Category: Bleeping Computer

Google: Chinese hackers likely behind Ivanti VPN zero-day attacks
09
Jan
2025

Chinese hackers likely behind Ivanti VPN zero-day attacks

Hackers exploiting the critical Ivanti Connect Secure zero-day vulnerability disclosed yesterday installed on compromised VPN appliances new malware called ‘Dryhook’ and…

Criminal IP outlook protection header
09
Jan
2025

Bringing Real-Time Phishing Detection to Microsoft Outlook

Criminal IP, a globally recognized Cyber Threat Intelligence (CTI) solution by AI SPERA, has launched its Criminal IP Malicious Link Detector add-in…

Outlook
09
Jan
2025

Microsoft fixes bug causing Outlook freezes when copying text

Microsoft has fixed a known issue causing the classic Outlook email client to stop responding when copying text with the…

Sonicwall
09
Jan
2025

SonicWall urges admins to patch exploitable SSLVPN bug immediately

SonicWall is emailing customers urging them to upgrade their firewall’s SonicOS firmware to patch an authentication bypass vulnerability in SSL VPN…

Ukrainian hacker
09
Jan
2025

Russian ISP confirms Ukrainian hackers “destroyed” its network

​Ukrainian hacktivists, part of the Ukrainian Cyber Alliance group, announced on Tuesday they had breached Russian internet service provider Nodex’s…

Ivanti
09
Jan
2025

Ivanti warns of new Connect Secure flaw used in zero-day attacks

Ivanti is warning that hackers exploited a Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 in zero-day attacks to install malware…

Unpatched critical flaws impact Fancy Product Designer WordPress plugin
09
Jan
2025

Unpatched critical flaws impact Fancy Product Designer WordPress plugin

Premium WordPress plugin Fancy Product Designer from Radykal is vulnerable to two critical severity flaws that remain unfixed in the…

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens
08
Jan
2025

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens

Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in…

Medusind
08
Jan
2025

Medical billing firm Medusind discloses breach affecting 360,000 people

​Medusind, a leading billing provider for healthcare organizations, is notifying hundreds of thousands of individuals of a data breach that…

Over 4,000 backdoors hijacked by registering expired domains
08
Jan
2025

Over 4,000 backdoors hijacked by registering expired domains

Over 4,000 abandoned but still active web backdoors were hijacked and their communication infrastructure sinkholed after researchers registered expired domains used…

Specops lock
08
Jan
2025

How initial access brokers (IABs) sell your users’ credentials

Even if you haven’t looked into the methods of initial access brokers (IABs), you’ve almost certainly read about their handiwork…

Packers Pro Shop
08
Jan
2025

Thousands of credit cards stolen in Green Bay Packers store breach

​American football team Green Bay Packers says cybercriminals stole the credit card data of over 8,500 customers after hacking its official…