Shutterfly says Clop ransomware attack did not impact customer data

Shutterfly, an online retail and photography manufacturing platform, is among the latest victims hit by Clop ransomware. Over the last few months, Clop ransomware gang has been exploiting a vulnerability in the MOVEit File Transfer utility to breach hundreds of companies to steal … | Continue reading


@bleepingcomputer.com | 1 year ago

AVrecon malware infects 70,0000 Linux routers to build botnet

Since at least May 2021, stealthy Linux malware called AVrecon was used to infect over 70,000 Linux-based small office/home office (SOHO) routers to a botnet designed to steal bandwidth and provide a hidden residential proxy service. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Cisco SD-WAN vManage impacted by unauthenticated REST API access

The Cisco SD-WAN vManage management software is impacted by a flaw that allows an unauthenticated, remote attacker to gain read or limited write permissions to the configuration of the affected instance. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google Play will enforce business checks to curb malware submissions

Google is fighting back against the constant invasion of malware on Google Play by requiring all new developer accounts registering as an organization to provide a valid D-U-N-S number before submitting apps. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 23H2 coming this fall as a small enablement package

Microsoft announced today that the upcoming Windows 11, version 23H2, will be available in the fourth quarter of 2023 as an enablement package since it shares Windows 11 22H2's code base and servicing branch. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fake Linux vulnerability exploit drops data-stealing malware

​Cybersecurity researchers and threat actors are targeted by a fake proof of concept (PoC) CVE-2023-35829 exploit that installs a Linux password-stealing malware. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Zimbra urges admins to manually fix zero-day exploited in attacks

Zimbra urged admins today to manually fix a zero-day vulnerability actively exploited to target and compromise Zimbra Collaboration Suite (ZCS) email servers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Source code for BlackLotus Windows UEFI malware leaked on GitHub

The source code for the BlackLotus UEFI bootkit has leaked online, allowing greater insight into a malware that has caused great concern among the enterprise, governments, and the cybersecurity community. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Cyberattacks through Browser Extensions – the Importance of MFA

More and more attacks are occurring via browser extensions or user-profile installations of tools. Learn more about these attacks from Specops Software and what you can do to protect yourself. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

USB drive malware attacks spiking again in first half of 2023

What's old is new again, with researchers seeing a threefold increase in malware distributed through USB drives in the first half of 2023 [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New PyLoose Linux malware mines crypto directly from memory

A new fileless malware named PyLoose has been targeting cloud workloads to hijack their computational resources for Monero cryptocurrency mining. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Apple re-releases zero-day patch after fixing browsing issue

Apple fixed and re-released emergency security updates addressing a WebKit zero-day vulnerability exploited in attacks. The initial patches had to be withdrawn on Monday due to browsing issues on certain websites. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

SonicWall warns admins to patch critical auth bypass bugs immediately

SonicWall warned customers today to urgently patch multiple critical vulnerabilities impacting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Russian state hackers lure Western diplomats with BMW car ads

The Russian state-sponsored hacking group 'APT29' (aka Nobelium, Cloaked Ursa) has been using unconventional lures like car listings to entice diplomats in Ukraine to click on malicious links that deliver malware. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New Windows 11 build ships with more Rust-based Kernel features

Microsoft announced that the latest Windows 11 build shipping to Insiders in the Canary channel comes with additional Windows Kernel components rewritten in the memory safety-focused Rust programming language. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Critical RCE found in popular Ghostscript open-source PDF library

Ghostscript, an open-source interpreter for PostScript language and PDF files widely used in Linux, has been found vulnerable to a critical-severity remote code execution flaw. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

GitHub goes passwordless, announces passkeys beta preview

GitHub announced today the introduction of passwordless authentication support in public beta, allowing users to upgrade from security keys to passkeys. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Fortinet warns of critical RCE flaw in FortiOS, FortiProxy devices

Fortinet has disclosed a critical severity flaw impacting FortiOS and FortiProxy, allowing a remote attacker to perform arbitrary code execution on vulnerable devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ransomware payments on record-breaking trajectory for 2023

Data from the first half of the year indicates that ransomware activity is on track to break previous records, seeing a rise in the number of payments, both big and small. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Chinese hackers breached US govt Exchange email accounts

A Chinese hacking group has breached the email accounts of more than two dozen organizations worldwide, including U.S. and Western European government agencies, according to Microsoft. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

What's new in the Windows 11 22H2 Moment 3 update, now available

Microsoft has begun the forced rollout of its Windows 11 22H2 'Moment 3' update, which introduces several new features and improvements to the operating system [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Unpatched Office zero-day exploited in NATO summit attacks

Microsoft disclosed today an unpatched zero-day security bug in multiple Windows and Office products exploited in the wild to gain remote code execution via malicious Office documents. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 10 KB5028168 and KB5028166 updates released

Microsoft has released Windows 10 KB5028166 and KB5028168 cumulative updates for versions 22H2, version 21H2, and 1809 to fix problems and add new features to the operating system. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft July 2023 Patch Tuesday warns of 6 zero-days, 132 flaws

Today is Microsoft's July 2023 Patch Tuesday, with security updates for 132 flaws, including six actively exploited and thirty-seven remote code execution vulnerabilities. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers exploit Windows policy to load malicious kernel drivers

Microsoft blocked code signing certificates predominantly used by Chinese hackers and developers to sign and load malicious kernel mode drivers on breached systems by exploiting a Windows policy loophole. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft rebrands Azure Active Directory to Microsoft Entra ID

