Golden Corral restaurant chain data breach impacts 183,000 people

The Golden Corral American restaurant chain disclosed a data breach after attackers behind an August cyberattack stole the personal information of over 180,000 people. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

New Bifrost malware for Linux mimics VMware domain for evasion

A new Linux variant of the Bifrost remote access trojan (RAT) employs several novel evasion techniques, including the use of a deceptive domain that was made to appear as part of VMware. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Brave browser launches privacy-focused AI assistant on Android

Brave Software is the next company to jump into AI, announcing a new privacy-preserving AI assistant called "Leo" is rolling out on the Android version of its browser through the latest release, version 1.63. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

CISA warns against using hacked Ivanti devices even after factory resets

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed today that attackers who breached Ivanti appliances using one of multiple actively exploited vulnerabilities can maintain root persistence even after performing factory resets. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Windows 10 KB5034843 update released with 9 new changes, fixes

Microsoft has released the optional KB5034843 Preview cumulative update for Windows 10 22H2 with an updated sharing experience and eight other fixes or changes. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Windows 11 KB5034848 preview update adds USB 80Gbps support

Microsoft has released the optional KB5034848 Preview cumulative update for Windows 11 23H2 and 22H2, which brings new features, including USB 80Gbps and nineteen other changes and fixes. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

GitHub enables push protection by default to stop secrets leak

GitHub has enabled push protection by default for all public repositories to prevent accidental exposure of secrets such as access tokens and API keys when pushing new code. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Citrix, Sophos software impacted by 2024 leap year bugs

Citrix and Sophos products have been impacted by leap year flaws, leading to unexpected problems in their products. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Windows 11 'Moment 5' update released, here are the new features

Microsoft has released the Windows 11 'Moment 5' update for versions 23H2 and 22H2, starting the rollout of new features, such as Windows Copilot skills and plugins, Voice Access, AI enhancements for ClipChamp and Photos, and Narrator improvements. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Microsoft rolls back decision to stop Windows 11 22H2 preview updates

Microsoft says that systems running Windows 11 22H2 will continue to receive non-security preview updates after initially stating they would no longer receive them after February 2024. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

20 million Cutout.Pro user records leaked on data breach forum

AI service Cutout.Pro has suffered a data breach exposing the personal information of 20 million members, including email addresses, hashed and salted passwords, IP addresses, and names. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Anycubic 3D printers hacked worldwide to expose security flaw

According to a wave of online reports from Anycubic customers, someone hacked their 3D printers to warn that the devices are exposed to attacks. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Malicious AI models on Hugging Face backdoor users’ machines

At least 100 instances of malicious AI ML models were found on the Hugging Face platform, some of which can execute code on the victim's machine, giving attackers a persistent backdoor. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

New executive order bans mass sale of personal data to China, Russia

U.S. President Joe Biden has signed an executive order that aims to ban the bulk sale and transfer of Americans' private data to "countries of concern" such as China, Russia, Iran, North Korea, Cuba, and Venezuela. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Rhysida ransomware wants $3.6 million for children’s stolen data

The Rhysida ransomware gang has claimed the cyberattack on Lurie Children's Hospital in Chicago at the start of the month. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Kali Linux 2024.1 released with 4 new tools, UI refresh

Kali Linux has released version 2024.1, the first version of 2024, with four new tools, a theme refresh, and desktop changes. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Ransomware gang claims they stole 6TB of Change Healthcare data

The BlackCat/ALPHV ransomware gang has officially claimed responsibility for a cyberattack on Optum, a subsidiary of UnitedHealth Group (UHG), which led to an ongoing outage affecting the Change Healthcare platform. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

LockBit ransomware returns to attacks with new encryptors, servers

The LockBit ransomware gang is once again conducting attacks, using updated encryptors with ransom notes linking to new servers after last week's law enforcement disruption. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Lazarus hackers exploited Windows zero-day to gain Kernel privileges

North Korean threat actors known as the Lazarus Group exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools, allowing them to bypass noisy BYOVD (Bring Your Own Vulnerable Driver) techniques. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Epic Games: "Zero evidence" we were hacked by Mogilevich gang

Epic Games said they found zero evidence of a cyberattack or data theft after the Mogilevich extortion group claimed to have breached the company's servers. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Japan warns of malicious PyPi packages created by North Korean hackers

Japan's Computer Security Incident Response Team (JPCERT/CC) is warning that the notorious North Korean hacking group Lazarus has uploaded four malicious PyPI packages to infect developers with malware. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Need to Know: Key Takeaways from the Latest Phishing Attacks

This article takes a look at some lessons from recent phishing attacks and highlights actionable tips to limit the risks of phishing affecting your company. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Savvy Seahorse gang uses DNS CNAME records to power investor scams

A threat actor named Savvy Seahorse is abusing CNAME DNS records Domain Name System to create a traffic distribution system that powers financial scam campaigns. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Registrars can now block all domains that resemble brand names

Registrars can now block people from registering tens of thousands of domain names that look like, are spelling variations of, or otherwise infringe on brand names. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Pharmaceutical giant Cencora says data was stolen in a cyberattack

Pharmaceutical giant Cencora says they suffered a cyberattack where threat actors stole data from corporate IT systems. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

