Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 14 min 36 sek zpět

Critical RCE flaw in Apache Tomcat actively exploited in attacks

17 Březen, 2025 - 14:29
A critical remote code execution (RCE) vulnerability in Apache Tomcat tracked as CVE-2025-24813 is actively exploited in the wild, enabling attackers to take over servers with a simple PUT request. [...]
Kategorie: Hacking & Security

Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts

16 Březen, 2025 - 19:36
A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code. [...]
Kategorie: Hacking & Security

Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts

16 Březen, 2025 - 15:19
Cybercriminals are promoting malicious Microsoft OAuth apps that masquerade as Adobe and DocuSign apps to deliver malware and steal Microsoft 365 accounts credentials. [...]
Kategorie: Hacking & Security

New Akira ransomware decryptor cracks encryptions keys using GPUs

15 Březen, 2025 - 15:16
Security researcher Yohanes Nugroho has released a decryptor for the Linux variant of Akira ransomware, which utilizes GPU power to retrieve the decryption key and unlock files for free. [...]
Kategorie: Hacking & Security

Coinbase phishing email tricks users with fake wallet migration

14 Březen, 2025 - 23:35
A large-scale Coinbase phishing attack poses as a mandatory wallet migration, tricking recipients into setting up a new wallet with a pre-generated recovery phrase controlled by attackers. [...]
Kategorie: Hacking & Security

Week-long Exchange Online outage causes email failures, delays

14 Březen, 2025 - 19:59
Microsoft says it partially mitigated a week-long Exchange Online outage causing delays or failures when sending or receiving email messages. [...]
Kategorie: Hacking & Security

Ransomware gang creates tool to automate VPN brute-force attacks

14 Březen, 2025 - 17:55
The Black Basta ransomware operation created an automated brute-forcing framework dubbed 'BRUTED' to breach edge networking devices like firewalls and VPNs. [...]
Kategorie: Hacking & Security

Cisco IOS XR vulnerability lets attackers crash BGP on routers

14 Březen, 2025 - 17:44
Cisco has patched a denial of service (DoS) vulnerability that lets attackers crash the Border Gateway Protocol (BGP) process on IOS XR routers with a single BGP update message. [...]
Kategorie: Hacking & Security

Suspected LockBit ransomware dev extradited to United States

14 Březen, 2025 - 15:22
A dual Russian-Israeli national, suspected of being a key developer for the LockBit ransomware operation, has been extradited to the United States to face charges. [...]
Kategorie: Hacking & Security

Microsoft apologizes for removing VSCode extensions used by millions

13 Březen, 2025 - 21:53
Microsoft has reinstated the 'Material Theme - Free' and 'Material Theme Icons - Free' extensions on the Visual Studio Marketplace after finding that the obfuscated code they contained wasn't actually malicious. [...]
Kategorie: Hacking & Security

New SuperBlack ransomware exploits Fortinet auth bypass flaws

13 Březen, 2025 - 20:57
A new ransomware operator named 'Mora_001' is exploiting two Fortinet vulnerabilities to gain unauthorized access to firewall appliances and deploy a custom ransomware strain dubbed SuperBlack. [...]
Kategorie: Hacking & Security

Windows Notepad to get AI text summarization in Windows 11

13 Březen, 2025 - 20:45
Microsoft is now testing an AI-powered text summarization feature in Notepad and a Snipping Tool "Draw & Hold" feature that helps draw perfect shapes. [...]
Kategorie: Hacking & Security

Microsoft says button to restore classic Outlook is broken

13 Březen, 2025 - 18:51
​Microsoft is investigating a known issue that causes the new Outlook email client to crash when users click the "Go to classic Outlook" button, which should help them switch back to the classic Outlook. [...]
Kategorie: Hacking & Security

Juniper patches bug that let Chinese cyberspies backdoor routers

13 Březen, 2025 - 17:40
​Juniper Networks has released emergency security updates to patch a Junos OS vulnerability exploited by Chinese hackers to backdoor routers for stealthy access. [...]
Kategorie: Hacking & Security

GitLab patches critical authentication bypass vulnerabilities

13 Březen, 2025 - 17:13
GitLab released security updates for Community Edition (CE) and Enterprise Edition (EE), fixing nine vulnerabilities, among which two critical severity ruby-saml library authentication bypass flaws. [...]
Kategorie: Hacking & Security

ClickFix attack delivers infostealers, RATs in fake Booking.com emails

13 Březen, 2025 - 16:00
Microsoft is warning that an ongoing phishing campaign impersonating Booking.com is using ClickFix social engineering attacks to infect hospitality workers with various malware, including infostealers and RATs. [...]
Kategorie: Hacking & Security

Red Report 2025: Unmasking a 3X Spike in Credential Theft and Debunking the AI Hype

13 Březen, 2025 - 15:01
Credential theft surged 3× in a year—but AI-powered malware? More hype than reality. The Red Report 2025 by Picus Labs reveals attackers still rely on proven tactics like stealth & automation to execute the "perfect heist." [...]
Kategorie: Hacking & Security

Facebook discloses FreeType 2 flaw exploited in attacks

12 Březen, 2025 - 22:04
Facebook is warning that a FreeType vulnerability in all versions up to 2.13 can lead to arbitrary code execution, with reports that the flaw has been exploited in attacks. [...]
Kategorie: Hacking & Security

CISA: Medusa ransomware hit over 300 critical infrastructure orgs

12 Březen, 2025 - 20:26
CISA says the Medusa ransomware operation has impacted over 300 organizations in critical infrastructure sectors in the United States until last month. [...]
Kategorie: Hacking & Security

New North Korean Android spyware slips onto Google Play

12 Březen, 2025 - 18:35
A new Android spyware named 'KoSpy' is linked to North Korean threat actors who have infiltrated Google Play and third-party app store APKPure through at least five malicious apps. [...]
Kategorie: Hacking & Security