BazarCall attacks abuse Google Forms to legitimize phishing emails

A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

French police arrests Russian suspect linked to Hive ransomware

French authorities arrested a Russian national in Paris for allegedly helping the Hive ransomware gang with laundering their victims' ransom payments. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

LockBit ransomware now poaching BlackCat, NoEscape affiliates

The LockBit ransomware operation is now recruiting affiliates and developers from the BlackCat/ALPHV and NoEscape after recent disruptions and exit scams. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

CISA: Russian hackers target TeamCity servers since September

CISA and partner cybersecurity agencies and intelligence services warned that the APT29 hacking group linked to Russia's Foreign Intelligence Service (SVR) has been targeting unpatched TeamCity servers in widespread attacks since September 2023. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Hackers are exploiting critical Apache Struts flaw using public PoC

Hackers are attempting to leverage a recently fixed critical vulnerability (CVE-2023-50164) in Apache Struts that leads to remote code execution, in attacks that rely on publicly available proof-of-concept exploit code. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New cybercrime market 'OLVX' gains popularity among hackers

A new cybercrime marketplace, OLVX, has emerged and is quickly gaining new customers looking to purchase tools to conduct online fraud and cyberattacks. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft: OAuth apps used to automate BEC and cryptomining attacks

Microsoft warns that financially-motivated threat actors are using OAuth applications to automate BEC and phishing attacks, push spam, and deploy VMs for cryptomining. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ukrainian military says it hacked Russia's federal tax agency

​The Ukrainian government's military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency's database and backup copies. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Avira antivirus causes Windows computers to freeze after boot

Since Friday, Windows users have reported problems with the operating system freezing shortly after booting, an issue linked to a faulty update for Avira's security software. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day

Today is Microsoft's December 2023 Patch Tuesday, which includes security updates for a total of 34 flaws and one previously disclosed, unpatched vulnerability in AMD CPUs. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Windows 11 KB5033375 update released with upgraded Copilot AI-assistant

Microsoft has released the KB5033375 update for Windows 11 versions 23H2 and 22H2 to fix security vulnerabilities, upgrade Copilot for Windows, and make 36 changes and fixes [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Windows 10 KB5033372 update released with Copilot for everyone, 20 changes

Microsoft has released the KB5033372 cumulative update for Windows 10 21H2 and Windows 10 22H2, which includes Copilot for Windows and nineteen other changes to the operating system. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Sophos backports RCE fix after attacks on unsupported firewalls

Sophos was forced to backport a security update for CVE-2022-3236 for end-of-life (EOL) firewall firmware versions after discovering hackers actively exploiting the flaw in attacks. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Ukraine's largest mobile carrier Kyivstar down following cyberattack

Kyivstar, Ukraine's largest telecommunications service provider serving over 25 million mobile and home internet subscribers, has suffered a cyberattack impacting mobile and data services. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Cloud engineer gets 2 years for wiping ex-employer’s code repos

Miklos Daniel Brody, a cloud engineer, was sentenced to two years in prison and a restitution of $529,000 for wiping the code repositories of his former employer in retaliation for being fired by the company.  [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Over 1,450 pfSense servers exposed to RCE attacks via bug chain

Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable attackers to perform remote code execution on the appliance. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable websites. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Lazarus hackers drop new RAT malware using 2-year-old Log4j bug

The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka "Log4Shell," this time to deploy three previously unseen malware families written in DLang. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Counter-Strike 2 HTML injection bug exposes players’ IP addresses

Valve has reportedly fixed an HTML injection flaw in Counter-Strike 2 that was heavily abused today to inject images into games and obtain other players' IP addresses. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Apple emergency updates fix recent zero-days on older iPhones

Apple has issued emergency security updates to backport patches for two actively exploited zero-day flaws to older iPhones and some Apple Watch and Apple TV models. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Cold storage giant Americold discloses data breach after April malware attack

Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen in an April attack, later claimed by Cactus ransomware. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Toyota warns customers of data breach exposing personal, financial info

Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Kelvin Security hacking group leader arrested in Spain

The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to be responsible for 300 cyberattacks against organizations in 90 countries since 2020. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Over 30% of Log4J apps use a vulnerable version of the library

Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two yea … | Continue reading


@bleepingcomputer.com | 11 months ago

AutoSpill attack steals credentials from Android password managers

Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Norton Healthcare discloses data breach after May ransomware attack

Kentucky health system Norton Healthcare has confirmed that a ransomware attack in May exposed personal information belonging to patients, employees, and dependents. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Google shares “fix” for deleted Google Drive files

