Category: Bleeping Computer

Nigeria arrests dev of Microsoft 365
19
Dec
2025

Nigeria arrests dev of Microsoft 365 ‘Raccoon0365’ phishing platform

The Nigerian police arrested three individuals linked to targeted Microsoft 365 cyberattacks via Raccoon0365 phishing platform. The attacks led to business…

Microsoft 365
19
Dec
2025

Microsoft 365 accounts targeted in wave of OAuth phishing attacks

Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism. Attackers trick…

Criminal IP + Palo Alto Cortex
19
Dec
2025

Criminal IP and Palo Alto Networks Cortex XSOAR integrate to bring AI-driven exposure intelligence to automated incident response

Criminal IP (criminalip.io), the AI-powered threat intelligence and attack surface monitoring platform developed by AI SPERA, is now officially integrated into…

New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock
19
Dec
2025

New UEFI flaw enables pre-boot attacks on motherboards from Gigabyte, MSI, ASUS, ASRock

The UEFI firmware implementation in some motherboards from ASUS, Gigabyte, MSI, and ASRock is vulnerable to direct memory access (DMA) attacks…

Fortinet
19
Dec
2025

Over 25,000 FortiCloud SSO devices exposed to remote attacks

Internet security watchdog Shadowserver has found over 25,000 Fortinet devices exposed online with FortiCloud SSO enabled, amid ongoing attacks targeting…

Denmark flag
19
Dec
2025

Denmark blames Russia for destructive cyberattack on water utility

Danish intelligence officials blamed Russia for orchestrating cyberattacks against Denmark’s critical infrastructure, as part of Moscow’s hybrid attacks against Western…

WatchGuard
19
Dec
2025

New critical WatchGuard Firebox firewall flaw exploited in attacks

WatchGuard has warned customers to patch a critical, actively exploited remote code execution (RCE) vulnerability in its Firebox firewalls. Tracked…

Instacart
19
Dec
2025

Instacart to refund $60M over deceptive subscription tactics

Grocery delivery service Instacart will refund $60 million to settle FTC claims that it misled customers with false advertising and…

Windows 10
19
Dec
2025

Windows 10 OOB update released to fix Message Queuing (MSMQ) issues

This month’s extended security update for Windows 10 broke Message Queuing (MSMQ), which is typically used by enterprises to manage background…

Hacker
19
Dec
2025

Clop ransomware targets Gladinet CentreStack in data theft attacks

The Clop ransomware gang (also known as Cl0p) is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign….

University of Sydney suffers data breach exposing student and staff info
18
Dec
2025

University of Sydney suffers data breach exposing student and staff info

Hackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal information…

New password spraying attacks target Cisco, PAN VPN gateways
18
Dec
2025

New password spraying attacks target Cisco, PAN VPN gateways

An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL…