Category: Bleeping Computer

Veeam
22
May
2024

Veeam warns of critical Backup Enterprise Manager auth bypass bug

​Veeam warned customers today to patch a critical security vulnerability that allows unauthenticated attackers to sign into any account via…

ShadowSyndicate hackers linked to multiple ransomware ops, 85 servers
22
May
2024

GhostEngine mining attacks kill EDR security using vulnerable drivers

A malicious crypto mining campaign codenamed ‘REF4578,’ has been discovered deploying a malicious payload named GhostEngine that uses vulnerable drivers to turn off…

London Drugs
22
May
2024

LockBit says they stole data in London Drugs ransomware attack

Today, the LockBit ransomware gang claimed they were behind the April cyberattack on Canadian pharmacy chain London Drugs and is…

Leak
21
May
2024

Bitbucket artifact files can leak plaintext authentication secrets

Threat actors were found breaching AWS accounts using authentication secrets leaked as plaintext in Atlassian Bitbucket artifact objects. The issue was…

WSU
21
May
2024

Western Sydney University data breach exposed student data

Western Sydney University (WSU) has notified students and academic staff about a data breach after threat actors breached its Microsoft…

Leak
21
May
2024

Atlassian Bitbucket artifacts can leak plaintext auth secrets

Threat actors were found breaching AWS accounts using authentication secrets leaked as plaintext in Atlassian Bitbucket artifact objects. The issue was…

Rockwell Automation
21
May
2024

Rockwell Automation warns admins to take ICS devices offline

Rockwell Automation warned customers to disconnect all industrial control systems (ICSs) not designed for online exposure from the Internet due…

Google Chrome
21
May
2024

Google rolls out Chrome fix for empty pages when switching tabs

Google is rolling out a server-side fix for a known issue affecting the Chrome browser that causes webpage content to…

GitHub
21
May
2024

GitHub warns of SAML auth bypass flaw in Enterprise Server

GitHub has fixed a maximum severity (CVSS v4 score: 10.0) authentication bypass vulnerability tracked as CVE-2024-4986, which impacts GitHub Enterprise Server (GHES)…

Zoom
21
May
2024

Zoom adds post-quantum end-to-end encryption to video meetings

Zoom has announced the global availability of post-quantum end-to-end encryption (E2EE) for Zoom Meetings, with Zoom Phone and Zoom Rooms…

Omnivision camera
21
May
2024

OmniVision discloses data breach after 2023 ransomware attack

The California-based imaging sensors manufacturer OmniVision is warning of a data breach after the company suffered a Cactus ransomware attack…

Hacker cloud
21
May
2024

Critical Fluent Bit flaw impacts all major cloud providers

​A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud…