Последние посты

BleepingComputer
22 сент., 20:07
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachThe ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/BleepingComputerShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachThe ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
BleepingComputer
22 сент., 18:22
New ClosedQuorum Windows malware uses AI for attack decisionsA new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/BleepingComputerNew ClosedQuorum Windows malware uses AI for attack decisionsA new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
BleepingComputer
22 сент., 17:24
Reducing shadow IT visibility gaps with WazuhShadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...]https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/BleepingComputerReducing shadow IT visibility gaps with WazuhShadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations…
BleepingComputer
22 сент., 17:24
Check Point warns of Management Server zero-day exploited in attacksCheck Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/BleepingComputerCheck Point warns of Management Server zero-day exploited in attacksCheck Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
BleepingComputer
22 сент., 15:13
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/BleepingComputerEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
BleepingComputer
22 сент., 13:26
Webinar tomorrow: Inside real-world Google Workspace breachesTomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]https://www.bleepingcomputer.com/news/security/webinar-tomorrow-inside-real-world-google-workspace-breaches/BleepingComputerWebinar tomorrow: Inside real-world Google Workspace breachesTomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make…
BleepingComputer
22 сент., 13:26
D-Link warns of max severity zero-day bug in DIR-822A routersD-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/BleepingComputerD-Link warns of max severity zero-day bug in DIR-822A routersD-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
BleepingComputer
22 сент., 10:22
New Windows Defender zero-day blocks Microsoft antivirus updatesOver the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. [...]https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/BleepingComputerNew Windows Defender zero-day blocks Microsoft antivirus updatesOver the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
BleepingComputer
22 сент., 09:20
CISA orders feds to patch Zyxel flaw exploited for data theftAttackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/BleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theftAttackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
BleepingComputer
21 сент., 21:39
BigCommerce alerts merchants of data breach linked to Ribon appsEcommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]https://www.bleepingcomputer.com/news/security/bigcommerce-alerts-merchants-of-data-breach-linked-to-ribon-apps/BleepingComputerBigCommerce alerts merchants of data breach linked to Ribon appsEcommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.
BleepingComputer
21 сент., 20:16
CISA alerts of active exploitation of three Linux kernel flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/BleepingComputerCISA alerts of active exploitation of three Linux kernel flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
BleepingComputer
21 сент., 19:30
WordPress Click2Shell flaw lets hackers execute PHP on the serverTechnical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/BleepingComputerWordPress Click2Shell flaw lets hackers execute PHP on the serverTechnical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.
BleepingComputer
21 сент., 18:18
Microsoft to retire Microsoft 365 Companion apps in DecemberMicrosoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/BleepingComputerMicrosoft to retire Microsoft 365 Companion apps in DecemberMicrosoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices.
BleepingComputer
21 сент., 16:25
Google fined €403 million over location data privacy violationsIreland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/BleepingComputerGoogle fined €403 million over location data privacy violationsIreland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data.
BleepingComputer
21 сент., 15:08
Microsoft fixes broken Excel copy and paste for all Office usersMicrosoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/BleepingComputerMicrosoft fixes broken Excel copy and paste for all Office usersMicrosoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates.
BleepingComputer
21 сент., 14:30
FBI's CJIS v6.1: What Security Teams Need to Know.The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. [...]https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/BleepingComputerFBI's CJIS v6.1: What Security Teams Need to Know.The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and…
BleepingComputer
21 сент., 13:23
Microsoft reminds admins to migrate Entra ID users to passkeysMicrosoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/BleepingComputerMicrosoft reminds admins to migrate Entra ID users to passkeysMicrosoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027.
BleepingComputer
21 сент., 12:06
Microsoft: September updates break File History backup featureMicrosoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...]https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-file-history-backup-feature/BleepingComputerMicrosoft: September updates break File History backup featureMicrosoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates.
BleepingComputer
20 сент., 14:34
Malicious npm packages evade install-script defenses at runtimeAn ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/BleepingComputerMalicious npm packages evade install-script defenses at runtimeAn ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.
BleepingComputer
20 сент., 12:30
Researchers escape OpenAI Codex sandbox to run commands on hostResearchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]https://www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/BleepingComputerResearchers escape OpenAI Codex sandbox to run commands on hostResearchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
