CISA, FBI urge admins to patch Atlassian Confluence immediately

CISA, FBI, and MS-ISAC warned network admins today to immediately patch their Atlassian Confluence servers against a maximum severity flaw actively exploited in attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft fixes Windows 10 security update installation issue

Microsoft has resolved a known issue that caused Windows 10 security updates released during this month's Patch Tuesday to fail with 0x8007000d errors. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Signal says there is no evidence rumored zero-day bug is real

Signal messenger has investigated rumors spreading online over the weekend of a zero-day security vulnerability related to the 'Generate Link Previews' feature, stating that there is no evidence this vulnerability is real. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Steam enforces SMS verification to curb malware-ridden updates

Valve has announced implementing additional security measures for developers publishing games on Steam, including SMS-based confirmation codes. This is to deal with a recent outbreak of malicious updates pushing malware from compromised publisher accounts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Women Political Leaders Summit targeted in RomCom malware phishing

A new, lightweight variant of the RomCom backdoor was deployed against participants of the Women Political Leaders (WPL) Summit in Brussels, a summit focusing on gender equality and women in politics. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

AI algorithm detects MitM attacks on unmanned military vehicles

Professors at the University of South Australia and Charles Sturt University have developed an algorithm to detect and intercept man-in-the-middle (MitM) attacks on unmanned military robots. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

DarkGate malware spreads through compromised Skype accounts

Between July and September, DarkGate malware attacks have used compromised Skype accounts to infect targets through messages containing VBA loader script attachments. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ubuntu discovers 'hate speech' in release 23.10 — how to upgrade?

Ubuntu, the most popular Linux distribution, has pulled its Desktop release 23.10 after its Ukrainian translations were discovered to contain hate speech. According to the Ubuntu project, a malicious contributor is behind anti-Semitic, homophobic, and xenophobic slurs that were i … | Continue reading


@bleepingcomputer.com | 1 year ago

The Week in Ransomware - October 13th 2023 - Increasing Attacks

Ransomware gangs continue to pummel the enterprise, with attacks causing disruption in business operations and resulting in data breaches if a ransom is not paid. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

23andMe hit with lawsuits after hacker leaks stolen genetics data

Genetic testing provider 23andMe faces multiple class action lawsuits in the U.S. following a large-scale data breach that is believed to have impacted millions of its customers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: October Windows 10 security updates fail to install

Microsoft says Windows 10 security updates released during this month's Patch Tuesday may fail to install with 0x8007000d errors, although initially displaying progress. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Kwik Trip IT systems outage caused by mysterious ‘network incident’

​Kwik Trip has been impacted by a wide range of mysterious business disruptions since this weekend that are indicative of a ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft plans to kill off NTLM authentication in Windows 11

Microsoft announced earlier this week that the NTLM authentication protocol will be killed off in Windows 11 in the future. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers use Binance Smart Chain contracts to store malicious scripts

Cybercriminals are employing a novel code distribution technique dubbed 'EtherHiding,' which abuses Binance's Smart Chain (BSC) contracts to hide malicious scripts in the blockchain. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CISA shares vulnerabilities, misconfigs used by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has unveiled additional details regarding misconfigurations and security vulnerabilities exploited by ransomware gangs, aiming to help critical infrastructure organizations thwart their attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

FBI shares AvosLocker ransomware technical details, defense tips

The U.S. government has updated the list of tools AvosLocker ransomware affiliates use in attacks to include open-source utilities along with custom PowerShell, and batch scripts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ransomware attacks now target unpatched WS_FTP servers

Internet-exposed WS_FTP servers unpatched against a maximum severity vulnerability are now targeted in ransomware attacks.  [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Malicious Solana, Kucoin packages infect NuGet devs with SeroXen RAT

Malicious NuGet packages appearing to have over 2 million downloads impersonate crypto wallets, crypto exchange, and Discord libraries to infect developers with the SeroXen remote access trojan. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Microsoft bug bounty program focuses on AI-powered Bing

Microsoft announced a new AI bounty program focused on the AI-driven Bing experience, with rewards reaching $15,000. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Apple fixes iOS Kernel zero-day vulnerability on older iPhones

Apple has published security updates for older iPhones and iPads to backport patches released one week ago, addressing two zero-day vulnerabilities exploited in attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

ToddyCat hackers use 'disposable' malware to target Asian telecoms

A newly discovered campaign dubbed "Stayin' Alive" has been targeting government organizations and telecommunication service providers across Asia since 2021, using a wide variety of "disposable" malware to evade detection. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hyped up curl vulnerability falls short of expectations

curl 8.4.0 has been released to patch and release details on a hyped up high-severity security vulnerability (CVE-2023-38546), easing week-long concerns regarding the flaw's severity. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Shadow PC warns of data breach as hacker tries to sell gamers' info

Shadow PC, a provider of high-end cloud computing services, is warning customers of a data breach that exposed customers' private information, as a threat actor claims to be selling the stolen data for over 500,000 customers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New WordPress backdoor creates rogue admin to hijack websites

A new malware has been posing as a legitimate caching plugin to target WordPress sites, allowing threat actors to create an administrator account and control the site's activity. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

