Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 16 min 37 sek zpět

SAP fixes critical vulnerabilities in NetWeaver application servers

15 Leden, 2025 - 23:02
SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information. [...]
Kategorie: Hacking & Security

CISA shares guidance for Microsoft expanded logging capabilities

15 Leden, 2025 - 21:39
​CISA shared guidance for government agencies and enterprises on using expanded cloud logs in their Microsoft 365 tenants as part of their forensic and compliance investigations. [...]
Kategorie: Hacking & Security

MikroTik botnet uses misconfigured SPF DNS records to spread malware

15 Leden, 2025 - 21:04
A newly discovered botnet of 13,000 MikroTik devices uses a misconfiguration in domain name server records to bypass email protections and deliver malware by spoofing roughly 20,000 web domains. [...]
Kategorie: Hacking & Security

Label giant Avery says website hacked to steal credit cards

15 Leden, 2025 - 20:44
Avery Products Corporation is warning it suffered a data breach after its website was hacked to steal customers' credit cards and personal information. [...]
Kategorie: Hacking & Security

Hackers use Google Search ads to steal Google Ads accounts

15 Leden, 2025 - 20:02
​Ironically, cybercriminals now use Google search advertisements to promote phishing sites that steal advertisers' credentials for the Google Ads platform. [...]
Kategorie: Hacking & Security

Microsoft ends support for Office apps on Windows 10 in October

15 Leden, 2025 - 18:05
Microsoft says it will drop support for Office apps in Windows 10 after the operating system reaches its end of support on October 14. [...]
Kategorie: Hacking & Security

Over 660,000 Rsync servers exposed to code execution attacks

15 Leden, 2025 - 18:00
Over 660,000 exposed Rsync servers are potentially vulnerable to six new vulnerabilities, including a critical-severity heap-buffer overflow flaw that allows remote code execution on servers. [...]
Kategorie: Hacking & Security

Windows BitLocker bug triggers warnings on devices with TPMs

15 Leden, 2025 - 16:46
​Microsoft is investigating a bug triggering security alerts on systems with a Trusted Platform Module (TPM) processor after enabling BitLocker. [...]
Kategorie: Hacking & Security

January Windows updates may fail if Citrix SRA is installed

14 Leden, 2025 - 23:04
Microsoft is warning that the January 2025 Windows 11 and Windows 10 cumulative updates may fail if Citrix Session Recording Agent (SRA) version 2411 is installed on the device. [...]
Kategorie: Hacking & Security

Allstate car insurer sued for tracking drivers without permission

14 Leden, 2025 - 22:29
Texas Attorney General Ken Paxton has filed a lawsuit against Allstate and its data subsidiary Arity for unlawfully collecting, using, and selling driving data from over 45 million Americans. [...]
Kategorie: Hacking & Security

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites

14 Leden, 2025 - 21:54
A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data. [...]
Kategorie: Hacking & Security

US govt says North Korea stole over $659 million in crypto last year

14 Leden, 2025 - 21:01
​North Korean state-backed hacking groups have stolen over $659 million worth of cryptocurrency in multiple crypto-heists, according to a joint statement issued by the United States, South Korea, and Japan on Tuesday. [...]
Kategorie: Hacking & Security

Windows 10 KB5049981 update released with new BYOVD blocklist

14 Leden, 2025 - 20:28
Microsoft has released the KB5049981 cumulative update for Windows 10 22H2 and Windows 10 21H2, which contains an updated Kernel driver blocklist to prevent Bring Your Own Vulnerable Driver (BYOVD) attacks. [...]
Kategorie: Hacking & Security

Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws

14 Leden, 2025 - 20:01
Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks. [...]
Kategorie: Hacking & Security

Windows 11 KB5050009 & KB5050021 cumulative updates released

14 Leden, 2025 - 19:48
Microsoft has released the Windows 11 KB5050009 and KB5050021 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. [...]
Kategorie: Hacking & Security

Google OAuth flaw lets attackers gain access to abandoned accounts

14 Leden, 2025 - 18:28
A weakness in Google's OAuth "Sign in with Google" feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms. [...]
Kategorie: Hacking & Security

FBI deletes Chinese PlugX malware from thousands of US computers

14 Leden, 2025 - 17:26
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States. [...]
Kategorie: Hacking & Security

FBI wipes Chinese PlugX malware from over 4,000 US computers

14 Leden, 2025 - 17:26
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States. [...]
Kategorie: Hacking & Security

Hackers use FastHTTP in new high-speed Microsoft 365 password attacks

14 Leden, 2025 - 16:57
Threat actors are utilizing the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts globally. [...]
Kategorie: Hacking & Security

Fortinet warns of auth bypass zero-day exploited to hijack firewalls

14 Leden, 2025 - 16:24
​Attackers are exploiting a new authentication bypass zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]
Kategorie: Hacking & Security