Category: Bleeping Computer

School hacker
07
May
2025

PowerSchool hacker now extorting individual school districts

PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student…

Oil pump
07
May
2025

CISA warns of hackers targeting critical oil infrastructure

CISA warned critical infrastructure organizations of “unsophisticated” threat actors actively targeting the U.S. oil and natural gas sectors. While these attacks use very basic…

Security key
07
May
2025

How Universal 2nd Factor (U2F) boosts online security

Passwords have long been the bedrock of online security, but the vulnerabilities are obvious, ranging from human error to phishing…

07
May
2025

How Universal 2nd Factor (U2F) boosts online security

Passwords have long been the bedrock of online security, but the vulnerabilities are obvious, ranging from human error to phishing…

Hacker
07
May
2025

Play ransomware exploited Windows logging flaw in zero-day attacks

The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges…

WhatsApp logo
07
May
2025

NSO Group fined $167M for spyware attacks on 1,400 WhatsApp users

A U.S. federal jury has ordered Israeli spyware vendor NSO Group to pay WhatsApp $167,254,000 in punitive damages and $444,719…

Masimo
07
May
2025

Medical device maker Masimo warns of cyberattack, manufacturing delays

Medical device company Masimo Corporation warns that a cyberattack is impacting production operations and causing delays in fulfilling customers’ orders….

DDoS
07
May
2025

Police takes down six DDoS-for-hire services, arrests admins

​Polish authorities have detained four suspects linked to six DDoS-for-hire platforms, believed to have facilitated thousands of attacks targeting schools,…

Windows Server
07
May
2025

April updates cause Windows Server auth issues

Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. The list…

Apache
06
May
2025

Apache Parquet exploit tool detect servers vulnerable to critical flaw

A proof-of-concept exploit has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy…

CISA
06
May
2025

Critical Langflow RCE flaw exploited to hack AI app servers

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations…

Samsung
06
May
2025

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks

Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and…