Category: Bleeping Computer

Hackers are exploiting ArrayOS AG VPN flaw to plant webshells
05
Dec
2025

Hackers are exploiting ArrayOS AG VPN flaw to plant webshells

Threat actors have been exploiting a command injection vulnerability in Array AG Series VPN devices to plant webshells and create…

Multiple London councils
05
Dec
2025

NCSC’s ‘Proactive Notifications’ warns orgs of flaws in exposed devices

The UK’s National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to…

Predator spyware uses new infection vector for zero-click attacks
05
Dec
2025

Predator spyware uses new infection vector for zero-click attacks

The Predator spyware from surveillance company Intellexa has been using a zero-click infection mechanism dubbed “Aladdin,” which compromised specific targets…

Apple
04
Dec
2025

Russia blocks FaceTime and Snapchat over use in terrorist attacks

Russian telecommunications watchdog Roskomnadzor has blocked access to Apple’s FaceTime video conferencing platform and the Snapchat instant messaging service, claiming…

Chinese hackers
04
Dec
2025

CISA warns of Chinese “BrickStorm” malware attacks on VMware servers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned network defenders of Chinese hackers backdooring VMware vSphere servers with Brickstorm…

Hackers
04
Dec
2025

Contractors with hacking records accused of wiping 96 govt databases

U.S. prosecutors have charged two Virginia brothers arrested on Wednesday with allegedly conspiring to steal sensitive information and destroy government…

Specops OT Environment
04
Dec
2025

How strong password policies secure OT systems against cyber threats

Operational technology (OT) interacts with crucial real-world infrastructure, empowering everything from energy plants to manufacturing facilities. Such environments are obvious…

Critical React, Next.js flaw lets hackers execute code on servers
04
Dec
2025

Critical React, Next.js flaw lets hackers execute code on servers

A maximum severity vulnerability, dubbed ‘React2Shell’, in the React Server Components (RSC) ‘Flight’ protocol allows remote code execution without authentication in React and…

Microsoft 365
04
Dec
2025

Microsoft 365 license check bug blocks desktop app downloads

​Microsoft is investigating and working to resolve a known issue that prevents customers from downloading Microsoft 365 desktop apps from…

Marquis
04
Dec
2025

Marquis data breach impacts over 74 US banks, credit unions

Financial software provider Marquis Software Solutions is warning that it suffered a data breach that impacted dozens of banks and…

French DIY retail giant Leroy Merlin discloses a data breach
04
Dec
2025

French DIY retail giant Leroy Merlin discloses a data breach

French home improvement and gardening retailer Leroy Merlin is notifying customers that their personal info has been compromised in a…

Roblox
03
Dec
2025

Russia blocks Roblox over distribution of LGBT “propaganda”

Roskomnadzor, Russia’s telecommunications watchdog, has blocked access to the Roblox online gaming platform for failing to stop the distribution of…