Category: Bleeping Computer

Pwn2Own Automotive Tokyo
24
Jan
2025

Hackers get $886,250 for 49 zero-days at Pwn2Own Automotive 2025

​The Pwn2Own Automotive 2025 hacking contest has ended with security researchers collecting $886,250 after exploiting 49 zero-days. Throughout the event,…

Hacker data theft
24
Jan
2025

North Korean IT workers steal source code to extort employers

The FBI warned today that North Korean IT workers are abusing their access to steal source code and extort U.S….

Android
23
Jan
2025

New Android Identity Check locks settings outside trusted locations

Google has announced a new Android “Identity Check” security feature that lock sensitive settings behind biometric authentication when outside a…

Google
23
Jan
2025

Google launches customizable Web Store for Enterprise extensions

Google has officially launched its Chrome Web Store for Enterprises, allowing organizations to create a curated list of extensions that…

Hundreds of fake Reddit sites push Lumma Stealer malware
23
Jan
2025

Hundreds of fake Reddit sites push Lumma Stealer malware

Hackers are distributing close to 1,000 web pages mimicking Reddit and the WeTransfer file sharing service that lead to downloading…

QNAP
23
Jan
2025

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app

QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS)…

Ivanti
23
Jan
2025

Hackers still exploiting older Ivanti bugs to breach networks

CISA and the FBI warned today that attackers are still exploiting Ivanti Cloud Service Appliances (CSA) security flaws patched since…

Brave Search now lets users ‘Rerank’ results from favorite sites
23
Jan
2025

Brave Search now lets users ‘Rerank’ results from favorite sites

Brave Search has introduced a new feature called Rerank, which allows users to define search results ordering preferences and set…

J-magic backdoor vets reply before giving access to enterprise Juniper routers
23
Jan
2025

Stealthy ‘Magic Packet’ malware targets Juniper VPN gateways

A malicious campaign has been specifically targeting Juniper edge devices, many acting as VPN gateways, with malware dubbed J-magic that…

SonicWall
23
Jan
2025

SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks

SonicWall is warning about a pre-authentication deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), with…

Pwn2Own Tokyo
23
Jan
2025

Tesla EV charger hacked twice on second day of Pwn2Own Tokyo

​Security researchers hacked Tesla’s Wall Connector electric vehicle charger twice on the second day of the Pwn2Own Automotive 2025 hacking…

Wordpress
23
Jan
2025

Critical zero-days impact premium WordPress real estate plugins

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow…