Category: Bleeping Computer

Hackers use Windows RID hijacking to create hidden admin account
24
Jan
2025

Hackers use Windows RID hijacking to create hidden admin account

A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account…

Subaru
24
Jan
2025

Subaru Starlink flaw let hackers hijack cars in US and Canada

Security researchers have discovered an arbitrary account takeover flaw in Subaru’s Starlink service that could let attackers track, control, and hijack vehicles in…

Hacker smiley face
24
Jan
2025

Hacker infects 18,000 “script kiddies” with fake malware builder

A threat actor targeted low-skilled hackers, known as “script kiddies,” with a fake malware builder that secretly infected them with…

SmartTech header
24
Jan
2025

Managed Detection and Response – How are you monitoring?

Security Information and Event Management (SIEM) systems are now a critical component of enterprise security operations, helping organizations detect, respond…

Exchange Server
24
Jan
2025

Outdated Exchange servers fail to auto-mitigate security bugs

Microsoft says outdated Exchange servers cannot receive new emergency mitigation definitions because an Office Configuration Service certificate type is being…

Pwn2Own Automotive Tokyo
24
Jan
2025

Hackers get $886,250 for 49 zero-days at Pwn2Own Automotive 2025

​The Pwn2Own Automotive 2025 hacking contest has ended with security researchers collecting $886,250 after exploiting 49 zero-days. Throughout the event,…

Hacker data theft
24
Jan
2025

North Korean IT workers steal source code to extort employers

The FBI warned today that North Korean IT workers are abusing their access to steal source code and extort U.S….

Android
23
Jan
2025

New Android Identity Check locks settings outside trusted locations

Google has announced a new Android “Identity Check” security feature that lock sensitive settings behind biometric authentication when outside a…

Google
23
Jan
2025

Google launches customizable Web Store for Enterprise extensions

Google has officially launched its Chrome Web Store for Enterprises, allowing organizations to create a curated list of extensions that…

Hundreds of fake Reddit sites push Lumma Stealer malware
23
Jan
2025

Hundreds of fake Reddit sites push Lumma Stealer malware

Hackers are distributing close to 1,000 web pages mimicking Reddit and the WeTransfer file sharing service that lead to downloading…

QNAP
23
Jan
2025

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app

QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS)…

Ivanti
23
Jan
2025

Hackers still exploiting older Ivanti bugs to breach networks

CISA and the FBI warned today that attackers are still exploiting Ivanti Cloud Service Appliances (CSA) security flaws patched since…