BianLian extortion group claims recent Air Canada breach

The BianLian extortion group claims to have stolen 210GB of data after breaching the network of Air Canada, the country's largest airline and a founding member of Star Alliance. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Defender now auto-isolates compromised accounts

Microsoft Defender for Endpoint now uses automatic attack disruption to isolate compromised user accounts and block lateral movement in hands-on-keyboard attacks with the help of a new 'contain user' capability in public preview. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Exchange Online mail delivery issues caused by anti-spam rules

Microsoft is investigating Exchange Online mail delivery issues causing "Server busy" errors and delays when receiving emails from outside organizations. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 21H2 and Windows Server 2012 reach end of support

Windows Server 2012 and multiple editions of Windows 11, version 21H2, have reached the end of support with this month's Patch Tuesday. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: State hackers exploiting Confluence zero-day since September

Microsoft says a Chinese-backed threat group tracked as 'Storm-0062' (aka DarkShadow or Oro0lxy) has been exploiting a critical privilege escalation zero-day in the Atlassian Confluence Data Center and Server since September 14, 2023. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Generative AI Security: Preventing Microsoft Copilot Data Exposure

Microsoft Copilot introduces potential privacy risks as it can have full access to your organization's documents, email, contacts, chats, and calendar. Learn more from Varonis about Microsoft Copilot's security model works and the privacy risks associated with using it. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Simpson Manufacturing shuts down IT systems after cyberattack

Simpson Manufacturing disclosed via a SEC 8-K filing a cybersecurity incident that has caused disruptions in its operations, which are expected to continue. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

LinkedIn Smart Links attacks return to target Microsoft accounts

Hackers are once again abusing LinkedIn Smart Links in phishing attacks to bypass protection measures and evade detection in attempts to steal Microsoft account credentials. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft warns of incorrect BitLocker encryption errors

Microsoft warned customers this week of incorrect BitLocker drive encryption errors being shown in some managed Windows environments. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Mirai DDoS malware variant expands targets with 13 router exploits

A Mirai-based DDoS (distributed denial of service) malware botnet tracked as IZ1H9 has added thirteen new payloads to target Linux-based routers and routers from D-Link, Zyxel, TP-Link, TOTOLINK, and others. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Exchange gets ‘better’ patch to mitigate critical bug

The Exchange Team asked admins to deploy a new and "better" patch for a critical Microsoft Exchange Server vulnerability initially addressed in August. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 10 KB5031356 update released with 25 improvements

Microsoft has released the KB5031356 cumulative update for Windows 10 21H2 and Windows 10 22H2, with twenty-five fixes for various issues. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft October 2023 Patch Tuesday fixes 3 zero-days, 104 flaws

Today is Microsoft's October 2023 Patch Tuesday, with security updates for 104 flaws, including three actively exploited zero-day vulnerabilities. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Air Europa data breach: Customers warned to cancel credit cards

Spanish airline Air Europa, the country's third-largest airline and a member of the SkyTeam alliance, warned customers on Monday to cancel their credit cards after attackers accessed their card information in a recent data breach. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft to kill off VBScript in Windows to block malware delivery

Microsoft is planning to phase out VBScript in future Windows releases after 30 years of use, making it an on-demand feature until it is removed. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New critical Citrix NetScaler flaw exposes 'sensitive' data

Citrix NetScaler ADC and NetScaler Gateway are impacted by a critical severity flaw that allows the disclosure of sensitive information from vulnerable appliances. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New 'HTTP/2 Rapid Reset' zero-day attack breaks DDoS records

A new DDoS (distributed denial of service) technique named 'HTTP/2 Rapid Reset' has been actively exploited as a zero-day since August, breaking all previous records in magnitude. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

A Primer on Cyber Risk Acceptance and What it Means to Your Business

A fundamental idea to understand about risk is that it is inevitable. Learn more from Outpost24 on cyber risk acceptance and the role of continuous penetration testing in making informed risk acceptance decisions. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google makes passkeys the default sign-in for personal accounts

Google announced today that passkeys are now the default sign-in option across all personal Google Accounts across its services and platforms. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

D-Link WiFi range extender vulnerable to command injection attacks

The popular D-Link DAP-X1860 WiFi 6 range extender is susceptible to a vulnerability allowing DoS (denial of service) attacks and remote command injection. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

ALPHV ransomware gang claims attack on Florida circuit court

The ALPHV (BlackCat) ransomware gang has claimed an attack that affected state courts across Northwest Florida (part of the First Judicial Circuit) last week. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

GNOME Linux systems exposed to RCE attacks via file downloads

A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on GNOME Linux systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 17,000 WordPress sites hacked in Balada Injector attacks last month

Multiple Balada Injector campaigns have compromised and infected over 17,000 WordPress sites using known flaws in premium theme plugins. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers modify online stores’ 404 pages to steal credit cards

A new Magecart card skimming campaign hijacks the 404 error pages of online retailer's websites, hiding malicious code to steal customers' credit card information. [...] | Continue reading


@bleepingcomputer.com | 1 year ago