Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 2 min 49 sek zpět

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

14 Září, 2026 - 22:36
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
Kategorie: Hacking & Security

Homebrew 7.0.0 gets built-in GUI, better security controls

14 Září, 2026 - 21:51
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
Kategorie: Hacking & Security

Twitch extension with 30K installs exposes users’ OAuth tokens

14 Září, 2026 - 21:03
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
Kategorie: Hacking & Security

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

14 Září, 2026 - 20:34
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
Kategorie: Hacking & Security

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

14 Září, 2026 - 18:15
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
Kategorie: Hacking & Security

Why Patch Automation Needs Brakes, Not Just an Accelerator

14 Září, 2026 - 16:01
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
Kategorie: Hacking & Security

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

14 Září, 2026 - 14:15
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]
Kategorie: Hacking & Security

Microsoft: September updates cause RDS failures on Windows Server

14 Září, 2026 - 11:50
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
Kategorie: Hacking & Security

Revolut discloses data breach exposing financial info, passports

14 Září, 2026 - 10:48
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
Kategorie: Hacking & Security

Microsoft: September updates break audio on some Windows PCs

14 Září, 2026 - 10:08
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
Kategorie: Hacking & Security

CISA: Hackers now exploit max severity GitLab flaw in attacks

14 Září, 2026 - 09:06
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]
Kategorie: Hacking & Security

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

13 Září, 2026 - 16:26
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
Kategorie: Hacking & Security

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

12 Září, 2026 - 16:14
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
Kategorie: Hacking & Security

Hackers abused Claude to extract secrets from 1.8M Android apps

11 Září, 2026 - 22:19
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
Kategorie: Hacking & Security

Florida confirms DMV database breached via stolen police account

11 Září, 2026 - 21:00
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Kategorie: Hacking & Security

Passkey-themed phishing attacks lead to Microsoft 365 data theft

11 Září, 2026 - 19:26
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
Kategorie: Hacking & Security

Artifactory flaws chained in attacks deploying backdoor malware

11 Září, 2026 - 18:29
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
Kategorie: Hacking & Security

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

11 Září, 2026 - 16:01
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]
Kategorie: Hacking & Security

GitLab urges users to patch max severity path traversal flaw

11 Září, 2026 - 13:15
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
Kategorie: Hacking & Security

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

11 Září, 2026 - 11:39
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security