abused in account hijacking attacks Threat actors are abusing the legitimate device-linking feature to hijack WhatsApp accounts via pairing codes in a campaign dubbed GhostPairing. […] Bill Toulas Go to bleepingcomputer
-
Cisco warns of unpatched AsyncOS zero-day exploited in attacks
Cisco warns of unpatched AsyncOS zero-day exploited in attacks Cisco warned customers today of an unpatched, maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. […] Sergiu Gatlan Go to bleepingcomputer
-
Cellik Android malware builds malicious versions from Google Play apps
Cellik Android malware builds malicious versions from Google Play apps A new Android malware-as-a-service (MaaS) named Cellik is being advertised on underground cybercrime forums offering a robust set of capabilities that include the option to embed it in any app available on the Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
GhostPoster attacks hide malicious JavaScript in Firefox addon logos
GhostPoster attacks hide malicious JavaScript in Firefox addon logos A new campaign dubbed ‘GhostPoster’ is hiding JavaScript code in the image logo of malicious Firefox extensions counting more than 50,000 downloads, to monitor browser activity and plant a backdoor. […] Bill Toulas Go to bleepingcomputer
-
Texas sues TV makers for taking screenshots of what people watch
Texas sues TV makers for taking screenshots of what people watch The Texas Attorney General sued five major television manufacturers, accusing them of illegally collecting their users’ data by secretly recording what they watch using Automated Content Recognition (ACR) technology. […] Sergiu Gatlan Go to bleepingcomputer
-
Amazon disrupts Russian GRU hackers attacking edge network devices
Amazon disrupts Russian GRU hackers attacking edge network devices The Amazon Threat Intelligence team has disrupted active operations attributed to hackers working for the Russian foreign military intelligence agency, the GRU, who targeted customers’ cloud infrastructure. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit newly patched Fortinet auth bypass flaws
Hackers exploit newly patched Fortinet auth bypass flaws Hackers are exploiting critical-severity vulnerabilities affecting multiple Fortinet products to get unauthorized access to admin accounts and steal system configuration files. […] Bill Toulas Go to bleepingcomputer
-
SoundCloud confirms breach after member data stolen, VPN access disrupted
SoundCloud confirms breach after member data stolen, VPN access disrupted Audio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database exposing users’ email addresses and profile information. […] Lawrence Abrams Go to bleepingcomputer
-
Google is shutting down its dark web report feature in January
Google is shutting down its dark web report feature in January Google is discontinuing its “dark web report” security tool, stating that it wants to focus on other tools it believes are more helpful. […] Mayank Parmar Go to bleepingcomputer
-
Askul confirms theft of 740k customer records in ransomware attack
Askul confirms theft of 740k customer records in ransomware attack Japanese e-commerce giant Askul Corporation has confirmed that RansomHouse hackers stole around 740,000 customer records in the ransomware attack it suffered in October. […] Bill Toulas Go to bleepingcomputer
-
New SantaStealer malware steals data from browsers, crypto wallets
New SantaStealer malware steals data from browsers, crypto wallets A new malware-as-a-service (MaaS) information stealer named SantaStealer is being advertised on Telegram and hacker forums as operating in memory to avoid file-based detection. […] Bill Toulas Go to bleepingcomputer
-
PornHub extorted after hackers steal Premium member activity data
PornHub extorted after hackers steal Premium member activity data Adult video platform PornHub is being extorted by the ShinyHunters extortion gang after the search and watch history of its Premium members was reportedly stolen in a recent Mixpanel data breach. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: December security updates cause Message Queuing failures
Microsoft: December security updates cause Message Queuing failures Microsoft has confirmed that the December 2025 security updates are breaking Message Queuing (MSMQ) functionality, affecting enterprise applications and Internet Information Services (IIS) websites. […] Sergiu Gatlan Go to bleepingcomputer
-
Beware: PayPal subscriptions abused to send fake purchase emails
Beware: PayPal subscriptions abused to send fake purchase emails An email scam is abusing abusing PayPal’s “Subscriptions” billing feature to send legitimate PayPal emails that contain fake purchase notifications embedded in the Customer service URL field. […] Lawrence Abrams Go to bleepingcomputer
-
CyberVolk’s ransomware debut stumbles on cryptography weakness
