Category: Bleeping Computer

FlowerStorm Phishing
23
Dec
2024

New FlowerStorm Microsoft phishing service fills void left by Rockstar2FA

A new Microsoft 365 phishing-as-a-service platform called “FlowerStorm” is growing in popularity, filling the void left behind by the sudden shutdown of…

North Korean hackers
23
Dec
2024

North Korean hackers stole $1.3 billion worth of crypto this year

North Korean hackers have stolen $1.34 billion worth of cryptocurrency across 47 cyberattacks that occurred in 2024, according to a…

Microsoft 365
23
Dec
2024

Microsoft fixes bug behind random Office 365 deactivation errors

​Microsoft has rolled out a fix for a known issue that causes random “Product Deactivated” errors for customers using Microsoft 365…

Apache fixes remote code execution bypass in Tomcat web server
23
Dec
2024

Apache fixes remote code execution bypass in Tomcat web server

Apache has released a security update that addresses an important vulnerability in Tomcat web server that could lead to an…

Sophos
21
Dec
2024

Sophos discloses critical Firewall remote code execution flaw

Sophos has addressed three vulnerabilities in its Sophos Firewall product that could allow remote unauthenticated threat actors to perform SQL…

Google Chrome
21
Dec
2024

Google Chrome uses AI to analyze pages in new scam detection feature

Google is using artificial intelligence to power a new Chrome scam protection feature that analyzes brands and the intent of pages…

Google Chrome
21
Dec
2024

Google says new scam protection feature in Chrome uses AI

Google is planning to use “AI” in Chrome to detect scams when you browse random web pages. As spotted by…

Cryptocurrency
20
Dec
2024

Malicious Rspack, Vant packages published using stolen NPM tokens

Three popular npm packages, @rspack/core, @rspack/cli, and Vant, were compromised through stolen npm account tokens, allowing threat actors to publish…

LockBit
20
Dec
2024

US charges Russian-Israeli as suspected LockBit ransomware coder

The US Department of Justice has charged a Russian-Israeli dual-national for his suspected role in developing malware and managing the…

Sophos
20
Dec
2024

Sophos Firewall vulnerable to critical remote code execution flaw

Sophos has addressed three vulnerabilities in its Sophos Firewall product that could allow remote unauthenticated threat actors to perform SQL…

Krispy Kreme
20
Dec
2024

Krispy Kreme breach, data theft claimed by Play ransomware gang

​The Play ransomware gang has claimed responsibility for a cyberattack that impacted the business operations of the U.S. doughnut chain…

Ascension
20
Dec
2024

Health data of 5.6 million stolen in ransomware attack

​Ascension, one of the largest private U.S. healthcare systems, is notifying over 5.6 million patients and employees that their personal…