Google fixes 8th Chrome zero-day exploited in attacks this year

Google has released emergency updates to fix another Chrome zero-day vulnerability exploited in the wild, the eighth patched since the start of the year. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Crypto scammers abuse X 'feature' to impersonate high-profile accounts

Cryptocurrency scammers are abusing a legitimate X "feature" to promote scams, fake giveaways, and fraudulent Telegram channels used to steal your crypto and NFTs. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New phishing attack steals your Instagram backup codes to bypass 2FA

A new phishing campaign pretending to be a 'copyright infringement' email attempts to steal the backup codes of Instagram users, allowing hackers to bypass the two-factor authentication configured on the account. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ivanti releases patches for 13 critical Avalanche RCE flaws

​Ivanti has released security updates to fix 13 critical security vulnerabilities in the company's Avalanche enterprise mobile device management (MDM) solution. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft fixes Wi-Fi issues triggered by recent Windows updates

Microsoft has fixed a known issue causing Wi-Fi network connectivity problems on Windows 11 systems triggered by recently released cumulative updates. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Healthcare software provider data breach impacts 2.7 million

ESO Solutions, a provider of software products for healthcare organizations and fire departments, disclosed that data belonging to 2.7 million patients has been compromised as a result of a ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

The password attacks of 2023: Lessons learned and next steps

The password attacks of 2023 involved numerous high-profile brands, leading to the exposure of millions of users' data. Learn more from Specops Software on how to respond to these types of attacks. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

German police takes down Kingdom Market cybercrime marketplace

The Federal Criminal Police Office in Germany (BKA) and the internet-crime combating unit of Frankfurt (ZIT) have announced the seizure of Kingdom Market, a dark web marketplace for drugs, cybercrime tools, and fake government IDs. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New Web injections campaign steals banking data from 50,000 people

A new malware campaign that emerged in March 2023 used JavaScript web injections to try to steal the banking data of over 50,000 users of 40 banks in North America, South America, Europe, and Japan. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

FBI: ALPHV ransomware raked in $300 million from over 1,000 victims

The ALPHV/BlackCat ransomware gang has made over $300 million in ransom payments from more than 1,000 victims worldwide as of September 2023, according to the Federal Bureau of Investigation (FBI). [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Interpol operation arrests 3,500 cybercriminals, seizes $300 million

An international law enforcement operation codenamed 'Operation HAECHI IV' has led to the arrest of 3,500 suspects of various lower-tier cybercrimes and seized $300 million in illicit proceeds. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft confirms Windows 11 Wi-Fi issues, asks for user feedback

Microsoft has confirmed that some Windows 11 devices experience Wi-Fi connectivity issues after installing recent cumulative updates. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

How the FBI seized BlackCat (ALPHV) ransomware’s servers

An unsealed FBI search warrant revealed how law enforcement hijacked the ALPHV/BlackCat ransomware operations websites and seized the associated URLs. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Terrapin attacks can downgrade security of OpenSSH connections

Academic researchers developed a new attack called Terrapin that manipulates sequence numbers during the handshake process to breaks the SSH channel integrity when certain widely-used encryption modes are used. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

FBI disrupts Blackcat ransomware operation, creates decryption tool

The Department of Justice announced today that the FBI successfully breached the ALPHV ransomware operation's servers to monitor their activities and obtain decryption keys. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Xfinity discloses data breach after recent Citrix server hack

Comcast Cable Communications, doing business as Xfinity, disclosed on Monday that attackers who breached one of its Citrix servers in October also stole customer-sensitive information from its systems. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

December's Windows 11 KB5033375 update breaks Wi-Fi connectivity

The KB5033375 cumulative update released during the December 2023 Patch Tuesday causes Wi-Fi connectivity issues on some Windows 11 devices. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft discovers critical RCE flaw in Perforce Helix Core Server

Four vulnerabilities, one of which is rated critical, have been discovered in the Perforce Helix Core Server, a source code management platform widely used by the gaming, government, military, and technology sectors. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Vans and North Face owner VF Corp hit by ransomware attack

American global apparel and footwear giant VF Corporation, the owner of brands like Supreme, Vans, Timberland, and The North Face, has disclosed a security incident that caused operational disruptions. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft fixes Windows printer issues with new troubleshooter

Microsoft has released a troubleshooter tool to fix an issue where the HP Smart app would automatically install on Windows systems after renaming all printers to HP LaserJet M101-M106. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

FBI: Play ransomware breached 300 victims, including critical orgs

The Federal Bureau of Investigation (FBI) says the Play ransomware gang has breached roughly 300 organizations worldwide between June 2022 and October 2023, some of them critical infrastructure entities. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Former IT manager pleads guilty to attacking high school network

Conor LaHiff, a former IT manager for a New Jersey public high school, has admitted to committing a cyberattack against his former employer following the termination of his employment in June 2023. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Mortgage giant Mr. Cooper data breach affects 14.7 million people

