Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 15 min 18 sek zpět

New Checkmarx supply-chain breach affects KICS analysis tool

23 Duben, 2026 - 18:05
Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments. [...]
Kategorie: Hacking & Security

Cosmetics giant Rituals discloses data breach affecting customers

23 Duben, 2026 - 16:16
Dutch cosmetics giant Rituals disclosed a data breach after attackers stole the personal information of an undisclosed number of customers from its "My Rituals" membership database. [...]
Kategorie: Hacking & Security

Regular Password Resets Aren’t as Safe as You Think

23 Duben, 2026 - 16:10
Password resets are one of the easiest ways for attackers to bypass security controls. Specops Software shows how helpdesk social engineering turns a seemingly legitimate reset request into full account compromise. [...]
Kategorie: Hacking & Security

Microsoft: Some Teams users can’t join meetings after Edge update

23 Duben, 2026 - 15:18
Microsoft confirmed that a recent Microsoft Edge browser update introduced a bug that prevents Windows users from joining Teams meetings. [...]
Kategorie: Hacking & Security

UK warns of Chinese hackers using proxy networks to evade detection

23 Duben, 2026 - 14:28
The United Kingdom's National Cyber Security Centre (NCSC-UK) and international partners warned that China-nexus hackers are increasingly using large-scale proxy networks of hijacked consumer devices to evade detection and disguise their malicious activity. [...]
Kategorie: Hacking & Security

New GopherWhisper APT group abuses Outlook, Slack, Discord for comms

23 Duben, 2026 - 14:06
A previously undocumented state-backed threat actor named GopherWhisper is using a Go-based custom toolkit and legitimate services like Microsoft 365 Outlook, Slack, and Discord in attacks against government entities. [...]
Kategorie: Hacking & Security

CISA orders feds to patch BlueHammer flaw exploited as zero-day

23 Duben, 2026 - 13:05
CISA has ordered U.S. federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks. [...]
Kategorie: Hacking & Security

Apple fixes bug that let the FBI recover deleted Signal messages

22 Duben, 2026 - 22:58
Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked for deletion to remain stored on the device. [...]
Kategorie: Hacking & Security

New Mirai campaign exploits RCE flaw in EoL D-Link routers

22 Duben, 2026 - 22:04
A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet. [...]
Kategorie: Hacking & Security

Kyber ransomware gang toys with post-quantum encryption on Windows

22 Duben, 2026 - 20:52
A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. [...]
Kategorie: Hacking & Security

Spain dismantles major $4.7M manga piracy platform, arrests four

22 Duben, 2026 - 17:06
The Spanish police have dismantled the largest Spanish-language manga piracy platform, operating since 2014, with millions of monthly users from around the globe. [...]
Kategorie: Hacking & Security

Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process

22 Duben, 2026 - 16:01
Fraud operations now operate like call centers, complete with hiring, training, and performance tracking. Flare reveals how cybercriminals manage "Caller-as-a-Service" operations like a professional sales team. [...]
Kategorie: Hacking & Security

New npm supply-chain attack self-spreads to steal auth tokens

22 Duben, 2026 - 14:57
A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts. [...]
Kategorie: Hacking & Security

Microsoft Teams to get efficiency mode on PCs with limited resources

22 Duben, 2026 - 14:24
Microsoft is preparing to roll out a new Efficiency Mode for Microsoft Teams for systems with limited CPU and memory resources to improve app responsiveness. [...]
Kategorie: Hacking & Security

Microsoft traces Universal Print issues to Graph API code change

22 Duben, 2026 - 12:15
Microsoft says that an ongoing Universal Print sharing issue that prevents users from creating some printer shares is due to a Microsoft Graph API code change. [...]
Kategorie: Hacking & Security

New GoGra malware for Linux uses Microsoft Graph API for comms

22 Duben, 2026 - 12:00
A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery. [...]
Kategorie: Hacking & Security

Microsoft releases emergency patches for critical ASP.NET flaw

22 Duben, 2026 - 10:08
Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability. [...]
Kategorie: Hacking & Security

Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks

22 Duben, 2026 - 08:53
Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks. [...]
Kategorie: Hacking & Security

French govt agency confirms breach as hacker offers to sell data

21 Duben, 2026 - 23:46
France Titres, the government agency in France for issuing and managing administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data. [...]
Kategorie: Hacking & Security

New Lotus data wiper used against Venezuelan energy, utility firms

21 Duben, 2026 - 20:38
A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. [...]
Kategorie: Hacking & Security