Category: Bleeping Computer

GitHub
22
Apr
2023

GitHub now allows enabling private vulnerability reporting at scale

GitHub announced that private vulnerability reporting is now generally available and can be enabled at scale, on all repositories belonging…

macOS logo with storms in the background
21
Apr
2023

The Week in Ransomware – April 21st 2023

A lot of news broke this week related to ransomware, with the discovery of LockBit testing macOS encryptors to an…

Power lines
21
Apr
2023

Critical infrastructure also hit by supply chain attack behind 3CX breach

The X_Trader software supply chain attack that led to last month’s 3CX breach has also impacted at least several critical…

Google Cloud Platform
21
Apr
2023

GhostToken GCP flaw let attackers backdoor Google accounts

Google has addressed a Cloud Platform (GCP) security vulnerability impacting all users and allowing attackers to backdoor their accounts using…

Kubernetes
21
Apr
2023

Kubernetes RBAC abused to create persistent cluster backdoors

Hackers use a novel method involving RBAC (Role-Based Access Control) to create persistent backdoor accounts on Kubernetes clusters and hijack…

Hacker stealing Scales of Justice
21
Apr
2023

American Bar Association data breach hits 1.4 million members

The American Bar Association (ABA) has suffered a data breach after hackers compromised its network and gained access to older…

fortnite
21
Apr
2023

University websites using MediaWiki, TWiki hacked to serve Fortnite spam

Websites of multiple U.S. universities are serving Fortnite and ‘gift card’ spam. Researchers observed Wiki and documentation pages being hosted by universities including Stanford, MIT, Berkeley,…

Wordpress
20
Apr
2023

Attackers use abandoned WordPress plugin to backdoor websites

Attackers are using Eval PHP, an outdated legitimate WordPress plugin, to compromise websites by injecting stealthy backdoors. Eval PHP is an…

Russia
20
Apr
2023

Ukraine targeted by 60% of Russian phishing attacks in 2023

Google’s Threat Analysis Group (TAG) has been monitoring and disrupting Russian state-backed cyberattacks targeting Ukraine’s critical infrastructure in 2023. Google…

VMware
20
Apr
2023

VMware fixes vRealize bug that let attackers run code as root

VMware addressed a critical vRealize Log Insight security vulnerability that allows remote attackers to gain remote execution on vulnerable appliances….

Lazarus
20
Apr
2023

Lazarus hackers now push Linux malware via fake job offers

A new Lazarus campaign considered part of “Operation DreamJob” has been discovered targeting Linux users with malware for the first…

Microsoft 365
20
Apr
2023

Microsoft 365 outage blocks access to web apps and services

Microsoft is investigating an ongoing outage blocking customers worldwide from accessing and using web apps and online services. The list…