Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 2 min 1 sek zpět

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

25 Srpen, 2026 - 16:01
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
Kategorie: Hacking & Security

Microsoft PowerToys adds Alt+Tab-style switching for an app's windows

25 Srpen, 2026 - 15:51
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
Kategorie: Hacking & Security

WhatsApp adds stronger two-step verification, multiple passkeys

25 Srpen, 2026 - 15:00
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
Kategorie: Hacking & Security

Hackers breached over 270 Zimbra servers in ongoing attacks

25 Srpen, 2026 - 14:04
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
Kategorie: Hacking & Security

Police arrests dozens of suspects in global cybercrime crackdown

25 Srpen, 2026 - 12:53
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
Kategorie: Hacking & Security

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

24 Srpen, 2026 - 23:14
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
Kategorie: Hacking & Security

Hackers target WordPress sites in miniOrange auth bypass attacks

24 Srpen, 2026 - 21:26
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Kategorie: Hacking & Security

TikTok reaches $400M settlement with US over COPPA violations

24 Srpen, 2026 - 19:56
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
Kategorie: Hacking & Security

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

24 Srpen, 2026 - 17:17
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Kategorie: Hacking & Security

Microsoft Teams now lets admins block external bots from meetings

24 Srpen, 2026 - 16:00
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
Kategorie: Hacking & Security

South Korean startup platform breach exposes key management failures

24 Srpen, 2026 - 16:00
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
Kategorie: Hacking & Security

Microsoft: August updates break printing, PDF export in WPF apps

24 Srpen, 2026 - 14:40
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
Kategorie: Hacking & Security

CISA orders urgent patching of actively exploited Zimbra flaw

24 Srpen, 2026 - 12:45
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
Kategorie: Hacking & Security

Microsoft shares temporary fix for Windows 11 gaming issues

24 Srpen, 2026 - 11:42
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

ToxicPanda Android malware uses VPN permissions to block Google Play

23 Srpen, 2026 - 16:23
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Kategorie: Hacking & Security

Hackers infect Android car head units with proxy botnet malware

22 Srpen, 2026 - 16:14
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
Kategorie: Hacking & Security

Named Pipes Under Attack: Securing Windows Interprocess Communication

22 Srpen, 2026 - 15:00
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]
Kategorie: Hacking & Security