News

Bleeping Computer
bleepingcomputer. com > news > security > new-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers

New Mirai campaign exploits RCE flaw in Eo L D-Link routers

13+ hour, 11+ min ago  (658+ words) New Lotus data wiper used against Venezuelan energy, utility firms Former ransomware negotiator pleads guilty to Black Cat attacks CISA flags new SD-WAN flaw as actively exploited in attacks China's Apple App Store infiltrated by crypto-stealing wallet apps New Mirai…...

Bleeping Computer
bleepingcomputer. com > news > security > french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data

French govt agency confirms breach as hacker offers to sell data

1+ day, 11+ hour ago  (640+ words) The Gentlemen ransomware now uses System BC for bot-powered attacks French govt agency confirms breach as hacker offers to sell data New Lotus data wiper used against Venezuelan energy, utility firms Lifetime cybersecurity training is on sale for a one-time…...

Bleeping Computer
bleepingcomputer. com > news > security > cisa-flags-new-sd-wan-flaw-as-actively-exploited-in-attacks

CISA flags new SD-WAN flaw as actively exploited in attacks

1+ day, 20+ hour ago  (636+ words) The Gentlemen ransomware now uses System BC for bot-powered attacks CISA flags new SD-WAN flaw as actively exploited in attacks Actively exploited Apache Active MQ flaw impacts 6, 400 servers Former ransomware negotiator pleads guilty to Black Cat attacks The U. S. Cybersecurity and…...

Bleeping Computer
bleepingcomputer. com > news > security > kelpdao-suffers-290-million-heist-tied-to-lazarus-hackers

Kelp DAO suffers $290 million heist tied to Lazarus hackers

2+ day, 10+ hour ago  (628+ words) Microsoft releases emergency updates to fix Windows Server issues Kelp DAO suffers $290 million heist tied to Lazarus hackers China's Apple App Store infiltrated by crypto-stealing wallet apps The Gentlemen ransomware now uses System BC for bot-powered attacks Seiko USA website…...

Bleeping Computer
bleepingcomputer. com > news > security > seiko-usa-website-defaced-as-hacker-claims-customer-data-theft

Seiko USA website defaced as hacker claims customer data theft

2+ day, 14+ hour ago  (510+ words) Payouts King ransomware uses QEMU VMs to bypass endpoint security Apple account change alerts abused to send phishing emails Critical flaw in Protobuf library enables Java Script code execution NIST to stop rating non-priority flaws due to volume increase Seiko…...

Bleeping Computer
bleepingcomputer. com > news > security > british-scattered-spider-hacker-pleads-guilty-to-crypto-theft-charges

British Scattered Spider hacker pleads guilty to crypto theft charges

2+ day, 19+ hour ago  (620+ words) Payouts King ransomware uses QEMU VMs to bypass endpoint security Apple account change alerts abused to send phishing emails Critical flaw in Protobuf library enables Java Script code execution NIST to stop rating non-priority flaws due to volume increase The…...

Bleeping Computer
bleepingcomputer. com > news > security > global-salt-typhoon-hacking-campaigns-linked-to-chinese-tech-firms

Global Salt Typhoon hacking campaigns linked to Chinese tech firms

7+ mon, 3+ week ago  (848+ words) Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Critical flaw in Protobuf library enables…...

Bleeping Computer
bleepingcomputer. com > news > security > critical-whisperpair-flaw-lets-hackers-track-eavesdrop-via-bluetooth-audio-devices

Critical Whisper Pair flaw lets hackers track, eavesdrop via Bluetooth audio devices

3+ mon, 1+ week ago  (732+ words) Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Microsoft Teams right-click paste broken by…...

Bleeping Computer
bleepingcomputer. com > news > security > operation-poweroff-identifies-75k-ddos-users-takes-down-53-domains

Operation Power OFF identifies 75k DDo S users, takes down 53 domains

6+ day, 17+ hour ago  (537+ words) Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Payouts King ransomware uses QEMU VMs…...

Bleeping Computer
bleepingcomputer. com > news > security > south-korean-giant-kyowon-confirms-data-theft-in-ransomware-attack

South Korean giant Kyowon confirms data theft in ransomware attack

3+ mon, 1+ week ago  (570+ words) New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Grinex exchange blames "Western intelligence" for $13. 7 M crypto hack Inside an Underground Guide: How Threat Actors Vet…...