Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 17 min 1 sek zpět

Hackers target WordPress sites in miniOrange auth bypass attacks

24 Srpen, 2026 - 21:26
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Kategorie: Hacking & Security

TikTok reaches $400M settlement with US over COPPA violations

24 Srpen, 2026 - 19:56
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
Kategorie: Hacking & Security

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

24 Srpen, 2026 - 17:17
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
Kategorie: Hacking & Security

Microsoft Teams now lets admins block external bots from meetings

24 Srpen, 2026 - 16:00
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
Kategorie: Hacking & Security

South Korean startup platform breach exposes key management failures

24 Srpen, 2026 - 16:00
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
Kategorie: Hacking & Security

Microsoft: August updates break printing, PDF export in WPF apps

24 Srpen, 2026 - 14:40
Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in WPF applications. [...]
Kategorie: Hacking & Security

CISA orders urgent patching of actively exploited Zimbra flaw

24 Srpen, 2026 - 12:45
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
Kategorie: Hacking & Security

Microsoft shares temporary fix for Windows 11 gaming issues

24 Srpen, 2026 - 11:42
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
Kategorie: Hacking & Security

ToxicPanda Android malware uses VPN permissions to block Google Play

23 Srpen, 2026 - 16:23
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Kategorie: Hacking & Security

Hackers infect Android car head units with proxy botnet malware

22 Srpen, 2026 - 16:14
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
Kategorie: Hacking & Security

Named Pipes Under Attack: Securing Windows Interprocess Communication

22 Srpen, 2026 - 15:00
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]
Kategorie: Hacking & Security

New SynkLoader malware pushed in Microsoft Teams phishing campaign

21 Srpen, 2026 - 20:01
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Kategorie: Hacking & Security

Hundreds of leaked AWS keys give full control over corporate accounts

21 Srpen, 2026 - 17:55
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Kategorie: Hacking & Security

Microsoft blames Windows gaming issues on RGB lighting devices

21 Srpen, 2026 - 16:54
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
Kategorie: Hacking & Security

Is Online Privacy Possible? How Digital Identities Can Help

21 Srpen, 2026 - 16:00
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]
Kategorie: Hacking & Security

Microsoft rolls out Classic Outlook theme for New Outlook users

21 Srpen, 2026 - 15:39
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
Kategorie: Hacking & Security

CISA orders feds to patch actively exploited TrueConf Server flaws

21 Srpen, 2026 - 14:25
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
Kategorie: Hacking & Security

Microsoft patches max severity code execution, privilege escalation flaws

21 Srpen, 2026 - 13:04
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges. [...]
Kategorie: Hacking & Security

Hackers abuse FTP server banners to deliver new Windows malware

21 Srpen, 2026 - 13:00
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
Kategorie: Hacking & Security

SickKids data breach exposes employee and job applicant info

21 Srpen, 2026 - 12:10
Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]
Kategorie: Hacking & Security