CyberVolk’s ransomware debut stumbles on cryptography weakness The pro-Russia hacktivist group CyberVolk launched a ransomware-as-a-service (RaaS) called VolkLocker that suffered from serious implementation flaws, allowing victims to potentially decrypt files for free. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks
Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
Coupang data breach traced to ex-employee who retained system access
Coupang data breach traced to ex-employee who retained system access A data breach at Coupang that exposed the information of 33.7 million customers has been tied to a former employee who retained access to internal systems after leaving the company. […] Bill Toulas Go to bleepingcomputer
-
Fake ‘One Battle After Another’ torrent hides malware in subtitles
Fake ‘One Battle After Another’ torrent hides malware in subtitles A fake torrent for Leonardo DiCaprio’s ‘One Battle After Another’ hides malicious PowerShell malware loaders inside subtitle files that ultimately infect devices with the Agent Tesla RAT malware. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2025.4 released with 3 new tools, desktop updates
Kali Linux 2025.4 released with 3 new tools, desktop updates Kali Linux has released version 2025.4, its final update of the year, introducing three new hacking tools, desktop environment improvements, the preview of Wifipumpkin3 in NetHunter, and enhanced Wayland support. […] Lawrence Abrams Go to bleepingcomputer
-
Shadow spreadsheets: The security gap your tools can’t see
Shadow spreadsheets: The security gap your tools can’t see When official systems can’t support everyday workflows, employees turn to spreadsheets — creating “shadow spreadsheets” that circulate unchecked. Grist shows how these spreadsheets expose sensitive data, create version sprawl, and remove the audit trails security teams depend on. […] Sponsored by Grist Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Geoserver flaw
CISA orders feds to patch actively exploited Geoserver flaw CISA has ordered U.S. federal agencies to patch a critical GeoServer vulnerability now actively exploited in XML External Entity (XXE) injection attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
MITRE shares 2025’s top 25 most dangerous software weaknesses
MITRE shares 2025’s top 25 most dangerous software weaknesses MITRE has shared this year’s top 25 list of the most dangerous software weaknesses behind over 39,000 security vulnerabilities disclosed between June 2024 and June 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
MKVCinemas streaming piracy service with 142M visits shuts down
MKVCinemas streaming piracy service with 142M visits shuts down An anti-piracy coalition has dismantled one of India’s most popular streaming piracy services, which has provided free access to movies and TV shows to millions over the past two years. […] Sergiu Gatlan Go to bleepingcomputer
-
Brave browser starts testing agentic AI mode for automated tasks
Brave browser starts testing agentic AI mode for automated tasks Brave has introduced a new AI browsing feature that leverages Leo, its privacy-respecting AI assistant, to perform automated tasks for the user. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet’s CentreStack and Triofox products for secure remote file access and sharing. […] Bill Toulas Go to bleepingcomputer
-
Google fixes eighth Chrome zero-day exploited in attacks in 2025
Google fixes eighth Chrome zero-day exploited in attacks in 2025 Google has released emergency updates to fix another Chrome zero-day vulnerability exploited in the wild, marking the eighth such security flaw patched since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware A new AMOS infostealer campaign is abusing Google search ads to lure users into Grok and ChatGPT conversations that appear to offer “helpful” instructions but ultimately lead to installing the AMOS info-stealing malware on macOS. […] Bill Toulas Go to bleepingcomputer
-
New DroidLock malware locks Android devices and demands a ransom
New DroidLock malware locks Android devices and demands a ransom A new Android malware called DroidLock has emerged with capabilities to lock screens for ransom payments, erase data, access text messages, call logs, contacts, and audio data. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams to warn of suspicious traffic with external domains
Microsoft Teams to warn of suspicious traffic with external domains Microsoft is working on a new Teams security feature that will analyze suspicious traffic with external domains to help IT administrators tackle potential security threats. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 10,000 Docker Hub images found leaking credentials, auth keys
