Category: Bleeping Computer

WordPress
07
May
2025

Hackers exploit OttoKit WordPress plugin flaw to add admin accounts

Hackers are exploiting a critical unauthenticated privilege escalation vulnerability in the OttoKit WordPress plugin to create rogue admin accounts on…

Phishing
07
May
2025

CoGUI phishing platform sent 580 million emails to steal credentials

A new phishing kit named ‘CoGUI’ sent over 580 million emails to targets between January and April 2025, aiming to…

School hacker
07
May
2025

PowerSchool hacker now extorting individual school districts

PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student…

Oil pump
07
May
2025

CISA warns of hackers targeting critical oil infrastructure

CISA warned critical infrastructure organizations of “unsophisticated” threat actors actively targeting the U.S. oil and natural gas sectors. While these attacks use very basic…

Security key
07
May
2025

How Universal 2nd Factor (U2F) boosts online security

Passwords have long been the bedrock of online security, but the vulnerabilities are obvious, ranging from human error to phishing…

07
May
2025

How Universal 2nd Factor (U2F) boosts online security

Passwords have long been the bedrock of online security, but the vulnerabilities are obvious, ranging from human error to phishing…

Hacker
07
May
2025

Play ransomware exploited Windows logging flaw in zero-day attacks

The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges…

WhatsApp logo
07
May
2025

NSO Group fined $167M for spyware attacks on 1,400 WhatsApp users

A U.S. federal jury has ordered Israeli spyware vendor NSO Group to pay WhatsApp $167,254,000 in punitive damages and $444,719…

Masimo
07
May
2025

Medical device maker Masimo warns of cyberattack, manufacturing delays

Medical device company Masimo Corporation warns that a cyberattack is impacting production operations and causing delays in fulfilling customers’ orders….

DDoS
07
May
2025

Police takes down six DDoS-for-hire services, arrests admins

​Polish authorities have detained four suspects linked to six DDoS-for-hire platforms, believed to have facilitated thousands of attacks targeting schools,…

Windows Server
07
May
2025

April updates cause Windows Server auth issues

Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. The list…

Apache
06
May
2025

Apache Parquet exploit tool detect servers vulnerable to critical flaw

A proof-of-concept exploit has been publicly released for a maximum severity Apache Parquet vulnerability, tracked as CVE-2025-30065, making it easy…