Bumblebee malware returns after recent law enforcement disruption

The Bumblebee malware loader has been spotted in new attacks recently, more than four months after Europol disrupted it during 'Operation Endgame' in May. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Severe flaws in E2EE cloud storage platforms used by millions

Several end-to-end encrypted (E2EE) cloud storage platforms are vulnerable to a set of security issues that could expose user data to malicious actors. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Internet Archive breached again through stolen access tokens

The Internet Archive was breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Google Scholar has a 'verified email' for Sir Isaac Newton

It's true: Google Scholar profile of the renowned former physicist and polymath, Sir Isaac Newton bears a "verified email" note. According to Google Scholar, Isaac Newton is a "Professor of Physics, MIT" with a "Verified email at mit.edu." [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft warns it lost some customer's security logs for a month

Microsoft is warning enterprise customers that, for almost a month, a bug caused critical logs to be partially lost, putting at risk companies that rely on this data to detect unauthorized activity. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Fake Google Meet conference errors push infostealing malware

A new ClickFix campaign is luring users to fraudulent Google Meet conference pages showing fake connectivity errors that deliver info-stealing malware for Windows and macOS operating systems. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

FBI arrest Alabama man suspected of hacking SEC's X account

An Alabama man was arrested today by the FBI for his suspected role in hacking the SEC's X account to make a fake announcement that Bitcoin ETFs were approved. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Undercover North Korean IT workers now steal data, extort employers

North Korean IT professionals who trick Western companies into hiring them are stealing data from the organization's network and asking for a ransom to not leak it. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

BianLian ransomware claims attack on Boston Children's Health Physicians

The BianLian ransomware group has claimed the cyberattack on Boston Children's Health Physicians (BCHP) and threatens to leak stolen files unless a ransom is paid. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Hackers blackmail Globe Life after stealing customer data

Insurance giant Globe Life says an unknown threat actor attempted to extort money in exchange for not publishing data stolen from the company's systems earlier this year. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Top 5 Cloud Security Automations for SecOps Teams

Learn about 5 powerful cloud security automations with Blink Ops to simplify security operations like S3 bucket monitoring, subdomain takeover detection and failed EC2 login detection. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Iranian hackers act as brokers selling critical infrastructure access

Iranian hackers are breaching critical infrastructure organizations to collect credentials and network data that can be sold on cybercriminal forums to enable cyberattacks from other threat actors. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Google: 70% of exploited flaws disclosed in 2023 were zero-days

Google Mandiant security analysts warn of a worrying new trend of threat actors demonstrating a better capability to discover and exploit zero-day vulnerabilities in software. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

USDoD hacker behind National Public Data breach arrested in Brazil

A notorious hacker named USDoD, who is linked to the National Public Data and InfraGard breaches, has been arrested by Brazil's Polícia Federal in "Operation Data Breach". [...] | Continue reading


@bleepingcomputer.com | 1 month ago

SolarWinds Web Help Desk flaw is now exploited in attacks

CISA has added three flaws to its 'Known Exploited Vulnerabilities' (KEV) catalog, among which is a critical hardcoded credentials flaw in SolarWinds Web Help Desk (WHD) that the vendor fixed in late August 2024. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

US disrupts Anonymous Sudan DDoS operation, indicts 2 Sudanese brothers

The United States Department of Justice unsealed an indictment today against two Sudanese brothers suspected of being the operators of Anonymous Sudan, a notorious and dangerous hacktivist group known for conducting over 35,000 DDoS attacks in a year. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Internet Archive Hacked, Data Breach Impacts 31 Million Users

Lawrence Abrams, reporting for Bleeping Computer: Internet Archive’s “The Wayback Machine” has suffered a data breach after a threat actor compromised the website and stole a user authentication database containing 31 million unique records. News of the breach began circulating W … | Continue reading


@bleepingcomputer.com | 1 month ago

New Mamba 2FA bypass service targets Microsoft 365 accounts

An emerging phishing-as-a-service (PhaaS) platform called Mamba 2FA has been observed targeting Microsoft 365 accounts in AiTM attacks using well-crafted login pages. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Windows 10 KB5044273 update released with 9 fixes, security updates

Microsoft has released the KB5044273 cumulative update for Windows 10 22H2 and Windows 10 21H2, which includes nine changes and fixes, including a new Windows Update opt-in notification shown when you log in to the operating system. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft Edge begins testing Copilot Vision

Microsoft Edge Canary has been updated with an interesting feature called Copilot Vision, but it's still in testing. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

MoneyGram confirms hackers stole customer data in cyberattack

MoneyGram has confirmed that hackers stole customers' personal information and transaction data in a September cyberattack that caused a five-day outage. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

ADT discloses second breach in 2 months, hacked via stolen credentials

Home and small business security company ADT disclosed it suffered a breach after threat actors gained access to its systems using stolen credentials and exfiltrated employee account data. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

LEGO's website hacked to push cryptocurrency scam

On Friday night, cryptocurrency scammers briefly hacked the LEGO website to promote a fake Lego token that could be purchased with Ethereum. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Ukrainian pleads guilty to operating Raccoon Stealer malware

Ukrainian national Mark Sokolovsky has pleaded guilty to his involvement in the Raccoon Stealer malware-as-a-service (MaaS) cybercrime operation. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