Over 10,000 Docker Hub images found leaking credentials, auth keys More than 10,000 Docker Hub container images expose data that should be protected, including live credentials to production systems, CI/CD databases, or LLM model keys. […] Bill Toulas Go to bleepingcomputer
-
SAP fixes three critical vulnerabilities across multiple products
SAP fixes three critical vulnerabilities across multiple products SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws. […] Bill Toulas Go to bleepingcomputer
-
Windows PowerShell now warns when running Invoke-WebRequest scripts
Windows PowerShell now warns when running Invoke-WebRequest scripts Microsoft says Windows PowerShell now warns when running scripts that use the Invoke-WebRequest cmdlet to download web content, aiming to prevent potentially risky code from executing. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5071546 extended security update
Microsoft releases Windows 10 KB5071546 extended security update Microsoft has released the KB5071546 extended security update to resolve 57 security vulnerabilities, including three zero-day flaws. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws
Microsoft December 2025 Patch Tuesday fixes 3 zero-days, 57 flaws Microsoft’s December 2025 Patch Tuesday fixes 57 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Fortinet warns of critical FortiCloud SSO login auth bypass flaws
Fortinet warns of critical FortiCloud SSO login auth bypass flaws Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. […] Sergiu Gatlan Go to bleepingcomputer
-
Ransomware gangs turn to Shanya EXE packer to hide EDR killers
Ransomware gangs turn to Shanya EXE packer to hide EDR killers Several ransomware groups have been spotted using a packer-as-a-service (PaaS) platform named Shanya to assist in EDR (endpoint detection and response) killing operations. […] Bill Toulas Go to bleepingcomputer
-
Malicious VSCode extensions on Microsoft’s registry drop infostealers
Malicious VSCode extensions on Microsoft’s registry drop infostealers Two malicious extensions on Microsoft’s Visual Studio Code Marketplace infect developers’ machines with information-stealing malware that can take screenshots, steal credentials, and hijack browser sessions. […] Bill Toulas Go to bleepingcomputer
-
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024
FinCEN says ransomware gangs extorted over $2.1B from 2022 to 2024 A new report by the Financial Crimes Enforcement Network (FinCEN) shows that ransomware activity peaked in 2023 before falling in 2024, following a series of law enforcement actions targeting the ALPHV/BlackCat and LockBit ransomware gangs. […] Lawrence Abrams Go to bleepingcomputer
-
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment
Poland arrests Ukrainians utilizing ‘advanced’ hacking equipment The police in Poland arrested three Ukrainian nationals for allegedly attempting to damage IT systems in the country using hacking equipment and for obtaining “computer data of particular importance to national defense.” […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds new security layer for Gemini AI agentic browsing
Google Chrome adds new security layer for Gemini AI agentic browsing Google Chrome is introducing a new security architecture designed to protect upcoming agentic AI browsing features powered by Gemini. […] Bill Toulas Go to bleepingcomputer
-
OpenAI denies rolling out ads on ChatGPT paid plans
OpenAI denies rolling out ads on ChatGPT paid plans ChatGPT is allegedly showing ads to those who pay $20 for the Plus subscription, but OpenAI says this is an app recommendation feature, not an ad. […] Mayank Parmar Go to bleepingcomputer
-
Portugal updates cybercrime law to exempt security researchers
Portugal updates cybercrime law to exempt security researchers Portugal has modified its cybercrime law to establish a legal safe harbor for good-faith security research and to make hacking non-punishable under certain strict conditions. […] Bill Toulas Go to bleepingcomputer
-
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors. […] Lawrence Abrams Go to bleepingcomputer
-
New wave of VPN login attempts targets Palo Alto GlobalProtect portals
New wave of VPN login attempts targets Palo Alto GlobalProtect portals A campaign has been observed targeting Palo Alto GlobalProtect portals with login attempts and launching scanning activity against SonicWall SonicOS API endpoints. […] Bill Toulas Go to bleepingcomputer
-
Barts Health NHS discloses data breach after Oracle zero-day hack
Barts Health NHS discloses data breach after Oracle zero-day hack Barts Health NHS Trust has announced that Clop ransomware actors have stolen files from a database by exploiting a vulnerability in its Oracle E-business Suite software. […] Bill Toulas Go to bleepingcomputer
-
FBI warns of virtual kidnapping scams using altered social media photos