Google says it identified and fixed a bug causing customer files added to Google Drive after April-May 2023 to disappear. However, the fix isn't working for all affected users. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Microsoft: Outlook email sending issues for users with lots of folders

Microsoft has acknowledged a new issue affecting Outlook for Microsoft 365 users and causing email-sending problems for those with too many nested folders. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

ALPHV ransomware site outage rumored to be caused by law enforcement

A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang's websites over the last 30 hours. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Privilege elevation exploits used in over 50% of insider attacks

Elevation of privilege flaws are the most common vulnerability leveraged by corporate insiders when conducting unauthorized activities on networks, whether for malicious purposes or by downloading risky tools in a dangerous manner. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Amazon sues REKK fraud gang that stole millions in illicit refunds

Amazon's Customer Protection and Enforcement team has taken legal action against an underground store refund scheme that has resulted in the theft of millions of dollars worth of products from Amazon's online platforms. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New 5Ghoul attack impacts 5G phones with Qualcomm, MediaTek chips

A new set of vulnerabilities in 5G modems by Qualcomm and MediaTek, collectively called "5Ghoul," impact 710 5G smartphone models from Google partners (Android) and Apple, routers, and USB modems. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Russian military hackers target NATO fast reaction corps

Russian APT28 military hackers used Microsoft Outlook zero-day exploits to target multiple European NATO member countries, including a NATO Rapid Deployable Corps. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

23andMe updates user agreement to prevent data breach lawsuits

As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Windows 11 Notepad gets a built-in character counter, finally

Microsoft keeps improving and adding more features to the Windows 11 Notepad application, the latest being a built-in character counter. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

WordPress fixes POP chain exposing websites to RCE attacks

WordPress has released version 6.4.2 that addresses a remote code execution (RCE) vulnerability that could be chained with another flaw to allow attackers run arbitrary PHP code on the target website. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Russian pleads guilty to running crypto-exchange used by ransomware gangs

Russian national Anatoly Legkodymov pleaded guilty to operating the Bitzlato cryptocurrency exchange that helped ransomware gangs and other cybercriminals launder over $700 million. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

UK and allies expose Russian FSB hacking group, sanction members

The UK National Cyber Security Centre (NCSC) and Microsoft warn that the Russian state-backed actor "Callisto Group" (aka "Seaborgium" or "Star Blizzard") is targeting organizations worldwide with spear-phishing campaigns used to steal account credentials and data. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Meta rolls out default end-to-end encryption on Messenger, Facebook

Meta has announced that the immediate availability of end-to-end encryption for all chats and calls made through the Messenger app, as well as the Facebook social media platform. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Krasue RAT malware hides on Linux servers using embedded rootkits

Security researchers discovered a remote access trojan they named Krasue that is targeting Linux systems of telecommunications companies and managed to remain undetected since 2021. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

New SLAM attack steals sensitive data from AMD, future Intel CPUs

Academic researchers developed a new side-channel attack called SLAM that exploits hardware features designed to improve security in upcoming CPUs from Intel, AMD, and Arm to obtain the root password hash from the kernel memory. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

US senator: Govts spy on Apple, Google users via mobile notifications

A U.S. senator revealed today that government agencies worldwide demand mobile push notification records from Apple and Google users to spy on their customers. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Navy contractor Austal USA confirms cyberattack after data leak

Austal USA, a shipbuilding company and a contractor for the U.S. Department of Defense (DoD) and the Department of Homeland Security (DHS) confirmed that it suffered a cyberattack and is currently investigating the impact of the incident. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Atlassian patches critical RCE flaws across multiple products

Atlassian has published security advisories for four critical remote code execution (RCE) vulnerabilities impacting Confluence, Jira, and Bitbucket servers, along with a companion app for macOS. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Varonis Introduces Athena AI to Transform Data Security and Incident Response

Athena AI, a new generative AI layer that spans across the entire Varonis Data Security Platform, enhances how security teams protect data — from visibility to action. Learn more from Varonis in this article. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

Nissan is investigating cyberattack and potential data breach

Japanese car maker Nissan is investigating a cyberattack that targeted its systems in Australia and New Zealand, which may have let hackers access personal information. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

"Sierra:21" vulnerabilities impact critical infrastructure routers

A set of 21 newly discovered vulnerabilities impact Sierra OT/IoT routers and threaten critical infrastructure with remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial of service attacks. [...] | Continue reading


@bleepingcomputer.com | 11 months ago

HTC Global Services confirms cyberattack after data leaked online

IT services and business consulting company HTC Global Services has confirmed that they suffered a cyberattack after the ALPHV ransomware gang began leaking screenshots of stolen data. [...] | Continue reading


@bleepingcomputer.com | 11 months ago