Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 11 sek zpět

GitHub disables Microsoft repos pushing password-stealing malware

9 Červen, 2026 - 17:42
Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub, disrupting continuous integration pipelines. [...]
Kategorie: Hacking & Security

New Veeam vulnerability exposes backup servers to RCE attacks

9 Červen, 2026 - 16:27
Veeam has released security updates to patch a critical Backup & Replication security flaw that can be exploited to gain remote code execution (RCE) on domain-joined backup servers. [...]
Kategorie: Hacking & Security

French govt messaging service breached in account hijacking attack

9 Červen, 2026 - 12:53
DINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government's encrypted messaging platform. [...]
Kategorie: Hacking & Security

CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day

9 Červen, 2026 - 10:18
CISA has ordered U.S. government agencies to secure their Check Point Remote Access VPN and Mobile Access deployments against a critical vulnerability exploited in zero-day attacks by Qilin ransomware affiliates. [...]
Kategorie: Hacking & Security

Google patches new Chrome zero-day flaw exploited in the wild

9 Červen, 2026 - 08:56
Google has released emergency updates to patch another Chrome zero-day vulnerability that has been exploited in the wild, the fifth such flaw patched since the start of the year. [...]
Kategorie: Hacking & Security

NFCShare Android malware spreads via fake banking app updates on GitHub

9 Červen, 2026 - 00:11
New variants of the NFCShare Android malware are being distributed as fake updates for legitimate banking apps hosted on GitHub. [...]
Kategorie: Hacking & Security

SoFi confirms third-party data breach at Hong Kong subsidiary

8 Červen, 2026 - 23:55
SoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information. [...]
Kategorie: Hacking & Security

New Apple feature automatically changes your compromised passwords

8 Červen, 2026 - 23:03
At WWDC 26, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. This works in Safari, and it's rolling out with iOS 27. [...]
Kategorie: Hacking & Security

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

8 Červen, 2026 - 22:41
Hackers compromised 19 packages on the PyPI, collectively downloaded hundreds of thousands of times, in a new Shai-Hulud supply-chain attack that delivered malware designed to steal developer secrets. [...]
Kategorie: Hacking & Security

WhatsApp says it disrupted new NSO spyware phishing attacks

8 Červen, 2026 - 20:40
WhatsApp has detected and stopped spear-phishing campaigns allegedly conducted by the NSO Group after investigating user reports of social engineering attacks. [...]
Kategorie: Hacking & Security

Gogs patches critical zero-day enabling remote code execution

8 Červen, 2026 - 18:18
Gogs has patched a critical security zero-day flaw that can allow attackers to compromise Internet-facing instances and access any repositories (including private ones). [...]
Kategorie: Hacking & Security

Critical UniFi OS bug lets hackers gain root without authentication

8 Červen, 2026 - 17:51
Attackers can chain three already fixed vulnerabilities in the Ubiquiti UniFi OS server to execute remote code with root privileges and without authentication. [...]
Kategorie: Hacking & Security

Reducing security operations complexity with Wazuh Cloud

8 Červen, 2026 - 16:01
Security teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastructure, automated scaling, and AI-driven security analysis. [...]
Kategorie: Hacking & Security

Check Point links VPN zero-day attacks to Qilin ransomware gang

8 Červen, 2026 - 15:05
Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks. [...]
Kategorie: Hacking & Security

Oxford University discloses data breach after careers platform hack

8 Červen, 2026 - 13:14
The University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised. [...]
Kategorie: Hacking & Security

Over 20,000 Instagram accounts stolen in Meta AI support hack

8 Červen, 2026 - 08:00
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]
Kategorie: Hacking & Security

Hands on with Intelligent Terminal, an AI-powered Windows Terminal

8 Červen, 2026 - 01:20
Microsoft has created an open-source fork of Windows Terminal called "Intelligent Terminal," and it allows you to use AI directly inside Terminal without interfering with the regular session. [...]
Kategorie: Hacking & Security

C0XMO botnet spreads via DD-WRT router flaw, kills rival malware

7 Červen, 2026 - 16:17
A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]
Kategorie: Hacking & Security

Silent Ransom Group targets law firms with fake IT support calls

7 Červen, 2026 - 16:09
The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant. [...]
Kategorie: Hacking & Security

Critical Everest Forms Pro flaw exploited to take over WordPress sites

6 Červen, 2026 - 16:09
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website. [...]
Kategorie: Hacking & Security