FBI warns of virtual kidnapping scams using altered social media photos The FBI warns of criminals altering images shared on social media and using them as fake proof of life photos in virtual kidnapping ransom scams. […] Sergiu Gatlan Go to bleepingcomputer
-
A Practical Guide to Continuous Attack Surface Visibility
A Practical Guide to Continuous Attack Surface Visibility Passive scan data goes stale fast as cloud assets shift daily, leaving teams blind to real exposures. Sprocket Security shows how continuous, automated recon gives accurate, up-to-date attack surface visibility. […] Sponsored by Sprocket Security Go to bleepingcomputer
-
EU fines X $140 million over deceptive blue checkmarks
EU fines X $140 million over deceptive blue checkmarks The European Commission has fined X €120 million ($140 million) for violating transparency obligations under the Digital Services Act (DSA). […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare blames today’s outage on React2Shell mitigations
Cloudflare blames today’s outage on React2Shell mitigations Cloudflare has blamed today’s outage on the emergency patching of a critical React remote code execution vulnerability, which is now actively exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Cloudflare down, websites offline with 500 Internal Server Error
Cloudflare down, websites offline with 500 Internal Server Error Cloudflare is down, as websites are crashing with a 500 Internal Server Error. Cloudflare is investigating the reports. […] Mayank Parmar Go to bleepingcomputer
-
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
Hackers are exploiting ArrayOS AG VPN flaw to plant webshells Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create rogue users. […] Bill Toulas Go to bleepingcomputer
-
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices
NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices The UK’s National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. […] Bill Toulas Go to bleepingcomputer
-
Predator spyware uses new infection vector for zero-click attacks
Predator spyware uses new infection vector for zero-click attacks The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed “Aladdin” that compromised specific targets when simply viewing a malicious advertisement. […] Bill Toulas Go to bleepingcomputer
-
Russia blocks FaceTime and Snapchat for alleged use by terrorists
Russia blocks FaceTime and Snapchat for alleged use by terrorists Russian telecommunications watchdog Roskomnadzor has blocked access to Apple’s FaceTime video conferencing platform and the Snapchat instant messaging service, claiming they’re being used to coordinate terrorist attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Marquis data breach impacts over 74 US banks, credit unions
Marquis data breach impacts over 74 US banks, credit unions Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and credit unions across the US. […] Lawrence Abrams Go to bleepingcomputer
-
Critical flaw in WordPress add-on for Elementor exploited in attacks
Critical flaw in WordPress add-on for Elementor exploited in attacks Attackers are exploiting a critical-severity privilege escalation vulnerability (CVE-2025-8489) in the King Addons for Elementor plugin for WordPress, which lets them obtain administrative permissions during the registration process. […] Bill Toulas Go to bleepingcomputer
-
French DIY retail giant Leroy Merlin discloses a data breach
French DIY retail giant Leroy Merlin discloses a data breach Leroy Merlin is sending security breach notifications to customers in France, informing them that their personal data was compromised. […] Bill Toulas Go to bleepingcomputer
-
Freedom Mobile discloses data breach exposing customer data
Freedom Mobile discloses data breach exposing customer data Freedom Mobile, the fourth-largest wireless carrier in Canada, has disclosed a data breach after attackers hacked into its customer account management platform and stole the personal information of an undisclosed number of customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia blocks Roblox over distribution of LGBT “propaganda”
Russia blocks Roblox over distribution of LGBT “propaganda” Roskomnadzor, Russia’s telecommunications watchdog, has blocked access to the Roblox online gaming platform for failing to stop the distribution of what it described as LGBT propaganda and extremist materials. […] Sergiu Gatlan Go to bleepingcomputer
-
Korea arrests suspects selling intimate videos from hacked IP cameras
Korea arrests suspects selling intimate videos from hacked IP cameras The Korean National Police have arrested four individuals suspected of hacking over 120,000 IP cameras across the country and then selling stolen footage to a foreign adult site. […] Bill Toulas Go to bleepingcomputer
-
