Bleeping Computer

Syndikovat obsah
BleepingComputer - All Stories
Aktualizace: 13 sek zpět

New 'CoPhish' technique wraps OAuth phishing in Microsoft Copilot

25 Říjen, 2025 - 17:16
A new phishing technique dubbed 'CoPhish' weaponizes Microsoft Copilot Studio agents to deliver fraudulent OAuth consent requests via legitimate and trusted Microsoft domains. [...]
Kategorie: Hacking & Security

Hackers launch mass attacks exploiting outdated WordPress plugins

24 Říjen, 2025 - 20:28
A widespread exploitation campaign is targeting WordPress websites with GutenKit and Hunk Companion plugins vulnerable to critical-severity, old security issues that can be used to achieve remote code execution (RCE). [...]
Kategorie: Hacking & Security

Critical WSUS flaw in Windows Server now exploited in attacks

24 Říjen, 2025 - 17:28
Attackers are now exploiting a critical-severity Windows Server Update Services (WSUS) vulnerability, which already has publicly available proof-of-concept exploit code. [...]
Kategorie: Hacking & Security

Amazon: This week’s AWS outage caused by major DNS failure

24 Říjen, 2025 - 16:33
Amazon says a major DNS failure was behind a massive AWS (Amazon Web Services) outage that took down many websites and online services on Monday. [...]
Kategorie: Hacking & Security

Fake LastPass death claims used to breach password vaults

24 Říjen, 2025 - 15:47
LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process. [...]
Kategorie: Hacking & Security

How to reduce costs with self-service password resets

24 Říjen, 2025 - 15:06
Password resets account for nearly 40% of IT help desk calls, costing orgs time and money. Specops Software's uReset lets users securely reset passwords with flexible MFA options like Duo, Okta, and Yubikey while enforcing identity verification to stop misuse. [...]
Kategorie: Hacking & Security

Mozilla: New Firefox extensions must disclose data collection practices

24 Říjen, 2025 - 14:17
Starting next month, Mozilla will require Firefox extension developers to disclose whether their add-ons collect or share user data with third parties. [...]
Kategorie: Hacking & Security

Windows Server emergency patches fix WSUS bug with PoC exploit

24 Říjen, 2025 - 08:27
Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code. [...]
Kategorie: Hacking & Security

Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland

24 Říjen, 2025 - 07:36
​The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities. [...]
Kategorie: Hacking & Security

Toys “R” Us Canada warns customers' info leaked in data breach

23 Říjen, 2025 - 23:25
Toys "R" Us Canada has sent notices of a data breach to customers informing them of a security incident where threat actors leaked customer records they had previously stolen from its systems. [...]
Kategorie: Hacking & Security

HP pulls update that broke Microsoft Entra ID auth on some AI PCs

23 Říjen, 2025 - 22:50
HP has pulled an HP OneAgent software update for Windows 11 that mistakenly deleted Microsoft certificates required for some organizations to log in to Microsoft Entra ID, effectively disconnecting them from their company's cloud environments. [...]
Kategorie: Hacking & Security

Meet the new Clippy: Microsoft unveils Copilot's "Mico" avatar

23 Říjen, 2025 - 18:28
Today, Microsoft introduced Mico, a new and more personal avatar for the AI-powered Copilot digital assistant, which the company describes as human-centered. [...]
Kategorie: Hacking & Security

CISA warns of Lanscope Endpoint Manager flaw exploited in attacks

23 Říjen, 2025 - 17:24
The Cybersecurity & Infrastructure Security Agency (CISA) is warning that hackers are exploiting a critical vulnerability in the Motex Landscope Endpoint Manager. [...]
Kategorie: Hacking & Security

Microsoft disables File Explorer preview for downloads to block attacks

23 Říjen, 2025 - 16:57
Microsoft says that the File Explorer (formerly Windows Explorer) now automatically blocks previews for files downloaded from the Internet to block credential theft attacks via malicious documents. [...]
Kategorie: Hacking & Security

Zero Trust Has a Blind Spot—Your AI Agents

23 Říjen, 2025 - 15:15
AI agents now act, decide, and access systems on their own — creating new blind spots Zero Trust can't see. Token Security helps organizations govern AI identities so every agent's access, intent, and action are verified and accountable. [...]
Kategorie: Hacking & Security

Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions

23 Říjen, 2025 - 15:09
OpenAI's Atlas and Perplexity's Comet browsers are vulnerable to AI sidebar spoofing attacks that mislead users into following fake AI-generated instructions. [...]
Kategorie: Hacking & Security

North Korean Lazarus hackers targeted European defense companies

23 Říjen, 2025 - 13:38
North Korean Lazarus hackers compromised three European companies in the defense sector through a coordinated Operation DreamJob campaign leveraging fake recruitment lures. [...]
Kategorie: Hacking & Security

Iranian hackers targeted over 100 govt orgs with Phoenix backdoor

22 Říjen, 2025 - 22:19
State-sponsored Iranian hacker group MuddyWater has targeted more than 100 government entities in attacks that deployed version 4 of the Phoenix backdoor. [...]
Kategorie: Hacking & Security

Pwn2Own Day 2: Hackers exploit 22 zero-days for $267.500

22 Říjen, 2025 - 19:52
Security researchers collected $267,500 in cash after exploiting 22​​​​​​​ unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition. [...]
Kategorie: Hacking & Security

Hackers exploiting critical "SessionReaper" flaw in Adobe Magento

22 Říjen, 2025 - 19:41
Hackers are actively exploiting the critical SessionReaper vulnerability (CVE-2025-54236) in Adobe Commerce (formerly Magento) platforms, with hundreds of attempts recorded. [...]
Kategorie: Hacking & Security