Trojanized Signal and Telegram apps on Google Play delivered spyware

Trojanized Signal and Telegram apps containing the BadBazaar spyware were uploaded onto Google Play and Samsung Galaxy Store by a Chinese APT hacking group known as GREF. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

How the FBI nuked Qakbot malware from infected Windows PCs

The FBI announced today the disruption of the Qakbot botnet in an international law enforcement operation that not only seized infrastructure but also uninstalled the malware from infected devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

DreamBus malware exploits RocketMQ flaw to infect servers

A new version of the DreamBus botnet malware exploits a critical-severity remote code execution vulnerability in RocketMQ servers to infect devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Android MMRat malware uses Protobuf protocol to steal your data

A novel Android banking malware named MMRat utilizes a rarely used communication method, protobuf data serialization, to more efficiently steal data from compromised devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Qakbot botnet dismantled after infecting over 700,000 computers

Qakbot, one of the largest and longest-running botnets to date, was taken down following a multinational law enforcement operation spearheaded by the FBI and known as Operation 'Duck Hunt.' [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft adds HSTS support to Exchange Server 2016 and 2019

Microsoft announced today that Exchange Server 2016 and 2019 now come with support for HTTP Strict Transport Security (also known as HSTS). [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers exploit critical Juniper RCE bug chain after PoC release

Hackers have started using a critical exploit chain to target Juniper EX switches and SRX firewalls via their Internet-exposed J-Web configuration interface. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

University of Michigan shuts down network after cyberattack

The University of Michigan has taken all of its systems and services offline to deal with a cybersecurity incident, causing a widespread impact on online services the night before classes started. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Genshin Impact dev will sue Kaveh Hacks users and developers

Genshin Impact developer miHoYohas responded to an in-game hacking situation that has caused problems recently in its player community, warning that they would take legal action against those responsible. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

US govt email servers hacked in Barracuda zero-day attacks

Suspected Chinese hackers disproportionately targeted and breached government and government-linked organizations worldwide in recent attacks targeting a Barracuda Email Security Gateway (ESG) zero-day, with a focus on entities across the Americas. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Attacks on Citrix NetScaler systems linked to ransomware actor

A threat actor believed to be tied to the FIN8 hacking group exploits the CVE-2023-3519 remote code execution flaw to compromise unpatched Citrix NetScaler systems in domain-wide attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

MalDoc in PDFs: Hiding malicious Word docs in PDF files

Japan's computer emergency response team (JPCERT) is sharing a new 'MalDoc in PDF' attack detected in July 2023 that bypasses detection by embedding malicious Word files into PDFs. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft will enable Exchange Extended Protection by default this fall

Microsoft announced today that Windows Extended Protection will be enabled by default on servers running Exchange Server 2019 starting this fall after installing the 2023 H2 Cumulative Update (CU14). [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Spain warns of LockBit Locker ransomware phishing attacks

The National Police of Spain is warning of an ongoing 'LockBit Locker' ransomware campaign targeting architecture companies in the country through phishing emails. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft blames ‘unsupported processor’ blue screens on OEM vendors

Microsoft says the recent wave of blue screens impacting some Windows users is not caused by issues in its August 2023 optional updates. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Exploit released for Juniper firewall bugs allowing RCE attacks

Proof-of-concept exploit code has been publicly released for vulnerabilities in Juniper SRX firewalls that, when chained, can allow unauthenticated attackers to gain remote code execution in Juniper's JunOS on unpatched devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Mom’s Meals service discloses data breach impacting 1.2 million

PurFoods, which conducts business in the U.S. as 'Mom's Meals,' is warning of a data breach after the personal information of 1.2 million customers and employees was stolen in a ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Four common password mistakes hackers love to exploit

Threat actors take advantage of common password mistakes to breach corporate networks. Learn more from Specops Software on the four most common mistakes and how to strengthen your Active Directory against these risks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Rhysida claims ransomware attack on Prospect Medical, threatens to sell data

The Rhysida ransomware gang has claimed responsibility for the massive cyberattack on Prospect Medical Holdings, claiming to have stolen 500,000 social security numbers, corporate documents, and patient records. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft wants you to learn more about new features in Windows 11

Microsoft is experimenting with different approaches to introduce new users to Windows 11's features as soon as they complete the initial setup, also known as the "Out of Box Experience" (OOBE). [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Data breach at French govt agency exposes info of 10 million people

Pôle emploi, France's governmental unemployment registration and financial aid agency, is informing of a data breach that exposed data belonging to 10 million individuals. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

MSI: Recent wave of Windows blue screens linked to MSI motherboards

MSI has officially confirmed the recent surge of blue screens of death (BSODs) encountered by Windows users after installing this week's optional preview updates is linked to some of its motherboard models. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

ICO calls social media firms to protect people's data from scraping

UK's Information Commissioner's Office (ICO), together with eleven data protection and privacy authorities from around the world, have published a statement calling social media platforms to up their protections against data scrapers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Stealthy Flax Typhoon hackers use LOLBins to evade detection

Microsoft has identified a new hacking group it now tracks as Flax Typhoon that argets government agencies and education, critical manufacturing, and information technology organizations likely for espionage purposes. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Leaseweb is restoring ‘critical’ systems after security breach

