Staples confirms cyberattack behind service outages, delivery issues

American office supply retailer Staples took down some of its systems earlier this week after a cyberattack to contain the breach's impact and protect customer data. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Zyxel warns of multiple critical vulnerabilities in NAS devices

Zyxel has addressed multiple security issues, including three critical ones that could allow an unauthenticated attacker to execute operating system commands on vulnerable network-attached storage (NAS) devices. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

FjordPhantom Android malware uses virtualization to evade detection

A new Android malware named FjordPhantom has been discovered using virtualization to run malicious code in a container and evade detection. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Dollar Tree hit by third-party data breach impacting 2 million customers

Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 customers after the hack of service provider Zeroed-In Technologies. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

SIM swapper gets 8 years in prison for account hacks, crypto theft

Amir Hossein Golshan, 25, was sentenced to eight years in prison by a Los Angeles District Court and ordered to pay $1.2 million in restitution for crimes involving SIM swapping, merchant fraud, support fraud, account hacking, and cryptocurrency theft. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft starts testing new Windows 11 Energy Saver feature

Microsoft has started testing a new Windows 11 Energy Saver feature that helps customers extend their portable computers' battery life. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Black Basta ransomware made over $100 million from extortion

Russia-linked ransomware gang Black Basta has raked in at least $100 million in ransom payments from more than 90 victims since it first surfaced in April 2022, according to joint research from Corvus Insurance and Elliptic. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Hackers breach US water facility via exposed Unitronics PLCs

CISA (Cybersecurity & Infrastructure Security Agency) is warning that threat actors breached a U.S. water facility by hacking into Unitronics programmable logic controllers (PLCs) exposed online. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Japanese Space Agency JAXA hacked in summer cyberattack

The Japan Aerospace Exploration Agency (JAXA) was hacked in a cyberattack over the summer, potentially compromising sensitive space-related technology and data. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

US seizes Sinbad crypto mixer used by North Korean Lazarus hackers

The U.S. Department of the Treasury has sanctioned the Sinbad cryptocurrency mixing service for its use as a money-laundering tool by the North Korean Lazarus hacking group. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

How Continuous Pen Testing Protects Web Apps from Emerging Threats

The nature and ubiquity of modern web apps make them rife for targeting by hackers. Learn more from Outpost24 about the value of continuous monitoring to secure modern web apps. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Okta: October data breach affects all customer support system users

Okta's investigation into the breach of its Help Center environment last month revealed that the hackers obtained data belonging to all customer support system users. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

New BLUFFS attack lets attackers hijack Bluetooth connections

Researchers at Eurecom have developed six new attacks collectively named 'BLUFFS' that can break the secrecy of Bluetooth sessions, allowing for device impersonation and man-in-the-middle (MitM) attacks. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Google Chrome emergency update fixes 5th zero-day exploited in 2023

Google has fixed the fifth Chrome zero-day vulnerability this year in an emergency security update released today to counter ongoing exploitation in attacks. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Qilin ransomware claims attack on automotive giant Yanfeng

The Qilin ransomware group has claimed responsibility for a cyber attack on Yanfeng Automotive Interiors (Yanfeng), one of the world's largest automotive parts suppliers. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft shares temp fix for Outlook crashes when sending emails

Today, Microsoft shared a temporary fix for a known issue causing Outlook Desktop to crash when sending emails from Outlook.com accounts. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

DP World confirms data stolen in cyberattack, no ransomware used

International logistics giant DP World has confirmed that data was stolen during a cyber attack that disrupted its operations in Australia earlier this month. However, no ransomware payloads or encryption was used in the attack. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Hackers start exploiting critical ownCloud flaw, patch now

Hackers are exploiting a critical ownCloud vulnerability tracked as CVE-2023-49103 that exposes admin passwords, mail server credentials, and license keys in containerized deployments. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Police dismantle ransomware group behind attacks in 71 countries

In cooperation with Europol and Eurojust, law enforcement agencies from seven nations have arrested in Ukraine the core members of a ransomware group linked to attacks against organizations in 71 countries. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft deprecates Defender Application Guard for Office

Microsoft is deprecating Defender Application Guard for Office and the Windows Security Isolation APIs, and it recommends Defender for Endpoint attack surface reduction rules, Protected View, and Windows Defender Application Control as an alternative. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Ransomware attack on indie game maker wiped all player accounts

A ransomware attack on the "Ethyrial: Echoes of Yore" MMORPG last Friday destroyed 17,000 player accounts, deleting their in-game items and progress in the game. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Healthcare giant Henry Schein hit twice by BlackCat ransomware

American healthcare company Henry Schein has reported a second cyberattack this month by the BlackCat/ALPHV ransomware gang, who also breached their network in October. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Ukraine says it hacked Russian aviation agency, leaks data

Ukraine's intelligence service, operating under the Defense Ministry, claims they hacked Russia's Federal Air Transport Agency, 'Rosaviatsia,' to expose a purported collapse of Russia's aviation sector. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Ardent hospital ERs disrupted in 6 states after ransomware attack

Ardent Health Services, a healthcare provider operating 30 hospitals across five U.S. states, disclosed today that its systems were hit by a ransomware attack on Thursday. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Slovenia's largest power provider HSE hit by ransomware attack

