OpenAI: ChatGPT payment data leak caused by open-source bug

OpenAI says a Redis client open-source library bug was behind Monday's ChatGPT outage and data leak, where users saw other users' personal information and chat queries. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Procter & Gamble confirms data theft via GoAnywhere zero-day

Consumer goods giant Procter & Gamble has confirmed a data breach affecting an undisclosed number of employees after its GoAnywhere MFT secure file-sharing platform was compromised in early February. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

UK creates fake DDoS-for-hire sites to identify cybercriminals

The U.K.'s National Crime Agency (NCA) revealed today that they created multiple fake DDoS-for-hire service websites to identify cybercriminals who utilize these platforms to attack organizations. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

'Bitter' espionage hackers target Chinese nuclear energy orgs

A cyberespionage hacking group tracked as 'Bitter APT' was recently seen targeting the Chinese nuclear energy industry using phishing emails to infect devices with malware downloaders. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

GitHub.com rotates its exposed private SSH key

GitHub has rotated its private SSH key for GitHub.com after the secret was was accidentally published in a public GitHub repository. The software development and version control service says, the private RSA key was only "briefly" exposed, but that it took action out of "an abund … | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft Teams, Virtualbox, Tesla zero-days exploited at Pwn2Own

During the second day of Pwn2Own Vancouver 2023, competitors were awarded $475,000 after successfully exploiting 10 zero-days in multiple products. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

BlackGuard stealer now targets 57 crypto wallets, extensions

A new variant of the BlackGuard stealer has been spotted in the wild, featuring new capabilities like USB propagation, persistence mechanisms, loading additional payloads in memory, and targeting additional crypto wallets. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

WordPress force patching WooCommerce plugin with 500K installs

Automattic, the company behind the WordPress content management system, is force installing a security update on hundreds of thousands of websites running the highly popular WooCommerce Payments for online stores. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

City of Toronto confirms data theft, Clop claims responsibility

City of Toronto is among Clop ransomware gang's latest victims hit in the ongoing GoAnywhere hacking spree. Other victims listed alongside the Toronto city government include UK's Virgin Group and the statutory corporation, Pension Protection Fund. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New CISA tool detects hacking activity in Microsoft cloud services

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has released a new open-source incident response tool that helps detect signs of malicious activity in Microsoft cloud environments. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 gets phishing protection boost and SHA-3 support

Microsoft announced that the new Windows 11 build rolling out to Insiders in the Canary channel comes with increased protection against phishing attacks and support for SHA-3 cryptographic hash functions. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft fixes Acropalypse privacy bug in Windows 11 Snipping Tool

Microsoft is testing an updated version of the Windows 11 Snipping Tool that fixes a recently disclosed 'Acropalypse' privacy flaw that allows the partial restoration of cropped images. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Exploit released for Veeam bug allowing cleartext credential theft

Cross-platform exploit code is now available for a high-severity Backup Service vulnerability impacting Veeam's Backup & Replication (VBR) software. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

CloudPanel installations use the same SSL certificate private key

Self-hosted web administration solution CloudPanel was found to have several security issues, including using the same SSL certificate private key across all installations and unintentional overwriting of firewall rules to default to weaker settings. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Python info-stealing malware uses Unicode to evade detection

A malicious Python package on PyPI uses Unicode as an obfuscation technique to evade detection while stealing and exfiltrating developers' account credentials and other sensitive data from compromised devices. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11, Tesla, Ubuntu, and macOS hacked at Pwn2Own 2023

On the first day of Pwn2Own Vancouver 2023, security researchers successfully demoed Tesla Model 3, Windows 11, and macOS zero-day exploits and exploit chains to win $375,000 and a Tesla Model 3. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers inject credit card stealers into payment processing modules

A new credit card stealing hacking campaign is doing things differently than we have seen in the past by hiding their malicious code inside the 'Authorize.net' payment gateway module for WooCommcerce, allowing the breach to evade detection by security scans. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Dole discloses employee data breach after ransomware attack

Fresh produce giant Dole Food Company has confirmed that the information of an undisclosed number of employees was accessed during a February ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft adding a USB4 troubleshooting page to Windows 11

Microsoft has released a new Windows 11 preview build that adds a new dedicated USB4 settings page and support for displaying seconds in the system tray clock. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Facebook accounts hijacked by new malicious ChatGPT Chrome extension

A trojanized version of the legitimate ChatGPT extension for Chrome is gaining popularity on the Chrome Web Store, accumulating over 9,000 downloads while stealing Facebook accounts. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

North Korean hackers using Chrome extensions to steal Gmail emails

A joint cybersecurity advisory from the German Federal Office for the Protection of the Constitution (BfV) and the National Intelligence Service of the Republic of Korea (NIS) warn about Kimsuky's use of Chrome extensions to steal target's Gmail emails. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

PoC exploits released for Netgear Orbi router vulnerabilities

Proof-of-concept exploits for vulnerabilities in Netgear's Orbi 750 series router and extender satellites have been released, with one flaw a critical severity remote command execution bug. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 10 KB5023773 preview update released with 10 fixes

Microsoft has released the optional KB5023773 Preview cumulative update for Windows 10 20H2, Windows 10 21H2, and Windows 10 22H2, with ten fixes for various issues. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Defender update behind Windows LSA protection warnings