Leaseweb, one of the world's largest cloud and hosting providers, notified people that it's working on restoring "critical" systems disabled following a recent security breach. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors

Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted in exposing to an unauthorized third-party the personal data of some credit claimants. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

FBI warns of patched Barracuda ESG appliances still being hacked

The Federal Bureau of Investigation warned that patches for a critical Barracuda Email Security Gateway (ESG) remote command injection flaw are "ineffective," and patched appliances are still being compromised in ongoing attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ransomware hackers dwell time drops to 5 days, RDP still widely used

Ransomware threat actors are spending less time on compromised networks before security solutions sound the alarm. In the first half of the year the hackers' median dwell time dropped to five days from nine in 2022 [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Jupiter X Core WordPress plugin could let hackers hijack sites

Two vulnerabilities affecting some version of Jupiter X Core, a premium plugin for setting up WordPress and WooCommerce websites, allow hijacking accounts and uploading files without authentication. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Windows updates cause UNSUPPORTED_PROCESSOR blue screens

Microsoft says the August 2023 preview updates released this week for Windows 11 and Windows 10 systems are causing blue screens with errors mentioning an unsupported processor issue. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Whiffy Recon malware uses WiFi to triangulate your location

Cybercriminals behind the Smoke Loader botnet are using a new piece of malware called Whiffy Recon to triangulate the location of infected devices through WiFi scanning and Google's geolocation API. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Exploit released for Ivanti Sentry bug abused as zero-day in attacks

Proof-of-concept exploit code is now available for a critical Ivanti Sentry authentication bypass vulnerability that enables attackers to execute code remotely as root on vulnerable systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Last call for mWISE, the security conference for frontline practitioners.

We're down to the final weeks of registration for mWISE, the community-focused cybersecurity conference from Mandiant. Learn more from Mandiant about the available attendance options and what you should expect. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers use public ManageEngine exploit to breach internet org

The North Korean state-backed hacker group tracked as Lazarus has been exploiting a critical vulnerability (CVE-2022-47966) in Zoho's ManageEngine ServiceDesk to compromise an internet backbone infrastructure provider and healthcare organizations. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Lapsus$ teen hackers convicted of high-profile cyberattacks

A London jury has found that an 18-year-old member of the Lapsus$ data extortion gang helped hack multiple high-profile companies, stole data from them, and demanded a ransom threatening to leak the information. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 10 KB5029331 update introduces a new Backup app

Microsoft has released the optional KB5029331 Preview cumulative update for Windows 10 22H2 with sixteen improvements or fixes, including the introduction of a new Backup app. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Over 3,000 Openfire servers vulnerable to takover attacks

Thousands of Openfire servers remain vulnerable to CVE-2023-32315, an actively exploited and path traversal vulnerability that allows an unauthenticated user to create new admin accounts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Bitwarden releases free and open-source E2EE Secrets Manager

Bitwarden, the maker of the popular open-source password manager tool, has released 'Secrets Manager,' an end-to-end encrypted secrets manager for IT professionals, software development teams, and the DevOps industry. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Discord starts notifying users affected by March data breach

Starting on Monday, Discord has been reaching out to users affected by a data breach disclosed earlier this year to let them know what Personal Identifying Information (PII) was exposed in the incident. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New stealthy techniques let hackers gain Windows SYSTEM privileges

Security researchers have released NoFilter, a tool that abuses the Windows Filtering Platform to elevate a user's privileges to increases privileges to SYSTEM, the highest permission level on Windows. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

US charges founders of Tornado Cash mixer used by Lazarus hackers

The U.S. Justice Department charged two Tornado Cash founders with helping criminals, including the notorious North Korean Lazarus hacking group, launder over $1 billion worth of stolen cryptocurrency through their decentralized crypto mixing service. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Kali Linux 2023.3 released with 9 new tools, internal changes

Kali Linux 2023.3, the third version of 2023, is now available for download, with nine new tools and internal optimizations. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google Workspace will require two admins to sign off on critical changes

Google announced today new cybersecurity defense controls that will allow security teams to thwart account takeover attempts and social engineering attacks targeting Workspace users. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

FBI: Lazarus hackers readying to cash out $41 million in stolen crypto

The FBI warned that North Koreans are likely readying to cash out tens of millions worth of stolen cryptocurrency out of hundreds of millions stolen in the last year alone. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hosting firm says it lost all customer data after ransomware attack

Danish hosting firms CloudNordic and AzeroCloud have suffered ransomware attacks, causing the loss of the majority of customer data and forcing the hosting providers to shut down all systems, including websites, email, and customer sites. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

The MOVEit hack and what it taught us about application security

When a cyberattack like the 2023 MOVEit hack makes global news headlines, attention often focuses on the names of the affected organizations. This article from @Outpost24 overviews the Moveit hack and aims to draw some important actionable takeaways for your business. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

WinRAR zero-day exploited since April to hack trading accounts

A WinRar zero-day vulnerability tracked as CVE-2023-38831 was actively exploited to install malware when clicking on harmless files in an archive, allowing the hackers to breach online cryptocurrency trading accounts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Scraped data of 2.6 million Duolingo users released on hacking forum

The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information. [...] | Continue reading


@bleepingcomputer.com | 1 year ago