Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 12 min 7 sek zpět

Hackers drain $3.9M from Unleash Protocol after multisig hijack

31 Prosinec, 2025 - 16:54
The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract upgrade that allowed asset withdrawals. [...]
Kategorie: Hacking & Security

RondoDox botnet exploits React2Shell flaw to breach Next.js servers

31 Prosinec, 2025 - 15:58
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. [...]
Kategorie: Hacking & Security

IBM warns of critical API Connect auth bypass vulnerability

31 Prosinec, 2025 - 11:34
IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers to access apps remotely. [...]
Kategorie: Hacking & Security

Disney will pay $10 million to settle children's data privacy lawsuit

31 Prosinec, 2025 - 10:43
A federal judge has approved an order requiring Disney to pay a $10 million civil penalty to settle claims that it violated the Children's Online Privacy Protection Act by mislabeling videos and allowing data collection for targeted advertising. [...]
Kategorie: Hacking & Security

New ErrTraffic service enables ClickFix attacks via fake browser glitches

30 Prosinec, 2025 - 22:08
A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating 'fake glitches' on compromised websites to lure users into downloading payloads or following malicious instructions [...]
Kategorie: Hacking & Security

European Space Agency confirms breach of "external servers"

30 Prosinec, 2025 - 17:26
The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described as "unclassified" information on collaborative engineering activities. [...]
Kategorie: Hacking & Security

Zoom Stealer browser extensions harvest corporate meeting intelligence

30 Prosinec, 2025 - 16:41
A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through 18 extensions that collect online meeting-related data like URLs, IDs, topics, descriptions, and embedded passwords. [...]
Kategorie: Hacking & Security

US cybersecurity experts plead guilty to BlackCat ransomware attacks

30 Prosinec, 2025 - 16:25
Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. [...]
Kategorie: Hacking & Security

CISA orders feds to patch MongoBleed flaw exploited in attacks

30 Prosinec, 2025 - 15:40
CISA ordered U.S. federal agencies to patch an actively exploited MongoDB vulnerability (MongoBleed) that can be exploited to steal credentials, API keys, and other sensitive data. [...]
Kategorie: Hacking & Security

Chinese state hackers use rootkit to hide ToneShell malware activity

30 Prosinec, 2025 - 01:08
A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader in attacks against government organizations. [...]
Kategorie: Hacking & Security

Coupang to split $1.17 billion among 33.7 million data breach victims

29 Prosinec, 2025 - 23:27
Coupang, the largest retailer in South Korea, announced $1.17 billion (1.685 trillion Won) total compensation for the 33.7 million customers whose information was exposed in the data breach discovered last month. [...]
Kategorie: Hacking & Security

Hacker arrested for KMSAuto malware campaign with 2.8 million downloads

29 Prosinec, 2025 - 20:25
A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as the KMSAuto tool for illegally activating Windows and Office software. [...]
Kategorie: Hacking & Security

Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack

29 Prosinec, 2025 - 17:43
Trust Wallet says attackers who compromised its browser extension right before Christmas have drained approximately $7 million from nearly 3,000 cryptocurrency wallet addresses. [...]
Kategorie: Hacking & Security

The Real-World Attacks Behind OWASP Agentic AI Top 10

29 Prosinec, 2025 - 16:00
OWASP's new Agentic AI Top 10 highlights real-world attacks already targeting autonomous AI systems, from goal hijacking to malicious MCP servers. Koi Security breaks down real-world incidents behind multiple categories, including two cases cited by OWASP, showing how agent tools and runtime behavior are being abused. [...]
Kategorie: Hacking & Security

ChatGPT finally rolls out Thinking time toggle on mobile

29 Prosinec, 2025 - 16:00
OpenAI is rolling out an update to ChatGPT on mobile that finally allows you to select the Thinking time toggle, also called "juice" of the model. [...]
Kategorie: Hacking & Security

Romanian energy provider hit by Gentlemen ransomware attack

29 Prosinec, 2025 - 15:26
A ransomware attack hit Oltenia Energy Complex (Complexul Energetic Oltenia), Romania's largest coal-based energy producer, on the second day of Christmas, taking down its IT infrastructure. [...]
Kategorie: Hacking & Security

Former Coinbase support agent arrested for helping hackers

29 Prosinec, 2025 - 15:16
A former Coinbase customer service agent was arrested in India for helping hackers earlier this year steal sensitive customer information from a company database. [...]
Kategorie: Hacking & Security

Korean Air data breach exposes data of thousands of employees

29 Prosinec, 2025 - 14:08
Korean Air experienced a data breach affecting thousands of employees after Korean Air Catering & Duty-Free (KC&D), its in-flight catering supplier and former subsidiary, was recently hacked. [...]
Kategorie: Hacking & Security

Microsoft Copilot is rolling out GPT 5.2 as "Smart Plus" mode

29 Prosinec, 2025 - 13:23
Microsoft is rolling out GPT 5.2 to Copilot on the web, Windows, and mobile as a free upgrade, and it'll coexist with the GPT 5.1 model. [...]
Kategorie: Hacking & Security

Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks

29 Prosinec, 2025 - 12:16
Fortinet has warned customers that threat actors are still actively exploiting a critical FortiOS vulnerability that allows them to bypass two-factor authentication (2FA) when targeting vulnerable FortiGate firewalls. [...]
Kategorie: Hacking & Security