Mr. Cooper is sending notices of a data breach to customers who were impacted by a cyberattack the firm suffered in November 2023. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

WordPress hosting service Kinsta targeted by Google phishing ads

WordPress hosting provider Kinsta is warning customers that Google ads have been observed promoting phishing sites to steal hosting credentials. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New Rhadamanthys stealer version enhances features, evasion

The developers of the Rhadamanthys information-stealing malware have recently released two major versions to add improvements and enhancements across the board, including new stealing capabilities and enhanced evasion. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

What to do when receiving unprompted MFA OTP codes

Receiving an unprompted one-time passcode (OTP) sent as an email or text should be a cause for concern as it likely means your credentials have been stolen. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Qbot malware returns in campaign targeting hospitality industry

The QakBot malware is once again being distributed in phishing campaigns after the botnet was disrupted by law enforcement over the summer. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

MongoDB says customer data was exposed in a cyberattack

MongoDB is warning that its corporate systems were breached and that customer data was exposed in a cyberattack that was detected by the company earlier this week. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

QNAP VioStor NVR vulnerability actively exploited by malware botnet

A Mirai-based botnet named 'InfectedSlurs' is exploiting a remote code execution (RCE) vulnerability in QNAP VioStor NVR (Network Video Recorder) devices to hijack and make them part of its DDoS (distributed denial of service) swarm. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft unveils new, more secure Windows Protected Print Mode

Microsoft announced a new Windows Protected Print Mode (WPP), introducing significant security enhancements to the Windows print system. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

The Week in Ransomware - December 15th 2023 - Ransomware Drama

The big news over the past two weeks is the continued drama plaguing BlackCat/ALPHV after their infrastructure suddenly stopped working for almost five days. Multiple sources told BleepingComputer that this outage was related to a law enforcement operation, but BlackCat claims th … | Continue reading


@bleepingcomputer.com | 11 months ago

Ex-Amazon engineer pleads guilty to hacking crypto exchanges

Former Amazon security engineer Shakeeb Ahmed pleaded guilty this week to hacking and stealing over $12.3 million from two cryptocurrency exchanges in July 2022. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

CISA urges tech manufacturers to stop using default passwords

Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged technology manufacturers to stop providing software and devices with default passwords. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

3CX warns customers to disable SQL database integrations

VoIP communications company 3CX warned customers today to disable SQL Database integrations because of risks posed by what it describes as a potential vulnerability. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ransomware gang behind threats to Fred Hutch cancer patients

The Hunters International ransomware gang claimed to be behind a cyberattack on the Fred Hutchinson Cancer Center (Fred Hutch) that resulted in patients receiving personalized extortion threats. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Box cloud storage down amid 'critical' outage

Cloud storage provider Box.com is suffering an outtage preventing customers from accessing their files. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Delta Dental says data breach exposed info of 7 million people

Delta Dental of California is warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Kraft Heinz investigates hack claims, says systems ‘operating normally’

Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New NKAbuse malware abuses NKN blockchain for stealthy comms

A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ubiquiti users report having access to others’ UniFi routers, cameras

Since yesterday, customers of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's cloud services. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

US detains suspects behind $80 million 'pig butchering' scheme

The U.S. Department of Justice charged four suspects (two of them already detained) for their alleged involvement in a pig butchering fraud scheme that resulted in more than $80 million in victim losses. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ten new Android banking trojans targeted 985 bank apps in 2023

This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Discord adds Security Key support for all users to enhance security

Discord has made security key multi-factor authentication (MFA) available for all accounts on the platform, bringing significant security and anti-phishing benefits to its 500+ million registered users. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

U.S. nuclear research lab data breach impacts 45,000 people

The Idaho National Laboratory (INL) confirmed that attackers stole the personal information of more than 45,000 individuals after breaching its cloud-based Oracle HCM HR management platform last month. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ledger dApp supply chain attack steals $600K from crypto wallets

Ledger is warnings users not to use web3 dApps after a supply chain attack on the 'Ledger dApp Connect Kit' library was found pushing a JavaScript wallet drainer that stole $600,000 in crypto and NFTs. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Protect your Active Directory from these Password-based Vulnerabilities

To safeguard against potential cyberattacks and outages, it is essential to be vigilant against common Active Directory attacks, Learn more from Specops Software about these attacks and how harden your defenses. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft seizes domains used to sell fraudulent Outlook accounts

Microsoft's Digital Crimes Unit seized multiple domains used by a Vietnam-based cybercrime group (Storm-1152) that registered over 750 million fraudulent accounts and raked in millions of dollars by selling them online to other cybercriminals. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Stealthy KV-botnet hijacks SOHO routers and VPN devices

The Chinese state-sponsored APT hacking group known as Volt Typhoon (Bronze Silhouette) has been linked to a sophisticated botnet named 'KV-botnet' since at least 2022 to attack SOHO routers in high-value targets. [...] | Continue reading


@bleepingcomputer.com | 11 months ago