Box cloud storage down amid 'critical' outage

Cloud storage provider Box.com is suffering an outtage preventing customers from accessing their files. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Delta Dental says data breach exposed info of 7 million people

Delta Dental of California is warning almost seven million patients that they suffered a data breach after personal data was exposed in a MOVEit Transfer software breach. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Kraft Heinz investigates hack claims, says systems ‘operating normally’

Kraft Heinz has confirmed that their systems are operating normally and that there is no evidence they were breached after an extortion group listed them on a data leak site. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

New NKAbuse malware abuses NKN blockchain for stealthy comms

A new Go-based multi-platform malware identified as 'NKAbuse' is the first malware abusing NKN (New Kind of Network) technology for data exchange, making it a stealthy threat. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Ubiquiti users report having access to others’ UniFi routers, cameras

Since yesterday, customers of Ubiquiti networking devices, ranging from routers to security cameras, have reported seeing other people's devices and notifications through the company's cloud services. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

US detains suspects behind $80 million 'pig butchering' scheme

The U.S. Department of Justice charged four suspects (two of them already detained) for their alleged involvement in a pig butchering fraud scheme that resulted in more than $80 million in victim losses. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Ten new Android banking trojans targeted 985 bank apps in 2023

This year has seen the emergence of ten new Android banking malware families, which collectively target 985 bank and fintech/trading apps from financial institutes across 61 countries. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Discord adds Security Key support for all users to enhance security

Discord has made security key multi-factor authentication (MFA) available for all accounts on the platform, bringing significant security and anti-phishing benefits to its 500+ million registered users. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

U.S. nuclear research lab data breach impacts 45,000 people

The Idaho National Laboratory (INL) confirmed that attackers stole the personal information of more than 45,000 individuals after breaching its cloud-based Oracle HCM HR management platform last month. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Ledger dApp supply chain attack steals $600K from crypto wallets

Ledger is warnings users not to use web3 dApps after a supply chain attack on the 'Ledger dApp Connect Kit' library was found pushing a JavaScript wallet drainer that stole $600,000 in crypto and NFTs. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Protect your Active Directory from these Password-based Vulnerabilities

To safeguard against potential cyberattacks and outages, it is essential to be vigilant against common Active Directory attacks, Learn more from Specops Software about these attacks and how harden your defenses. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft seizes domains used to sell fraudulent Outlook accounts

Microsoft's Digital Crimes Unit seized multiple domains used by a Vietnam-based cybercrime group (Storm-1152) that registered over 750 million fraudulent accounts and raked in millions of dollars by selling them online to other cybercriminals. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Stealthy KV-botnet hijacks SOHO routers and VPN devices

The Chinese state-sponsored APT hacking group known as Volt Typhoon (Bronze Silhouette) has been linked to a sophisticated botnet named 'KV-botnet' since at least 2022 to attack SOHO routers in high-value targets. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

BazarCall attacks abuse Google Forms to legitimize phishing emails

A new wave of BazarCall attacks uses Google Forms to generate and send payment receipts to victims, attempting to make the phishing attempt appear more legitimate. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

French police arrests Russian suspect linked to Hive ransomware

French authorities arrested a Russian national in Paris for allegedly helping the Hive ransomware gang with laundering their victims' ransom payments. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

LockBit ransomware now poaching BlackCat, NoEscape affiliates

The LockBit ransomware operation is now recruiting affiliates and developers from the BlackCat/ALPHV and NoEscape after recent disruptions and exit scams. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

CISA: Russian hackers target TeamCity servers since September

CISA and partner cybersecurity agencies and intelligence services warned that the APT29 hacking group linked to Russia's Foreign Intelligence Service (SVR) has been targeting unpatched TeamCity servers in widespread attacks since September 2023. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Hackers are exploiting critical Apache Struts flaw using public PoC

Hackers are attempting to leverage a recently fixed critical vulnerability (CVE-2023-50164) in Apache Struts that leads to remote code execution, in attacks that rely on publicly available proof-of-concept exploit code. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

New cybercrime market 'OLVX' gains popularity among hackers

A new cybercrime marketplace, OLVX, has emerged and is quickly gaining new customers looking to purchase tools to conduct online fraud and cyberattacks. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft: OAuth apps used to automate BEC and cryptomining attacks

Microsoft warns that financially-motivated threat actors are using OAuth applications to automate BEC and phishing attacks, push spam, and deploy VMs for cryptomining. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Ukrainian military says it hacked Russia's federal tax agency

​The Ukrainian government's military intelligence service says it hacked the Russian Federal Taxation Service (FNS), wiping the agency's database and backup copies. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Avira antivirus causes Windows computers to freeze after boot

Since Friday, Windows users have reported problems with the operating system freezing shortly after booting, an issue linked to a faulty update for Avira's security software. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft December 2023 Patch Tuesday fixes 34 flaws, 1 zero-day

