Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 26 min 42 sek zpět

Smart Slider updates hijacked to push malicious WordPress, Joomla versions

9 Duben, 2026 - 18:15
Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors. [...]
Kategorie: Hacking & Security

When attackers already have the keys, MFA is just another door to open

9 Duben, 2026 - 16:02
Stolen credentials turn authentication systems into the attack surface. Token shows how wearable biometric authentication verifies the user—not the session—blocking phishing relays and MFA bypass. [...]
Kategorie: Hacking & Security

Webinar: From noise to signal - What threat actors are targeting next

9 Duben, 2026 - 14:20
Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs into proactive defensive action before an intrusion begins. [...]
Kategorie: Hacking & Security

Eurail says December data breach impacts 300,000 individuals

9 Duben, 2026 - 12:31
Eurail B.V., a European travel operator that provides digital passes covering 33 national railways, says attackers stole the personal information of over 300,000 individuals in a December 2025 data breach. [...]
Kategorie: Hacking & Security

Hackers exploiting Acrobat Reader zero-day flaw since December

9 Duben, 2026 - 11:22
Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December. [...]
Kategorie: Hacking & Security

Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot

9 Duben, 2026 - 09:44
Bitcoin Depot, which operates one of the largest Bitcoin ATM networks, says attackers stole $3.665 million worth of Bitcoin from its crypto wallets after breaching its systems last month. [...]
Kategorie: Hacking & Security

Microsoft suspends dev accounts for high-profile open source projects

9 Duben, 2026 - 08:46
Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users. [...]
Kategorie: Hacking & Security

Hackers use pixel-large SVG trick to hide credit card stealer

9 Duben, 2026 - 00:34
A massive campaign impacting nearly 100 online stores using the Magento e-commerce platform hides credit card-stealing code in a pixel-sized Scalable Vector Graphics (SVG) image. [...]
Kategorie: Hacking & Security

Google: New UNC6783 hackers steal corporate Zendesk support tickets

8 Duben, 2026 - 23:46
A threat actor tracked as UNC6783 is compromising business process outsourcing (BPO) providers to gain access to high-value companies across multiple sectors. [...]
Kategorie: Hacking & Security

New macOS stealer campaign uses Script Editor in ClickFix attack

8 Duben, 2026 - 20:55
A new campaign delivering the Atomic Stealer malware to macOS users abuses the Script Editor in a variation of the ClickFix attack that tricked users into executing commands in Terminal. [...]
Kategorie: Hacking & Security

CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday

8 Duben, 2026 - 20:15
CISA has given U.S. government agencies four days to secure their systems against a critical-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in attacks since January. [...]
Kategorie: Hacking & Security

13-year-old bug in ActiveMQ lets hackers remotely execute commands

8 Duben, 2026 - 19:26
Security researchers discovered a remote code execution (RCE) vulnerability in Apache ActiveMQ Classic that has gone undetected for 13 years and could be exploited to execute arbitrary commands. [...]
Kategorie: Hacking & Security

Is a $30,000 GPU Good at Password Cracking?

8 Duben, 2026 - 16:00
A $30,000 AI GPU doesn't outperform consumer GPUs at password cracking. Specops explains why attackers don't need exotic hardware to break weak passwords. [...]
Kategorie: Hacking & Security

Microsoft rolls out fix for broken Windows Start Menu search

8 Duben, 2026 - 09:00
Microsoft has pushed a server-side fix for a known issue that broke the Windows Start Menu search feature on some Windows 11 23H2 devices. [...]
Kategorie: Hacking & Security

Hackers exploit critical flaw in Ninja Forms WordPress plugin

8 Duben, 2026 - 00:03
A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution. [...]
Kategorie: Hacking & Security

FBI: Americans lost a record $21 billion to cybercrime last year

7 Duben, 2026 - 22:41
U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise, tech support fraud, and data breaches, the Federal Bureau of Investigation says. [...]
Kategorie: Hacking & Security

Snowflake customers hit in data theft attacks after SaaS integrator breach

7 Duben, 2026 - 21:39
Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen. [...]
Kategorie: Hacking & Security

US warns of Iranian hackers targeting critical infrastructure

7 Duben, 2026 - 20:02
Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. [...]
Kategorie: Hacking & Security

Max severity Flowise RCE vulnerability now exploited in attacks

7 Duben, 2026 - 19:02
Hackers are exploiting a maximum-severity vulnerability, tracked as CVE-2025-59528, in the open-source platform Flowise for building custom LLM apps and agentic systems to execute arbitrary code. [...]
Kategorie: Hacking & Security

Authorities disrupt router DNS hijacks used to steal Microsoft 365 logins

7 Duben, 2026 - 17:51
An international operation from law enforcement authorities in partnership with private companies has disrupted FrostArmada, an APT28 campaign hijacking local traffic from MikroTik and TP-Link routers to steal Microsoft account credentials. [...]
Kategorie: Hacking & Security