Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 9 min 39 sek zpět

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

25 Květen, 2026 - 14:45
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]
Kategorie: Hacking & Security

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

24 Květen, 2026 - 16:12
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]
Kategorie: Hacking & Security

Laravel Lang packages hijacked to deploy credential-stealing malware

23 Květen, 2026 - 22:48
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]
Kategorie: Hacking & Security

Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

23 Květen, 2026 - 16:23
Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. [...]
Kategorie: Hacking & Security

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

22 Květen, 2026 - 19:24
Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. [...]
Kategorie: Hacking & Security

Former US execs plead guilty to aiding tech support scammers

22 Květen, 2026 - 17:32
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]
Kategorie: Hacking & Security

Trend Micro warns of Apex One zero-day exploited in the wild

22 Květen, 2026 - 15:39
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]
Kategorie: Hacking & Security

Drupal: Critical SQL injection flaw now targeted in attacks

22 Květen, 2026 - 15:14
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. [...]
Kategorie: Hacking & Security

Why Chargebacks are Just One Piece of the Fraud Puzzle

22 Květen, 2026 - 15:09
Fraud losses don't stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact. [...]
Kategorie: Hacking & Security

Ubiquiti patches three max severity UniFi OS vulnerabilities

22 Květen, 2026 - 14:00
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges. [...]
Kategorie: Hacking & Security

US and Canada arrest and charge suspected Kimwolf botnet admin

22 Květen, 2026 - 11:01
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. [...]
Kategorie: Hacking & Security

Google accidentally exposed details of unfixed Chromium flaw

21 Květen, 2026 - 20:13
Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device. [...]
Kategorie: Hacking & Security

Apple blocked over $11 billion in App Store fraud in 6 years

21 Květen, 2026 - 17:11
Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. [...]
Kategorie: Hacking & Security

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

21 Květen, 2026 - 16:00
Modern crypto drainers don't hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishing and automation. [...]
Kategorie: Hacking & Security

Chinese hackers target telcos with new Linux, Windows malware

21 Květen, 2026 - 16:00
A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. [...]
Kategorie: Hacking & Security

Max severity Cisco Secure Workload flaw gives Site Admin privileges

21 Květen, 2026 - 15:58
Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. [...]
Kategorie: Hacking & Security

Police seize “First VPN” service used in ransomware, data theft attacks

21 Květen, 2026 - 15:09
A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcement operation. [...]
Kategorie: Hacking & Security

Flipper One project needs community help to build open Linux platform

21 Květen, 2026 - 13:00
Flipper Devices, the maker of the Flipper Zero pentesting tool, is asking the community to help build Flipper One, an open Linux platform for connected devices. [...]
Kategorie: Hacking & Security

Microsoft warns of new Defender zero-days exploited in attacks

21 Květen, 2026 - 09:49
On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. [...]
Kategorie: Hacking & Security

GitHub links repo breach to TanStack npm supply-chain attack

21 Květen, 2026 - 08:54
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm supply-chain attack. [...]
Kategorie: Hacking & Security