Category: Bleeping Computer

Ivanti
09
Jan
2025

Ivanti warns of new Connect Secure flaw used in zero-day attacks

Ivanti is warning that hackers exploited a Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 in zero-day attacks to install malware…

Unpatched critical flaws impact Fancy Product Designer WordPress plugin
09
Jan
2025

Unpatched critical flaws impact Fancy Product Designer WordPress plugin

Premium WordPress plugin Fancy Product Designer from Radykal is vulnerable to two critical severity flaws that remain unfixed in the…

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens
08
Jan
2025

Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens

Hackers are trying to exploit CVE-2024-52875, a critical CRLF injection vulnerability that leads to 1-click remote code execution (RCE) attacks in…

Medusind
08
Jan
2025

Medical billing firm Medusind discloses breach affecting 360,000 people

​Medusind, a leading billing provider for healthcare organizations, is notifying hundreds of thousands of individuals of a data breach that…

Over 4,000 backdoors hijacked by registering expired domains
08
Jan
2025

Over 4,000 backdoors hijacked by registering expired domains

Over 4,000 abandoned but still active web backdoors were hijacked and their communication infrastructure sinkholed after researchers registered expired domains used…

Specops lock
08
Jan
2025

How initial access brokers (IABs) sell your users’ credentials

Even if you haven’t looked into the methods of initial access brokers (IABs), you’ve almost certainly read about their handiwork…

Packers Pro Shop
08
Jan
2025

Thousands of credit cards stolen in Green Bay Packers store breach

​American football team Green Bay Packers says cybercriminals stole the credit card data of over 8,500 customers after hacking its official…

ICAO
08
Jan
2025

UN aviation agency confirms recruitment database security breach

​The United Nations’ International Civil Aviation Organization (ICAO) has confirmed that a threat actor has stolen approximately 42,000 records after…

Empty school
08
Jan
2025

PowerSchool hack exposes student, teacher data from K-12 districts

Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat actor to steal the personal…

Casio
08
Jan
2025

Casio says data of 8,500 people exposed in October ransomware attack

Japanese electronics manufacturer Casio says that the October 2024 ransomware incident exposed the personal data of approximately 8,500 people. The…

Bios flaws and no Secure Boot expose Illumina DNA sequencers to attacks
08
Jan
2025

BIOS flaws expose iSeq DNA sequencers to bootkit attacks

BIOS/UEFI vulnerabilities in the iSeq 100 DNA sequencer from U.S. biotechnology company Illumina could let attackers disable devices used for…

New Mirai botnet targets industrial routers with zero-day exploits
08
Jan
2025

New Mirai botnet targets industrial routers with zero-day exploits

A relatively new Mirai-based botnet has been growing in sophistication and is now leveraging zero-day exploits for security flaws in…