Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 39 sek zpět

Critical n8n flaws disclosed along with public exploits

4 Únor, 2026 - 22:14
Multiple critical vulnerabilities in the popular n8n open-source workflow automation platform allow escaping the confines of the environment and taking complete control of the host server. [...]
Kategorie: Hacking & Security

CISA: VMware ESXi flaw now exploited in ransomware attacks

4 Únor, 2026 - 18:38
CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was used in zero-day attacks since at least February 2024. [...]
Kategorie: Hacking & Security

CISA warns of five-year-old GitLab flaw exploited in attacks

4 Únor, 2026 - 16:42
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. [...]
Kategorie: Hacking & Security

The Double-Edged Sword of Non-Human Identities

4 Únor, 2026 - 16:05
Leaked non-human identities like API keys and tokens are becoming a major breach driver in cloud environments. Flare shows how exposed machine credentials quietly grant attackers long-term access to enterprise systems. [...]
Kategorie: Hacking & Security

EDR killer tool uses signed kernel driver from forensic software

4 Únor, 2026 - 15:17
Hackers are abusing a legitimate but long-revoked EnCase kernel driver in an EDR killer that can detect 59 security tools in attempts to deactivate them. [...]
Kategorie: Hacking & Security

New Amaranth Dragon cyberespionage group exploits WinRAR flaw

4 Únor, 2026 - 15:00
A new threat actor called Amaranth Dragon, linked to APT41 state-sponsored Chinese operations, exploited the CVE-2025-8088 vulnerability in WinRAR in espionage attacks on government and law enforcement agencies. [...]
Kategorie: Hacking & Security

Microsoft rolls out native Sysmon monitoring in Windows 11

4 Únor, 2026 - 13:58
Microsoft has started rolling out built-in Sysmon functionality to some Windows 11 systems enrolled in the Windows Insider program. [...]
Kategorie: Hacking & Security

Owner of Incognito dark web drugs market gets 30 years in prison

4 Únor, 2026 - 12:24
A Taiwanese man was sentenced to 30 years in prison for operating Incognito Market, one of the world's largest online narcotics marketplaces that sold over $105 million worth of illegal drugs to customers worldwide. [...]
Kategorie: Hacking & Security

Coinbase confirms insider breach linked to leaked support tool screenshots

4 Únor, 2026 - 03:04
Coinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which BleepingComputer has learned is a new incident that occurred in December. [...]
Kategorie: Hacking & Security

Step Finance says compromised execs' devices led to $40M crypto theft

3 Únor, 2026 - 22:33
Step Finance announced that it lost $40 million worth of digital assets after hackers compromised devices belonging to the company's team of executives. [...]
Kategorie: Hacking & Security

Wave of Citrix NetScaler scans use thousands of residential proxies

3 Únor, 2026 - 21:25
A coordinated reconnaissance campaign targeting Citrix NetScaler infrastructure over the past week used tens of thousands of residential proxies to discover login panels. [...]
Kategorie: Hacking & Security

CISA flags critical SolarWinds RCE flaw as exploited in attacks

3 Únor, 2026 - 20:37
CISA has flagged a critical SolarWinds Web Help Desk vulnerability as actively exploited in attacks and ordered federal agencies to patch their systems within three days. [...]
Kategorie: Hacking & Security

Iron Mountain: Data breach mostly limited to marketing materials

3 Únor, 2026 - 17:49
Iron Mountain, a leading data storage and recovery services company, says that a recent breach claimed by the Everest extortion gang is limited to mostly marketing materials. [...]
Kategorie: Hacking & Security

AI Agent Identity Management: A New Security Control Plane for CISOs

3 Únor, 2026 - 16:01
Autonomous AI agents are creating a new identity blind spot as they operate outside traditional IAM controls. Token Security shows why managing the full lifecycle of AI agent identities is becoming a critical CISO priority. [...]
Kategorie: Hacking & Security

UK privacy watchdog probes Grok over AI-generated sexual images

3 Únor, 2026 - 15:25
The United Kingdom's data protection authority launched a formal investigation into X and its Irish subsidiary over reports that the Grok AI assistant was used to generate nonconsensual sexual images. [...]
Kategorie: Hacking & Security

Hackers exploit critical React Native Metro bug to breach dev systems

3 Únor, 2026 - 15:00
Hackers are targeting developers by exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native to deliver malicious payloads for Windows and Linux. [...]
Kategorie: Hacking & Security

Hackers exploit critical React Native Metro bug to breach dev systems

3 Únor, 2026 - 15:00
Hackers are targeting developers by exploiting the critical vulnerability CVE-2025-11953 in the Metro server for React Native to deliver malicious payloads for Windows and Linux. [...]
Kategorie: Hacking & Security

French prosecutors raid X offices, summon Musk over Grok deepfakes

3 Únor, 2026 - 13:43
French prosecutors have raided X's offices in Paris on Tuesday as part of a criminal investigation into the platform's Grok AI tool, widely used to generate sexually explicit images. [...]
Kategorie: Hacking & Security

New GlassWorm attack targets macOS via compromised OpenVSX extensions

2 Únor, 2026 - 23:04
A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems. [...]
Kategorie: Hacking & Security

Russian hackers exploit recently patched Microsoft Office bug in attacks

2 Únor, 2026 - 22:00
Ukraine's Computer Emergency Response Team (CERT) says that Russian hackers are exploiting CVE-2026-21509, a recently patched vulnerability in multiple versions of Microsoft Office. [...]
Kategorie: Hacking & Security