Microsoft says the KB5007651 Microsoft Defender Antivirus update triggers Windows Security warnings on Windows 11 systems saying that Local Security Authority (LSA) Protection is off. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 Snipping Tool privacy bug exposes cropped image content

A severe privacy flaw named 'acropalypse' has also been found to affect the Windows Snipping Tool, allowing people to partially recover content that was edited out of an image. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers use new PowerMagic and CommonMagic malware to steal data

Security researchers have discovered attacks from an advanced threat actor that used "a previously unseen malicious framework" called CommonMagic and a new backdoor called PowerMagic. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Mozilla Firefox fixes freeze caused by KB5023706 Windows update

Mozilla has addressed a known issue causing the Firefox web browser to freeze on startup on Windows 11 systems after installing the KB5023706 March 2023 cumulative update. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft: Windows preview updates to target last week of the month

Microsoft today announced that optional non-security preview release updates would be released during the fourth week of the month starting in April 2023. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

LockBit ransomware gang now also claims City of Oakland breach

Another ransomware operation, the LockBit gang, now threatens to leak what it describes as files stolen from the City of Oakland's systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Breached hacking forum shuts down, fears it's not 'safe' from FBI

The notorious Breached hacking forum has shut down after the remaining administrator, Baphomet, disclosed that they believe law enforcement has access to the site's servers. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Coinbase Wallet 'Red Pill' flaw allowed attacks to evade detection

Coinbase wallet and other decentralized crypto apps (dapps) were found to be vulnerable to "red pill attacks," a method that can be used to hide malicious smart contract behavior from security features. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Clop ransomware claims Saks Fifth Avenue, retailer says mock data stolen

The Clop ransomware gang claims to have attacked Saks Fifth Avenue on its dark web leak site. Saks admits the incident is linked to the ongoing GoAnywhere MFT software exploits but states that no real customer data was stolen. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Ferrari discloses data breach after receiving ransom demand

Ferrari has disclosed a data breach following a ransom demand received after attackers gained access to some of the company's IT systems. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 bug warns Local Security Authority protection is off

Windows 11 users report seeing widespread Windows Security warnings that Local Security Authority (LSA) Protection has been disabled even though it shows as being toggled on. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

General Bytes Bitcoin ATMs hacked using zero-day, $1.5M stolen

Leading Bitcoin ATM maker General Bytes disclosed that hackers stole cryptocurrency from the company and its customers using a zero-day vulnerability in its BATM management platform. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers target .NET developers with malicious NuGet packages

Threat actors are targeting and infecting .NET developers with cryptocurrency stealers delivered through the NuGet repository and impersonating multiple legitimate packages via typosquatting. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

File-sharing site Zippyshare shutting down after 17 years

File-sharing site Zippyshare has announced they are shutting down the site by the end of March 2023 after announcing they can no longer afford to keep the service running. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hackers mostly targeted Microsoft, Google, Apple zero-days in 2022

Hackers continue to target zero-day vulnerabilities in malicious campaigns, with researchers reporting that 55 zero-days were actively exploited in 2022, most targeting Microsoft, Google, and Apple products. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Google Pixel flaw allowed recovery of redacted, cropped images

An 'Acropalypse' flaw in Google Pixel's Markup tool made it possible to partially recover edited or redacted screenshots and images, including those that have been cropped or had their contents masked, for the past five years. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

New ‘HinataBot’ botnet could launch massive 3.3 Tbps DDoS attacks

A new malware botnet was discovered targeting Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into DDoS (distributed denial of service) swarm with the potential for massive attacks. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Emotet malware now distributed in Microsoft OneNote files to evade defenses

The Emotet malware is now distributed using Microsoft OneNote email attachments, aiming to bypass Microsoft security restrictions and infect more targets. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Windows 11 to ask for permission before pinning applications

Microsoft says it will provide developers with a new API that also asks Windows users for permission when pinning their apps to the taskbar, desktop, or the Start Menu. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Alleged BreachForums owner ‘Pompompurin’ arrested on cybercrime charges

U.S. law enforcement arrested on Wednesday a New York man believed to be Pompompurin, the owner of the BreachForums hacking forum. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

The Week in Ransomware - March 17th 2023 - Shifting to data extortion

The fallout from the Clop ransomware attacks on GoAnywhere platforms has become apparent this week, with the threat actors starting to extort victims on their data leak site and companies confirming breaches. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

NBA alerts fans of a data breach exposing personal information

The NBA (National Basketball Association) is notifying fans of a data breach after some of their personal information, "held" by a third-party newsletter service, was stolen. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Microsoft is testing a built-in crypto wallet in Microsoft Edge

Microsoft is working on a non-custodial built-in Ethereum crypto wallet for Microsoft Edge to allow users to send and receive cryptocurrency and NFTs. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

Hitachi Energy confirms data breach after Clop GoAnywhere attacks

Hitachi Energy confirmed it suffered a data breach after the Clop ransomware gang stole data using a zero-day GoAnyway zero-day vulnerability. [...] | Continue reading


@bleepingcomputer.com | 1 year ago

RAT developer arrested for infecting 10,000 PCs with malware

Ukraine's cyberpolice has arrested the developer of a remote access trojan (RAT) malware that infected over 10,000 computers while posing as game applications. [...] | Continue reading


@bleepingcomputer.com | 1 year ago