FTC settlement requires Illuminate to delete unnecessary student data
FTC settlement requires Illuminate to delete unnecessary student data The Federal Trade Commission (FTC) is proposing that education technology provider Illuminate Education to delete unnecessary student data and improve its security to settle allegations related to an incident in 2021 that exposed info of 10 million students. […] Bill Toulas Go to bleepingcomputer
-
ChatGPT is down worldwide, conversations disappeared for users
ChatGPT is down worldwide, conversations disappeared for users OpenAI’s AI-powered ChatGPT is down worldwide with users receiving errors when attempting to access chats, with no reasons currently given. […] Mayank Parmar Go to bleepingcomputer
-
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets The second Shai-Hulud attack last week exposed around 400,000 raw secrets after infecting hundreds of packages in the NPM (Node Package Manager) registry and publishing stolen data in 30,000 GitHub repositories. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Defender portal outage disrupts threat hunting alerts
Microsoft Defender portal outage disrupts threat hunting alerts Microsoft is working to mitigate an ongoing incident that has been blocking access to some Defender XDR portal capabilities, including threat hunting alerts. […] Sergiu Gatlan Go to bleepingcomputer
-
Glassworm malware returns in third wave of malicious VS Code packages
Glassworm malware returns in third wave of malicious VS Code packages The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now in its third wave, with 24 new packages added on the two platforms. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says new Outlook can’t open some Excel attachments
Microsoft says new Outlook can’t open some Excel attachments Microsoft is working to resolve a known issue that prevents some users from opening Excel email attachments in the new Outlook client. […] Sergiu Gatlan Go to bleepingcomputer
-
SmartTube YouTube app for Android TV breached to push malicious update
SmartTube YouTube app for Android TV breached to push malicious update The popular open-source SmartTube YouTube client for Android TV was compromised after an attacker gained access to the developer’s signing keys, leading to a malicious update being pushed to users. […] Bill Toulas Go to bleepingcomputer
-
Retail giant Coupang data breach impacts 33.7 million customers
Retail giant Coupang data breach impacts 33.7 million customers South Korea’s largest retailer, Coupang, has suffered a data breach that exposed the personal information of 33.7 million customers. […] Bill Toulas Go to bleepingcomputer
-
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats
When Hackers Wear Suits: Protecting Your Team from Insider Cyber Threats Hackers impersonate IT pros with deepfakes, fake resumes, and stolen identities, turning hiring pipelines into insider threats. Huntres sLabs explains how stronger vetting and access controls help stop these threats. […] Sponsored by Huntress Labs Go to bleepingcomputer
-
Police takes down Cryptomixer cryptocurrency mixing service
Police takes down Cryptomixer cryptocurrency mixing service Law enforcement officers from Switzerland and Germany have taken down the Cryptomixer cryptocurrency-mixing service, believed to have helped cybercriminals launder stolen funds. […] Sergiu Gatlan Go to bleepingcomputer
-
Japanese beer giant Asahi says data breach hit 1.5 million people
Japanese beer giant Asahi says data breach hit 1.5 million people Asahi Group Holdings, Japan’s largest beer producer, has finished the investigation into the September cyberattack and found that the incident has impacted up to 1.9 million individuals. […] Bill Toulas Go to bleepingcomputer
-
Leak confirms OpenAI is preparing ads on ChatGPT for public roll out
Leak confirms OpenAI is preparing ads on ChatGPT for public roll out OpenAI is now internally testing ‘ads’ inside ChatGPT that could redefine the web economy. […] Mayank Parmar Go to bleepingcomputer
-
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison
Man behind in-flight Evil Twin WiFi attacks gets 7 years in prison A 44-year-old man was sentenced to seven years and four months in prison for operating an “evil twin” WiFi network to steal the data of unsuspecting travelers at various airports across Australia. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Windows updates make password login option invisible
Microsoft: Windows updates make password login option invisible Microsoft warned users that Windows 11 updates released since August may cause the password sign-in option to disappear from the lock screen options, even though the button remains functional. […] Sergiu Gatlan Go to bleepingcomputer
-
Public GitLab repositories exposed more than 17,000 secrets
