Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 23 min 56 sek zpět

Grafana says stolen GitHub token let hackers steal codebase

2 hodiny 37 min zpět
Grafana Labs disclosed that hackers have downloaded its source code after breaching its GitHub environment using a stolen access token. [...]
Kategorie: Hacking & Security

Microsoft testing adjustable taskbar, Start menu in Windows 11

5 hodin 9 min zpět
Microsoft has finally brought back the resizable taskbar and Start menu to Windows 11 in the latest preview version rolling out to Insiders in the Experimental channel. [...]
Kategorie: Hacking & Security

Microsoft confirms Windows 11 security update install issues

7 hodin 1 min zpět
Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. [...]
Kategorie: Hacking & Security

Exploit available for new DirtyDecrypt Linux root escalation flaw

9 hodin 5 min zpět
A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. [...]
Kategorie: Hacking & Security

Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026

10 hodin 50 min zpět
The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws. [...]
Kategorie: Hacking & Security

New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

17 hodin 54 min zpět
A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems.  [...]
Kategorie: Hacking & Security

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

17 Květen, 2026 - 16:43
The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. [...]
Kategorie: Hacking & Security

Microsoft rejects critical Azure vulnerability report, no CVE issued

16 Květen, 2026 - 22:55
A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that "no product changes were made," despite the researcher documenting a silent fix. [...]
Kategorie: Hacking & Security

Russian hackers turn Kazuar backdoor into modular P2P botnet

16 Květen, 2026 - 16:15
The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. [...]
Kategorie: Hacking & Security

Funnel Builder WordPress plugin bug exploited to steal credit cards

15 Květen, 2026 - 21:30
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]
Kategorie: Hacking & Security

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

15 Květen, 2026 - 19:47
​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. [...]
Kategorie: Hacking & Security

Popular node-ipc npm package compromised to steal credentials

15 Květen, 2026 - 19:10
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]
Kategorie: Hacking & Security

Avada Builder WordPress plugin flaws allow site credential theft

15 Květen, 2026 - 17:56
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database. [...]
Kategorie: Hacking & Security

Microsoft backpedals: Edge to stop loading passwords into memory

15 Květen, 2026 - 16:49
Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was "by design." [...]
Kategorie: Hacking & Security

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

15 Květen, 2026 - 16:02
Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the REMUS infostealer evolved around session theft and operational scalability. [...]
Kategorie: Hacking & Security

Microsoft to automatically roll back faulty Windows drivers

15 Květen, 2026 - 14:29
Microsoft is introducing a new capability that will allow it to remotely roll back problematic Windows drivers delivered through Windows Update. [...]
Kategorie: Hacking & Security

Microsoft warns of Exchange zero-day flaw exploited in attacks

15 Květen, 2026 - 11:40
On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. [...]
Kategorie: Hacking & Security

TeamPCP hackers advertise Mistral AI code repos for sale

15 Květen, 2026 - 00:50
The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. [...]
Kategorie: Hacking & Security

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

14 Květen, 2026 - 23:07
Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites. [...]
Kategorie: Hacking & Security

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

14 Květen, 2026 - 22:09
Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices. [...]
Kategorie: Hacking & Security