Category: Bleeping Computer

WordPress
12
Dec
2023

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution…

Lazarus hackers
12
Dec
2023

Lazarus hackers drop new RAT malware using 2-year-old Log4j bug

The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka “Log4Shell,” this time to deploy three…

Counter-Strike 2
11
Dec
2023

Counter-Strike 2 HTML injection bug exposes players’ IP addresses

Valve has reportedly fixed an HTML injection flaw in Counter-Strike 2 that was heavily abused today to inject images into…

Apple emergency updates fix recent zero-days on older iPhones
11
Dec
2023

Apple emergency updates fix recent zero-days on older iPhones

Apple has issued emergency security updates to backport patches for two actively exploited zero-day flaws to older iPhones and some…

Toyota
11
Dec
2023

Toyota warns customers of data breach exposing personal, financial info

Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was…

Americold
11
Dec
2023

Cold storage giant Americold discloses data breach after April malware attack

Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen…

Hacker arrest
11
Dec
2023

Kelvin Security hacking group leader arrested in Spain

The Spanish police have arrested one of the alleged leaders of the ‘Kelvin Security’ hacking group, which is believed to…

Over 30% of Log4J apps use a vulnerable version of the library
10
Dec
2023

Over 30% of Log4J apps use a vulnerable version of the library

Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a…

Android
09
Dec
2023

AutoSpill attack steals credentials from Android password managers

Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation….

Hospital cyberattack
09
Dec
2023

Norton Healthcare discloses data breach after May ransomware attack

Kentucky health system Norton Healthcare has confirmed that a ransomware attack in May exposed personal information belonging to patients, employees,…

Google Drive
08
Dec
2023

Google shares “fix” for deleted Google Drive files

Google says it identified and fixed a bug causing customer files added to Google Drive after April-May 2023 to disappear….

BlackCat Munchkin
08
Dec
2023

ALPHV ransomware site outage rumored to be caused by law enforcement

A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang’s websites over the last 30…