Today is Microsoft's December 2023 Patch Tuesday, which includes security updates for a total of 34 flaws and one previously disclosed, unpatched vulnerability in AMD CPUs. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Windows 11 KB5033375 update released with upgraded Copilot AI-assistant

Microsoft has released the KB5033375 update for Windows 11 versions 23H2 and 22H2 to fix security vulnerabilities, upgrade Copilot for Windows, and make 36 changes and fixes [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Windows 10 KB5033372 update released with Copilot for everyone, 20 changes

Microsoft has released the KB5033372 cumulative update for Windows 10 21H2 and Windows 10 22H2, which includes Copilot for Windows and nineteen other changes to the operating system. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Sophos backports RCE fix after attacks on unsupported firewalls

Sophos was forced to backport a security update for CVE-2022-3236 for end-of-life (EOL) firewall firmware versions after discovering hackers actively exploiting the flaw in attacks. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Ukraine's largest mobile carrier Kyivstar down following cyberattack

Kyivstar, Ukraine's largest telecommunications service provider serving over 25 million mobile and home internet subscribers, has suffered a cyberattack impacting mobile and data services. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Cloud engineer gets 2 years for wiping ex-employer’s code repos

Miklos Daniel Brody, a cloud engineer, was sentenced to two years in prison and a restitution of $529,000 for wiping the code repositories of his former employer in retaliation for being fired by the company.  [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Over 1,450 pfSense servers exposed to RCE attacks via bug chain

Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable attackers to perform remote code execution on the appliance. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable websites. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Lazarus hackers drop new RAT malware using 2-year-old Log4j bug

The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka "Log4Shell," this time to deploy three previously unseen malware families written in DLang. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Counter-Strike 2 HTML injection bug exposes players’ IP addresses

Valve has reportedly fixed an HTML injection flaw in Counter-Strike 2 that was heavily abused today to inject images into games and obtain other players' IP addresses. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Apple emergency updates fix recent zero-days on older iPhones

Apple has issued emergency security updates to backport patches for two actively exploited zero-day flaws to older iPhones and some Apple Watch and Apple TV models. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Cold storage giant Americold discloses data breach after April malware attack

Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen in an April attack, later claimed by Cactus ransomware. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Toyota warns customers of data breach exposing personal, financial info

Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Kelvin Security hacking group leader arrested in Spain

The Spanish police have arrested one of the alleged leaders of the 'Kelvin Security' hacking group, which is believed to be responsible for 300 cyberattacks against organizations in 90 countries since 2020. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Over 30% of Log4J apps use a vulnerable version of the library

Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two yea … | Continue reading


@bleepingcomputer.com | 4 months ago

AutoSpill attack steals credentials from Android password managers

Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Norton Healthcare discloses data breach after May ransomware attack

Kentucky health system Norton Healthcare has confirmed that a ransomware attack in May exposed personal information belonging to patients, employees, and dependents. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Google shares “fix” for deleted Google Drive files

Google says it identified and fixed a bug causing customer files added to Google Drive after April-May 2023 to disappear. However, the fix isn't working for all affected users. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Microsoft: Outlook email sending issues for users with lots of folders

Microsoft has acknowledged a new issue affecting Outlook for Microsoft 365 users and causing email-sending problems for those with too many nested folders. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

ALPHV ransomware site outage rumored to be caused by law enforcement

A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang's websites over the last 30 hours. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Privilege elevation exploits used in over 50% of insider attacks

Elevation of privilege flaws are the most common vulnerability leveraged by corporate insiders when conducting unauthorized activities on networks, whether for malicious purposes or by downloading risky tools in a dangerous manner. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Amazon sues REKK fraud gang that stole millions in illicit refunds

Amazon's Customer Protection and Enforcement team has taken legal action against an underground store refund scheme that has resulted in the theft of millions of dollars worth of products from Amazon's online platforms. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

New 5Ghoul attack impacts 5G phones with Qualcomm, MediaTek chips

A new set of vulnerabilities in 5G modems by Qualcomm and MediaTek, collectively called "5Ghoul," impact 710 5G smartphone models from Google partners (Android) and Apple, routers, and USB modems. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Russian military hackers target NATO fast reaction corps

Russian APT28 military hackers used Microsoft Outlook zero-day exploits to target multiple European NATO member countries, including a NATO Rapid Deployable Corps. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

23andMe updates user agreement to prevent data breach lawsuits

As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company. [...] | Continue reading


@bleepingcomputer.com | 4 months ago

Windows 11 Notepad gets a built-in character counter, finally

Microsoft keeps improving and adding more features to the Windows 11 Notepad application, the latest being a built-in character counter. [...] | Continue reading


@bleepingcomputer.com | 4 months ago