Public GitLab repositories exposed more than 17,000 secrets After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains. […] Bill Toulas Go to bleepingcomputer
-
French Football Federation discloses data breach after cyberattack
French Football Federation discloses data breach after cyberattack The French Football Federation (FFF) disclosed a data breach on Friday after attackers used a compromised account to gain access to administrative management software used by football clubs. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious LLMs empower inexperienced hackers with advanced tools
Malicious LLMs empower inexperienced hackers with advanced tools Unrestricted large language models (LLMs) like WormGPT 4 and KawaiiGPT are improving their capabilities to generate malicious code, delivering functional scripts for ransomware encryptors and lateral movement. […] Bill Toulas Go to bleepingcomputer
-
OpenAI discloses API customer data breach via Mixpanel vendor hack
OpenAI discloses API customer data breach via Mixpanel vendor hack OpenAI is notifying some ChatGPT API customers that limited identifying information was exposed following a breach at its third-party analytics provider Mixpanel. […] Ionut Ilascu Go to bleepingcomputer
-
New ShadowV2 botnet malware used AWS outage as a test opportunity
New ShadowV2 botnet malware used AWS outage as a test opportunity A new Mirai-based botnet malware named ‘ShadowV2’ has been observed targeting IoT devices from D-Link, TP-Link, and other vendors with exploits for known vulnerabilities. […] Bill Toulas Go to bleepingcomputer
-
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025 The NordVPN Black Friday Deal is now live, and you can get the best discount available: 77% off that applies automatically when you follow our link. If you’ve been waiting for the right moment to upgrade your online security, privacy, and streaming freedom, this is…
-
Popular Forge library gets fix for signature verification bypass flaw
Popular Forge library gets fix for signature verification bypass flaw A vulnerability in the ‘node-forge’ package, a popular JavaScript cryptography library, could be exploited to bypass signature verifications by crafting data that appears valid. […] Bill Toulas Go to bleepingcomputer
-
Comcast to pay $1.5M fine for vendor breach affecting 270K customers
Comcast to pay $1.5M fine for vendor breach affecting 270K customers Comcast will pay a $1.5 million fine to settle a Federal Communications Commission investigation into a February 2024 vendor data breach that exposed the personal information of nearly 275,000 customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Multiple London councils’ IT systems disrupted by cyberattack
Multiple London councils’ IT systems disrupted by cyberattack The Royal Borough of Kensington and Chelsea (RBKC) and the Westminster City Council (WCC) announced that they are experiencing service disruptions following a cybersecurity issue. […] Bill Toulas Go to bleepingcomputer
-
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide
OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide Risk management company Crisis24 has confirmed its OnSolve CodeRED platform suffered a cyberattack that disrupted emergency notification systems used by state and local governments, police departments, and fire agencies across the United States. […] Lawrence Abrams Go to bleepingcomputer
-
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals
The Black Friday 2025 Cybersecurity, IT, VPN, & Antivirus Deals Black Friday 2025 is almost here, and early deals are already live across security software, online courses, system administration tools, antivirus products, and VPN services. These discounts are limited-time offers and vary by provider, so if you see something that fits your needs, it’s best…
-
FBI: Cybercriminals stole $262M by impersonating bank support teams
FBI: Cybercriminals stole $262M by impersonating bank support teams The FBI warns of a surge in account takeover (ATO) fraud schemes and says that cybercriminals impersonating various financial institutions have stolen over $262 million in ATO attacks since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Tor switches to new Counter Galois Onion relay encryption algorithm
Tor switches to new Counter Galois Onion relay encryption algorithm Tor has announced improved encryption and security for the circuit traffic by replacing the old tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO). […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Exchange Online outage blocks access to Outlook mailboxes
Microsoft: Exchange Online outage blocks access to Outlook mailboxes Microsoft is investigating an Exchange Online service outage that is preventing customers from accessing their mailboxes using the classic Outlook desktop client. […] Sergiu Gatlan Go to bleepingcomputer