Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 20 min 40 sek zpět

Microsoft shares manual fix for WSUS sync delays and timeouts

21 Červenec, 2026 - 11:05
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]
Kategorie: Hacking & Security

Windows LegacyHive zero-day flaw gets free, unofficial patches

21 Červenec, 2026 - 10:06
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]
Kategorie: Hacking & Security

Estée Lauder discloses data breach via Oracle E-Business flaw

21 Červenec, 2026 - 00:39
Cosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]
Kategorie: Hacking & Security

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

21 Červenec, 2026 - 00:23
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]
Kategorie: Hacking & Security

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

21 Červenec, 2026 - 00:22
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]
Kategorie: Hacking & Security

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

20 Červenec, 2026 - 23:14
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]
Kategorie: Hacking & Security

JadePuffer agentic attacks now target AI model data with ransomware

20 Červenec, 2026 - 23:08
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. [...]
Kategorie: Hacking & Security

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

20 Červenec, 2026 - 19:43
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. [...]
Kategorie: Hacking & Security

An AI SOC Evaluation Guide for Security Leaders

20 Červenec, 2026 - 16:01
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]
Kategorie: Hacking & Security

Hugging Face warns an autonomous AI agent hacked its network

20 Červenec, 2026 - 13:56
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
Kategorie: Hacking & Security

Microsoft confirms Windows Server Update Services sync delays

20 Červenec, 2026 - 12:47
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]
Kategorie: Hacking & Security

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

20 Červenec, 2026 - 12:06
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]
Kategorie: Hacking & Security

Critical ServiceNow code execution flaw now exploited in attacks

20 Červenec, 2026 - 11:29
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Kategorie: Hacking & Security

Hackers abuse ViPNet software to target Russian govt agencies

19 Červenec, 2026 - 16:23
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
Kategorie: Hacking & Security

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

18 Červenec, 2026 - 21:32
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]
Kategorie: Hacking & Security

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

18 Červenec, 2026 - 19:22
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]
Kategorie: Hacking & Security

Microsoft warns of surge in ACR Stealer attacks on customers

18 Červenec, 2026 - 16:17
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]
Kategorie: Hacking & Security

The Future of Age Verification: Your Face Never Leaves Your Device

18 Červenec, 2026 - 15:15
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. [...]
Kategorie: Hacking & Security

Abbott probes two cyber incidents amid extortion claims

17 Červenec, 2026 - 22:45
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. [...]
Kategorie: Hacking & Security

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

17 Červenec, 2026 - 19:56
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...]
Kategorie: Hacking & Security