Samsung to pay $1,000,000 for RCEs on Galaxy’s secure vault

Samsung has launched a new bug bounty program for its mobile devices with rewards of up to $1,000,000 for reports demonstrating critical attack scenarios. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

France's Grand Palais discloses cyberattack during Olympic games

The Grand Palais Réunion des musées nationaux (Rmn) in France is warning that it suffered a cyberattack on Saturday night, August 3, 2024. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

Hacker wipes 13,000 devices after breaching classroom management platform

A hacker has breached Mobile Guardian, a digital classroom management platform used worldwide, and remotely wiped data from at least 13,000 student's iPads and Chromebooks. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

Point of entry: Why hackers target stolen credentials for initial access

Stolen credentials are a big problem, commonly used to breach networks in attacks. Learn more from Specops Software about checking the password hygiene of your Active Directory. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

Proton VPN adds ‘Discreet Icons’ to hide app on Android devices

Proton VPN has announced a series of updates to its Windows and Android apps to help users combat censorship, circumvent blocks, and protect themselves from authoritarian governments due to using forbidden tools. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

Proofpoint settings exploited to send millions of phishing emails daily

A massive phishing campaign dubbed "EchoSpoofing" exploited a security gap in Proofpoint's email protection service to dispatch millions of spoofed emails impersonating big entities like Disney, Nike, IBM, and Coca-Cola, to target Fortune 100 companies. [...] | Continue reading


@bleepingcomputer.com | 3 months ago

Windows 11 taskbar has a hidden "End Task" feature, how to turn it on

Microsoft has added a feature to Windows 11 that allows you to end tasks directly from the taskbar. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

X begins training Grok AI with your posts, here's how to disable

X has quietly begun training its Grok AI chat platform using members' public posts without first alerting anyone that it is doing it by default. Here's how to block Grok from using your data. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

WhatsApp for Windows lets Python, PHP scripts execute with no warning

A security issue in the latest version of WhatsApp for Windows allows sending Python and PHP attachments that are executed without any warning when the recipient opens them. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Crypto exchange Gemini discloses third-party data breach

Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated Clearing House (ACH) service provider, whose name was not disclosed. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

FBCS data breach impact now reaches 4.2 million people

Debt collection agency Financial Business and Consumer Solutions (FBCS) has again increased the number of people impacted by a February data breach, now saying it affects 4.2 million people in the US. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Acronis warns of Cyber Infrastructure default password abused in attacks

​Acronis warned customers to patch a critical Cyber Infrastructure security flaw that lets attackers bypass authentication on vulnerable servers using default credentials. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

PKfail Secure Boot bypass lets attackers install UEFI malware

Hundreds of UEFI products from 10 vendors are susceptible to compromise due to a critical firmware supply-chain issue known as PKfail, which allows attackers to bypass Secure Boot and install malware. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

US offers $10M for tips on DPRK hacker linked to Maui ransomware attacks

The U.S. State Department is offering a reward of up to $10 million for information that could lead to the identification or location of a North Korean military hacker. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

French police push PlugX malware self-destruct payload to clean PCs

The French police and Europol are pushing out a "disinfection solution" that automatically removes the PlugX malware from infected devices in France. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Why Multivendor Cybersecurity Stacks Are Increasingly Obsolete

Multivendor tech stacks are costly and complex to integrate and manage. Learn more from Cynet about how an All-in-One approach reduces costs for MSPs and SMEs, while offering increased security. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Over 3,000 GitHub accounts used by malware distribution service

Threat actors known as 'Stargazer Goblin' have created a malware Distribution-as-a-Service (DaaS) from over 3,000 fake accounts on GitHub that push information-stealing malware. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Docker fixes critical 5-year old authentication bypass flaw

Docker has issued security updates to address a critical vulnerability impacting certain versions of Docker Engine that could allow an attacker to bypass authorization plugins (AuthZ) under certain circumstances. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Google Chrome now warns about risky password-protected archives

Google Chrome now warns when downloading risky password-protected files and provides improved alerts with more information about potentially malicious downloaded files. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

CrowdStrike: 'Content Validator' bug let faulty update pass checks

CrowdStrike released a Preliminary Post Incident Review (PIR) on the faulty Falcon update explaining that a bug allowed bad data to pass its Content Validator and cause millions of Windows systems to crash on July 19, 2024. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Hot topics: Can’t-miss sessions at Mandiant’s 2024 mWISE event

Now that the mWISE 2024 session catalog is out, it's time to take a closer look at the topics. Learn more from @mWISEConference about the three hottest tracks in this year's conference. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Windows July security updates send PCs into BitLocker recovery

Microsoft warned that some Windows devices will boot into BitLocker recovery after installing the July 2024 Windows security updates. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

BreachForums v1 database leak is an OPSEC test for hackers

The entire database for the notorious BreachForums v1 hacking forum was released on Telegram Tuesday night, exposing a treasure trove of data, including members' information, private messages, cryptocurrency addresses, and every post on the forum. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Chinese hackers deploy new Macma macOS backdoor version

