Category: Bleeping Computer

Amazon: Ongoing cryptomining campaign uses hacked AWS accounts
31
Dec
2025

Hackers drain $3.9M from Unleash Protocol after multisig hijack

The decentralized intellectual property platform Unleash Protocol has lost around $3.9 million worth of cryptocurrency after someone executed an unauthorized contract…

RondoDox botnet exploits React2Shell flaw to breach Next.js servers
31
Dec
2025

RondoDox botnet exploits React2Shell flaw to breach Next.js servers

The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. First…

IBM
31
Dec
2025

IBM warns of critical API Connect auth bypass vulnerability

IBM urged customers to patch a critical authentication bypass vulnerability in its API Connect enterprise platform that could allow attackers…

Disney
31
Dec
2025

Disney will pay $10 million to settle children’s data privacy lawsuit

Disney has agreed to pay a $10 million civil penalty to settle claims that it violated the Children’s Online Privacy…

New password spraying attacks target Cisco, PAN VPN gateways
31
Dec
2025

New ErrTraffic service enables ClickFix attacks via fake browser glitches

A new cybercrime tool called ErrTraffic allows threat actors to automate ClickFix attacks by generating ‘fake glitches’ on compromised websites to…

Zoom Stealer browser extensions harvest corporate meeting intelligence
30
Dec
2025

Zoom Stealer browser extensions harvest corporate meeting intelligence

A newly discovered campaign, which researchers call Zoom Stealer, is affecting 2.2 million Chrome, Firefox, and Microsoft Edge users through…

European Space Agency
30
Dec
2025

European Space Agency confirms breach of “external servers”

The European Space Agency (ESA) confirmed that attackers recently breached servers outside its corporate network, which contained what it described…

Hackers
30
Dec
2025

US cybersecurity experts plead guilty to BlackCat ransomware attacks

Two former employees of cybersecurity incident response companies Sygnia and DigitalMint have pleaded guilty to targeting U.S. companies in BlackCat…

CISA
30
Dec
2025

CISA orders feds to patch MongoBleed flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to secure their systems against a high-severity MongoDB flaw…

Chinese state hackers use rootkit to hide ToneShell malware activity
30
Dec
2025

Chinese state hackers use rootkit to hide ToneShell malware activity

A new sample of the ToneShell backdoor, typically seen in Chinese cyberespionage campaigns, has been delivered through a kernel-mode loader…

Coupang to split $1.17 billion among 33.7 million data breach victims
30
Dec
2025

Coupang to split $1.17 billion among 33.7 million data breach victims

Coupang, the largest retailer in South Korea, announced $1.17 billion (1.685 trillion Won) total compensation for the 33.7 million customers whose…

ClickFix attack uses fake Windows Update screen to push malware
29
Dec
2025

Hacker arrested for KMSAuto malware campaign with 2.8 million downloads

A Lithuanian national has been arrested for his alleged involvement in infecting 2.8 million systems with clipboard-stealing malware disguised as…