American Water shuts down online services after cyberattack

American Water, the largest publicly traded U.S. water and wastewater utility company, was forced to shut down some of its systems after a Thursday cyberattack. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Comcast and Truist Bank customers caught up in FBCS data breach

Comcast Cable Communications and Truist Bank have disclosed they were impacted by a data breach at FBCS, and are now informing their respective customers that their data has been compromised. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Man pleads guilty to stealing $37 million in crypto from 571 victims

A 21-year-old man from Indiana named Evan Frederick Light pleaded guilty to stealing $37,704,560 worth of cryptocurrency from 571 victims in a 2022 cyberattack. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Google Pay alarms users with accidental ‘new card’ added emails

Google Pay alarmed users this week after erroneously sending out "new card" added email notifications. Google has acknowledged that the email was "accidental" and that no user information was compromised. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

MoneyGram: No evidence ransomware is behind recent cyberattack

MoneyGram says there is no evidence that ransomware is behind a recent cyberattack that led to a five-day outage in September. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Recently patched CUPS flaw can be used to amplify DDoS attacks

A recently disclosed vulnerability in the Common Unix Printing System (CUPS) open-source printing system can be exploited by threat actors to launch distributed denial-of-service (DDoS) attacks with a 600x amplification factor. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure

Microsoft and the Justice Department have seized over 100 domains used by the Russian ColdRiver hacking group to target United States government employees and nonprofit organizations from Russia and worldwide in spear-phishing attacks. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks

Approximately 5% of all Adobe Commerce and Magento online stores, or 4,275 in absolute numbers, have been hacked in "CosmicSting" attacks. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Cloudflare blocks largest recorded DDoS attack peaking at 3.8Tbps

During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors, volumetric attacks peaked at 3.8 terabits per second, the largest publicly recorded to date. The assault consisted of a "month-long" barrag … | Continue reading


@bleepingcomputer.com | 1 month ago

Linux malware “perfctl” behind years-long cryptomining campaign

A Linux malware named "perfctl" has been targeting Linux servers and workstations for at least three years, remaining largely undetected through high levels of evasion and the use of rootkits. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Why your password policy should include a custom dictionary

Utilizing a custom dictionaries helps strengthen your password policies. Learn more from Specops Software about how to build custom dictionaries in your Windows Active Directory password policy. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

CISA: Network switch RCE flaw impacts critical infrastructure

U.S. cybersecurity agency CISA is warning about two critical vulnerabilities that allow authentication bypass and remote code execution in Optigo Networks ONS-S8 Aggregation Switch products used in critical infrastructure. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft warns of Windows 11 24H2 gaming performance issues

Microsoft is working to fix several known issues behind Asphalt 8 game crashes and Easy Anti-Cheat blue screens on some Windows 24H2 systems. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Arc browser launches bug bounty program after fixing RCE bug

The Browser Company has introduced an Arc Bug Bounty Program to encourage security researchers to report vulnerabilities to the project and receive rewards. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft fixes Outlook email sending issue for users with many folders

​Microsoft has fixed a known issue affecting Outlook for Microsoft 365 users that caused problems sending emails for those with too many nested folders. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Rackspace monitoring data stolen in ScienceLogic zero-day attack

Cloud hosting provider Rackspace suffered a data breach exposing "limited" customer monitoring data after threat actors exploited a zero-day vulnerability in a third-party tool used by the ScienceLogic SL1 platform. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Ransomware attack forces UMC Health System to divert some patients

Texas healthcare provider UMC Health System was forced to divert some patients to other locations after a ransomware attack impacted its operations. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Evil Corp hit with new sanctions, BitPaymer ransomware charges

The Evil Corp cybercrime syndicate has been hit with new sanctions by the United States, United Kingdom, and Australia. The US also indicted one of its members for conducting BitPaymer ransomware attacks. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Police arrest four suspects linked to LockBit ransomware gang

Law enforcement authorities from 12 countries arrested four suspects linked to the LockBit ransomware gang, including a developer, a bulletproof hosting service administrator, and two people connected to LockBit activity. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Microsoft fixes Windows KB5043145 reboot loops, USB and Bluetooth issues

Microsoft fixes a known issue in the Windows KB5043145 preview update that causes reboot loops, freezes systems, and breaks USB and Bluetooth devices. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Windows 11 24H2 now rolling out, here are the new features

Today, Microsoft announced the release of Windows 11, version 24H2, the next feature update for its operating system (also known as the Windows 11 2024 Update). [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Man charged for selling forged license keys for network switches

The U.S. government has indicted a co-owner of a Minnesota IT company for his participation in an international conspiracy to sell forged license keys for networking devices. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Media giant AFP hit by cyberattack impacting news delivery services

Global news agency AFP (Agence France-Presse) is warning that it suffered a cyberattack on Friday, which impacted IT systems and content delivery services for its partners. [...] | Continue reading


@bleepingcomputer.com | 1 month ago

Windows 11 KB5043145 update causes reboot loops, blue screens

​Microsoft warns that some Windows 11 systems enter reboot loops or might freeze with blue screens after installing the September 2024 KB5043145 preview update. [...] | Continue reading


@bleepingcomputer.com | 1 month ago