Category: Bleeping Computer

pfSense
12
Dec
2023

Over 1,450 pfSense servers exposed to RCE attacks via bug chain

Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable…

Kyivstar store
12
Dec
2023

Ukraine’s largest mobile carrier Kyivstar down following cyberattack

Kyivstar, Ukraine’s largest telecommunications service provider serving over 25 million mobile and home internet subscribers, has suffered a cyberattack impacting…

Hacker
12
Dec
2023

Cloud engineer gets 2 years for wiping ex-employer’s code repos

Miklos Daniel Brody, a cloud engineer, was sentenced to two years in prison and a restitution of $529,000 for wiping…

WordPress
12
Dec
2023

50K WordPress sites exposed to RCE attacks by critical bug in backup plugin

A critical severity vulnerability in a WordPress plugin with more than 90,000 installs can let attackers gain remote code execution…

Lazarus hackers
12
Dec
2023

Lazarus hackers drop new RAT malware using 2-year-old Log4j bug

The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka “Log4Shell,” this time to deploy three…

Counter-Strike 2
11
Dec
2023

Counter-Strike 2 HTML injection bug exposes players’ IP addresses

Valve has reportedly fixed an HTML injection flaw in Counter-Strike 2 that was heavily abused today to inject images into…

Apple emergency updates fix recent zero-days on older iPhones
11
Dec
2023

Apple emergency updates fix recent zero-days on older iPhones

Apple has issued emergency security updates to backport patches for two actively exploited zero-day flaws to older iPhones and some…

Toyota
11
Dec
2023

Toyota warns customers of data breach exposing personal, financial info

Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was…

Americold
11
Dec
2023

Cold storage giant Americold discloses data breach after April malware attack

Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen…

Hacker arrest
11
Dec
2023

Kelvin Security hacking group leader arrested in Spain

The Spanish police have arrested one of the alleged leaders of the ‘Kelvin Security’ hacking group, which is believed to…

Over 30% of Log4J apps use a vulnerable version of the library
10
Dec
2023

Over 30% of Log4J apps use a vulnerable version of the library

Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a…

Android
09
Dec
2023

AutoSpill attack steals credentials from Android password managers

Security researchers developed a new attack, which they named AutoSpill, to steal account credentials on Android during the autofill operation….