Category: Bleeping Computer

J-magic backdoor vets reply before giving access to enterprise Juniper routers
23
Jan
2025

Stealthy ‘Magic Packet’ malware targets Juniper VPN gateways

A malicious campaign has been specifically targeting Juniper edge devices, many acting as VPN gateways, with malware dubbed J-magic that…

SonicWall
23
Jan
2025

SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks

SonicWall is warning about a pre-authentication deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), with…

Pwn2Own Tokyo
23
Jan
2025

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo

​Security researchers hacked Tesla’s Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking…

Wordpress
23
Jan
2025

Critical zero-days impact premium WordPress real estate plugins

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow…

Cloudflare
23
Jan
2025

Cloudflare CDN flaw leaks user location data, even through secure chat apps

A security researcher discovered a flaw in Cloudflare’s content delivery network (CDN), which could expose a person’s general location by simply…

Telegram
23
Jan
2025

Telegram captcha tricks you into running malicious PowerShell scripts

Threat actors on X are exploiting the news around Ross Ulbricht to direct unsuspecting users to a Telegram channel that…

Cisco
22
Jan
2025

Cisco warns of denial of service flaw with PoC exploit code

Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code. Tracked as…

Hacker in a school
22
Jan
2025

PowerSchool hacker claims they stole data of 62 million students

The hacker who breached education tech giant PowerSchool claimed in an extortion demand that they stole the personal data of…

Conduent
22
Jan
2025

Conduent confirms cybersecurity incident behind recent outage

American business services giant and government contractor Conduent confirmed today that a recent outage resulted from what it described as…

Pwn2Own Tokyo 2025
22
Jan
2025

Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025

On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards….

VPN Protected
22
Jan
2025

IPany VPN breached in supply-chain attack to push custom malware

South Korean VPN provider IPany was breached in a supply chain attack by the “PlushDaemon” China-aligned hacking group, who compromised…

Windows 11
22
Jan
2025

Windows 11 24H2 now also offered to all eligible Windows 10 PCs

Microsoft says Windows 11 24H2 has entered the broad deployment phase and is now available to all seekers via Windows Update. The…