FBI, CISA warn US hospitals of targeted BlackCat ransomware attacks

Today, the FBI, CISA, and the Department of Health and Human Services (HHS) warned U.S. healthcare organizations of targeted ALPHV/Blackcat ransomware attacks. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

LabHost cybercrime service lets anyone phish Canadian bank users

The Phishing as a Service (PhaaS) platform 'LabHost' has been helping cybercriminals target North American banks, particularly financial institutes in Canada, causing a notable increase in activity. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Black Basta, Bl00dy ransomware gangs join ScreenConnect attacks

The Black Basta and Bl00dy ransomware gangs have joined widespread attacks targeting ScreenConnect servers unpatched against a maximum severity authentication bypass vulnerability. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Russian hackers hijack Ubiquiti routers to launch stealthy attacks

Russian APT28 military hackers are using compromised Ubiquiti EdgeRouters to evade detection, the FBI says in a joint advisory issued with the NSA, the U.S. Cyber Command, and international partners. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

German state of Hessen says systems encrypted by ransomware

The German state of Hessen (Hesse) has been hit with a ransomware attack, causing the government to shut down IT systems and disrupting the availability of its consumer advice center. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Malicious code in Tornado Cash governance proposal puts user funds at risk

Malicious JavaScript code hidden in a Tornado Cash governance proposal has been leaking deposit notes and data to a private server for almost two months. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Windows February 2024 updates fail to install with 0x800F0922 errors

Microsoft says the February 2024 updates fail to install on Windows 11 22H2 and 23H2 systems, with 0x800F0922 errors and downloads stopping at 96%. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

UnitedHealth subsidiary Optum hack linked to BlackCat ransomware

A cyberattack on UnitedHealth Group subsidiary Optum that led to an ongoing outage impacting the Change Healthcare payment exchange platform was linked to the BlackCat ransomware group by sources familiar with the investigation. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

New IDAT loader version uses steganography to push Remcos RAT

A hacking group tracked as 'UAC-0184' was observed utilizing steganographic image files to deliver the Remcos remote access trojan (RAT) onto the systems of a Ukrainian entity operating in Finland. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Mowing down demons: DOOM comes to Husqvarna smart lawnmowers

If you ever wanted to play DOOM on a lawnmower, you will soon have your chance with a new software update coming to Husqvarna's robotic line of lawnmowers this spring. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

White House urges devs to switch to memory-safe programming languages

The White House Office of the National Cyber Director (ONCD) urged tech companies today to switch to memory-safe programming languages, such as Rust, to improve software security by reducing the number of memory safety vulnerabilities. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Hackers exploit 14-year-old CMS editor on govt, edu sites for SEO poisoning

Threat actors are exploiting a CMS editor discontinued 14 years ago to compromise education and government entities worldwide to poison search results with malicious sites or scams. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Russian hackers shift to cloud attacks, US and allies warn

Members of the Five Eyes (FVEY) intelligence alliance warned today that Russian Foreign Intelligence Service (SVR) hackers tracked as APT29 are now increasingly targeting their victims' cloud services. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Steel giant ThyssenKrupp confirms cyberattack on automotive division

Steel giant ThyssenKrupp confirms that hackers breached systems in its Automotive division last week, forcing them to shut down IT systems as part of its response and containment effort. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Cybersecurity Training Not Sticking? How to Fix Risky Password Habits

While security training can help create a culture of cybersecurity awareness, it can't be relied upon to consistently change behavior. Learn more from Specops Software about the limitations of training and five ways you can increase password security. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

SubdoMailing campaign spams 5 million emails daily via 8k hijacked domains

A massive ad fraud campaign named "SubdoMailing" is using over 8,000 legitimate internet domains and 13,000 subdomains to send up to five million emails per day to generate revenue through scams and malvertising. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

LockBit ransomware returns, restores servers after police disruption

The LockBit gang is relaunching its ransomware operation on a new infrastructure less than a week after law enforcement hacked their servers, and is threatening to focus more of their attacks on the government sector. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

PayPal files patent for new method to detect stolen cookies

PayPal has filed a patent application for a novel method that can identify when "super-cookie" is stolen, which could improve the cookie-based authentication mechanism and limit account takeover attacks. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

RCMP investigating cyber attack as its website remains down

The Royal Canadian Mounted Police (RCMP), Canada's national police force has disclosed that it recently faced a cyber attack targeting its networks. The federal body has started its criminal investigation into the matter as it works to determine the scope of the security breach. … | Continue reading


@bleepingcomputer.com | 9 months ago

Apple adds PQ3 quantum-resistant encryption to iMessage

Apple is adding to the iMessage instant messaging service a new post-quantum cryptographic protocol named PQ3, designed to defend encryption from quantum attacks. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

FTC sues H&R Block over deceptive 'free' online filing ads

The U.S. Federal Trade Commission (FTC) sued tax preparation giant H&R Block over the company's deceptive "free" online filing advertising and for pressuring people into overpaying for its services. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Insomniac Games alerts employees hit by ransomware data breach

Sony subsidiary Insomniac Games is sending data breach notification letters to employees whose personal information was stolen and leaked online following a Rhysida ransomware attack in November. [...] | Continue reading


@bleepingcomputer.com | 9 months ago

Google Pay app shutting down in US, users have till June to move funds

Google is retiring the standalone Pay app in the United States. Users have until June 4 to transfer the balance to bank accounts. [...] | Continue reading


@bleepingcomputer.com | 9 months ago