Microsoft announced today that it would change the name of its Azure Active Directory (Azure AD) enterprise identity service to Microsoft Entra ID by the end of the year. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Deutsche Bank confirms provider breach exposed customer data

Deutsche Bank AG has confirmed to BleepingComputer that a data breach on one of its service providers has exposed its customers' data in a likely MOVEit Transfer data-theft attack. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Apple confirms WebKit security updates break browsing on some sites

Apple confirmed today that emergency security updates released on Monday to address a zero-day bug exploited in attacks break browsing on some websites, and new ones will be released soon to address this known issue. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

HCA confirms breach after hacker steals data of 11 million patients

HCA Healthcare disclosed a data breach impacting an estimated 11 million patients who received care at one of its hospitals and clinics after a threat actor posted samples of stolen data on a hacking forum. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft finally fixes broken Surface Pro X laptop cameras

Microsoft is finally rolling out a driver update to address a known issue causing built-in cameras on ARM-based Windows devices (including Surface Pro X laptops) to stop working. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

RomCom hackers target NATO Summit attendees in phishing attacks

A threat actor referred to as 'RomCom' has been targeting organizations supporting Ukraine and guests of the upcoming NATO Summit set to start tomorrow in Vilnius, Lithuania. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

VMware warns of exploit available for critical vRealize RCE bug

VMware warned customers today that exploit code is now available for a critical vulnerability in the VMware Aria Operations for Logs analysis tool, which helps admins manage terabytes worth of app and infrastructure logs in large-scale environments. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Amazon's AppStore is getting more apps and games on Windows 11

In collaboration with Microsoft, Amazon has announced the general availability of its AppStore on Windows 11 for all developers. This means more apps and games are coming to Windows 11 as Amazon developers can now easily access the AppStore for Windows and bring their Amazon Stor … | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Windows 11 21H2 reaching end of service in October

Microsoft warned customers today that multiple editions of Windows 11, version 21H2, will reach the end-of-service (EOS) in three months, on October 10, 2023. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Apple releases emergency update to fix zero-day exploited in attacks

Apple has issued a new round of Rapid Security Response (RSR) updates to address a new zero-day bug exploited in attacks and impacting fully-patched iPhones, Macs, and iPads. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Former employee charged for attacking water treatment plant

A former employee of Discovery Bay Water Treatment Facility in California was indicted by a federal grand jury for intentionally attempting to cause malfunction to the facility's safety and protection systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hands on with Windows Copilot - A Bing.com web wrapper

The first preview of Windows Copilot falls short of expectations. Though it promises features like turning on simple settings like switching to dark mode, the 'AI integration' feels far from native. In fact, Copilot feels like a web wrapper, a pane running Bing.com within Microso … | Continue reading


@bleepingcomputer.com | 1 year ago

Razer investigates data breach claims, resets user sessions

Gaming gear company Razer reacted to recent rumors of a massive data breach with a short statement on Twitter, letting users know that they started an investigation into the matter. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Edge's Bing AI sidebar will remember previous conversations

Bing AI sidebar in Edge does not currently support recalling previous conversations. Microsoft plans to address this issue by adding a memory feature, allowing Bing AI to remember and continue from where a user left off in a previous interaction. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Streamlining security operations with automated incident response

Automated incident response solutions help reduce the mean time to respond to incidents, address known security threats, and also minimize alert fatigue. Learn more about these solutions from Wazuh, the open source XDR/SIEM platform. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Edge Canary update on Windows adds mouse gestures flag

In a bid to enhance user experience, Microsoft has reintroduced mouse gestures in its Edge Canary version, a feature previously present in legacy Edge before the transition to Chromium. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Chrome's big design refresh uses Microsoft Mica effect in custom themes

Google is working on a significant design overhaul for Chrome across Windows, Mac, and Chromebook platforms. Named Chrome's Material You-based, the project is close to roll out and is set to introduce a series of fresh aesthetic changes that significantly alter the browser's inte … | Continue reading


@bleepingcomputer.com | 1 year ago

Charming Kitten hackers use new ‘NokNok’ malware for macOS

Security researchers observed a new campaign they attribute to the Charming Kitten APT group where hackers used new NokNok malware that targets macOS systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows Subsystem for Android gets July 2023 preview with new features

Today's update introduces several significant Android Windows Subsystem improvements. Firstly, enhancements have been made to camera compatibility, thus improving the experience of using Android apps that require camera access. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

AMD releases Adrenalin 23.7.1 WHQL driver for Windows

After a long break, AMD has launched a new graphics driver, Adrenalin 23.7.1 WHQL (driver version 23.10.01.45). [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Instagram's Threads to get Twitter-like hashtags support, edit button and more

Instagram's dedicated text-sharing app, Threads, is set to introduce many new features, including Twitter-style hashtags, an edit button, a trending page, and possibly even an automatic archiving function. Instagram's Head, Adam Mosseri, confirmed these upcoming features in a ser … | Continue reading


@bleepingcomputer.com | 1 year ago

New ‘Big Head’ ransomware displays fake Windows update alert

Security researchers have dissected a recently emerged ransomware strain named 'Big Head' that may be spreading through malvertising that promotes fake Windows updates and Microsoft Word installers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CISA warns govt agencies to patch actively exploited Android driver

CISA ordered federal agencies today to patch a high-severity Arm Mali GPU kernel driver privilege escalation flaw added to its list of actively exploited vulnerabilities and addressed with this month's Android security updates. [...] | Continue reading


@bleepingcomputer.com | 1 year ago