Slovenian power company Holding Slovenske Elektrarne (HSE) has suffered a ransomware attack that compromised its systems and encrypted files, yet the company says the incident did not disrupt electric power production. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Leveraging Wazuh to combat insider threats

Effective strategies for mitigating insider threats involve a combination of detective and preventive controls. Such controls are provided by the Wazuh SIEM and XDR platform. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Google Drive users angry over losing months of stored data

Google Drive users are reporting that recent files stored in the cloud have suddenly disappeared, with the cloud service reverting to a storage snapshot as it was around April-May 2023. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

New Rust-based SysJoker backdoor linked to Hamas hackers

A new version of the multi-platform malware known as 'SysJoker' has been spotted, featuring a complete code rewrite in the Rust programming language. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

General Electric investigates claims of cyberattack, data theft

General Electric is investigating claims that a threat actor breached the company's development environment in a cyberattack and leaked allegedly stolen data. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Atomic Stealer malware strikes macOS via fake browser updates

The 'ClearFake' fake browser update campaign has expanded to macOS, targeting Apple computers with Atomic Stealer (AMOS) malware. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Critical bug in ownCloud file sharing app exposes admin passwords

Open source file sharing software ownCloud is warning of three critical-severity security vulnerabilities, including one that can expose administrator passwords and mail server credentials. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Hackers exploit MagicLine4NX zero-day in supply-chain attack

A joint advisory by the National Cyber Security Centre (NCSC) and Korea's National Intelligence Service (NIS) discloses a supply-chain attack executed by North Korean hackers involving the MagicLineThe National Cyber Security Centre (NCSC) and Korea's National Intelligence Servic … | Continue reading


@bleepingcomputer.com | 5 months ago

Cyberattack on IT provider CTS impacts dozens of UK law firms

A cyberattack on CTS, a leading managed service provider (MSP) for law firms and other organizations in the UK legal sector, is behind a major outage impacting numerous law firms and home buyers in the country since Wednesday. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Black Friday 2023: Get 25% off the Zero2Automated malware analysis course

The popular Zero2Automated malware analysis and reverse-engineering course has a Black Friday 2023 through Cyber Monday sale, where you can get 25% off sitewide, including gift certificates and courses. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Kansas courts confirm data theft, ransom demand after cyberattack

The Kansas Judicial Branch has published an update on a cybersecurity incident it suffered last month, confirming that hackers stole sensitive files containing confidential information from its systems. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Windows Hello auth bypassed on Microsoft, Dell, Lenovo laptops

Security researchers bypassed Windows Hello fingerprint authentication on Dell Inspiron, Lenovo ThinkPad, and Microsoft Surface Pro X laptops in attacks exploiting security flaws found in the embedded fingerprint sensors. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Welltok data breach exposes data of 8.5 million US patients

Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft: Lazarus hackers breach CyberLink in supply chain attack

Microsoft says a North Korean hacking group has breached Taiwanese multimedia software company CyberLink and trojanized one of its installers to push malware in a supply chain attack targeting potential victims worldwide. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

New botnet malware exploits two zero-days to infect NVRs and routers

A new Mirai-based malware botnet named 'InfectedSlurs' has been exploiting two zero-day remote code execution (RCE) vulnerabilities to infect routers and video recorder (NVR) devices. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

The Black Friday 2023 Security, IT, VPN, & Antivirus Deals

Black Friday 2023 is here, and great deals are live in computer security, software, online courses, system admin services, antivirus, and VPN software. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Open-source Blender project battling DDoS attacks since Saturday

Blender has confirmed that recent site outages have been caused by ongoing DDoS (distributed denial of service) attacks that started on Saturday. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft now rolling out Copilot to Windows 10 devices

Microsoft is now rolling out the Copilot AI assistant to eligible non-managed systems enrolled in the Windows Insider program and running Windows 10 22H2 Home and Pro editions. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Hacktivists breach U.S. nuclear research lab, steal employee data

The Idaho National Laboratory (INL) confirms they suffered a cyberattack after 'SiegedSec' hacktivists leaked stolen human resources data online. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Lumma malware can allegedly restore expired Google auth cookies

The Lumma information-stealer malware (aka 'LummaC2') is promoting a new feature that allegedly allows cybercriminals to restore expired Google cookies, which can be used to hijack Google accounts. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Microsoft launches Defender Bounty Program with $20,000 rewards

Microsoft has unveiled a new bug bounty program aimed at the Microsoft Defender security platform, with rewards between $500 and $20,000. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Auto parts giant AutoZone warns of MOVEit data breach

AutoZone is warning tens of thousands of its customers that it suffered a data breach as part of the Clop MOVEit file transfer attacks. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

CISA orders federal agencies to patch Looney Tunables Linux bug

Today, CISA ordered U.S. federal agencies to secure their systems against an actively exploited vulnerability that lets attackers gain root privileges on many major Linux distributions. [...] | Continue reading


@bleepingcomputer.com | 5 months ago

Citrix warns admins to kill NetScaler user sessions to block hackers

Citrix reminded admins today that they must take additional measures after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to secure vulnerable devices against attacks. [...] | Continue reading


@bleepingcomputer.com | 5 months ago