The Chinese hacking group tracked as 'Evasive Panda' was spotted using new versions of the Macma backdoor and the Nightdoor Windows malware. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Hamster Kombat’s 250 million players targeted in malware attacks

Threat actors are taking advantage of the massive popularity of the Hamster Kombat game, targeting players with fake Android and Windows software that install spyware and information-stealing malware. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Windows 10 KB5040525 fixes WDAC issues causing app failures, memory leak

Microsoft has released the July 2024 preview update for Windows 10, version 22H2, with fixes for Windows Defender Application Control (WDAC) issues causing app crashes and system memory exhaustion. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

DeFi exchange dYdX v3 website hacked in DNS hijack attack

Decentralized finance (DeFi) crypto exchange dYdX announced on Tuesday that the website for its older v3 trading platform has been compromised. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Verizon to pay $16 million in TracFone data breach settlement

Verizon Communications has agreed to a $16,000,000 settlement with the Federal Communications Commission (FCC) in the U.S. concerning three data breach incidents its wholly-owned subsidiary, TracFone Wireless, suffered after its acquisition in 2021. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Fake CrowdStrike repair manual pushes new infostealer malware

CrowdStrike is warning that a fake recovery manual to repair Windows devices is installing a new information-stealing malware called Daolpu. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Greece’s Land Registry agency breached in wave of 400 cyberattacks

The Land Registry agency in Greece has announced that it suffered a limited-scope data breach following a wave of 400 cyberattacks targeting its IT infrastructure over the last week. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Los Angeles Superior Court shuts down after ransomware attack

The largest trial court in the United States, the Superior Court of Los Angeles County, closed all 36 courthouse locations on Monday to restore systems affected by a Friday ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

End-user cybersecurity errors that can cost you millions

An innocent mistake can lead to a corporate nightmare. Learn from Specops Software about five of the most frequent cybersecurity blunders that can let attackers breach a network. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Spain arrests three for using DDoSia hacktivist platform

The Spanish authorities have arrested three individuals for using DDoSia, a distributed denial of service platform operated by pro-Russian hacktivists, to conduct DDoS attacks against governments and organizations in NATO countries. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft confirms CrowdStrike update also hit Windows 365 PCs

Microsoft says the faulty CrowdStrike Falcon update, which caused widespread outages by crashing Windows systems worldwide, also resulted in Windows 365 Cloud PCs getting stuck in reboot loops, rendering them unusable. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

MediSecure: Ransomware gang stole data of 12.9 million people

MediSecure, an Australian prescription delivery service provider, revealed that roughly 12.9 million people had their personal and health information stolen in an April ransomware attack. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

CrowdStrike update crashes Windows systems, causes outages worldwide

A faulty component in the latest CrowdStrike Falcon update is crashing Windows systems, impacting various organizations and services across the world, including airports, TV stations, and hospitals. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Major Microsoft 365 outage caused by Azure configuration change

Microsoft says an Azure configuration change caused a major Microsoft 365 outage on Thursday, affecting customers across the Central US region. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

SolarWinds fixes 8 critical bugs in access rights audit software

SolarWinds has fixed eight critical vulnerabilities in its Access Rights Manager (ARM) software, six of which allowed attackers to gain remote code execution (RCE) on vulnerable devices. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft fixes bug blocking Windows 11 Photos from starting

Microsoft has fixed a known issue preventing the Microsoft Photos app from starting on some Windows 11 22H2 and 23H2 systems. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Notorious FIN7 hackers sell EDR killer to other threat actors

The notorious FIN7 hacking group has been spotted selling its custom "AvNeutralizer" tool, used to evade detection by killing enterprise endpoint protection software on corporate networks. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Over 400,000 Life360 user phone numbers leaked via unsecured API

A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Email addresses of 15 million Trello users leaked on hacking forum

A threat actor has released over 15 million email addresses associated with Trello accounts that were collected using an unsecured API in January. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Rite Aid says June data breach impacts 2.2 million people

Rite Aid, the third-largest drugstore chain in the United States, says that 2.2 million customers' personal information was stolen last month in what it described as a "data security incident." [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft links Scattered Spider hackers to Qilin ransomware attacks

Microsoft says the Scattered Spider cybercrime gang has added Qilin ransomware to its arsenal and is now using it in attacks. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Kaspersky is shutting down its business in the United States

Russian cybersecurity company and antivirus software provider Kaspersky Lab will start shutting down operations in the United States on July 20. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Critical Exim bug bypasses security filters on 1.5 million mail servers

Censys warns that over 1.5 million Exim mail transfer agent (MTA) instances are unpatched against a critical vulnerability that lets threat actors bypass security filters. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Rite Aid confirms data breach after June ransomware attack

Pharmacy giant Rite Aid confirmed a data breach after suffering a cyberattack in June, which was claimed by the RansomHub ransomware operation. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

DNS hijacks target crypto platforms registered with Squarespace

A wave of coordinated DNS hijacking attacks targets decentralized finance (DeFi) cryptocurrency domains using the Squarespace registrar, redirecting visitors to phishing sites hosting wallet drainers. [...] | Continue reading


@bleepingcomputer.com | 4 months ago