Category: Bleeping Computer

22
Oct
2025

Hackers exploit 56 zero-days for $790,000

Security researchers collected $792,750 in cash after exploiting 56 unique zero-day vulnerabilities during the second day of the Pwn2Own Ireland 2025 hacking competition. Today’s highlight…

Box
22
Oct
2025

TARmageddon flaw in abandoned Rust library enables RCE attacks

A high-severity vulnerability in the now-abandoned async-tar Rust library and its forks can be exploited to gain remote code execution…

Person typing on laptop
22
Oct
2025

FinWise data breach shows why encryption is your last defense

The 2024 FinWise data breach serves as a stark example of the growing insider threats faced by modern financial institutions….

Meta
22
Oct
2025

Meta launches new anti-scam tools for WhatsApp and Messenger

Meta has announced new tools to help WhatsApp and Messenger users protect themselves from potential scams and secure their accounts. On Messenger,…

Card
22
Oct
2025

PhantomCaptcha ClickFix attack targets Ukraine war relief orgs

A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for…

Hacker
22
Oct
2025

Sharepoint ToolShell attacks targeted orgs across four continents

Hackers believed to be associated with China have leveraged the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint in attacks targeting government…

CommetJacking attack tricks Comet browser into stealing emails
22
Oct
2025

Vidar Stealer 2.0 adds multi-threaded data theft, better evasion

Security researchers are warning that Vidar Stealer infections are likely to increase after the malware developer released a new major…

TP-Link warns of critical command injection flaw in Omada gateways
22
Oct
2025

TP-Link warns of critical command injection flaw in Omada gateways

TP-Link is warning of two command injection vulnerabilities in Omada gateway devices that could be exploited to execute arbitrary OS commands….

Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
21
Oct
2025

Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities

The latest releases of Cursor and Windsurf integrated development environments are vulnerable to more than 94 known and patched security issues in…

CISA
21
Oct
2025

CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw

CISA has confirmed that an Oracle E-Business Suite flaw tracked as CVE-2025-61884 is being exploited in attacks, adding it to its…

Windows
21
Oct
2025

Recent Windows updates cause login issues on some PCs

Microsoft has confirmed that Windows updates released since August 29, 2025, are breaking authentication on systems sharing Security Identifiers. Windows…

Pwn2Own Ireland
21
Oct
2025

Hackers exploit 34 zero-days on first day of Pwn2Own Ireland

On the first day of Pwn2Own Ireland 2025, security researchers exploited 34 unique zero-days and collected $522,500 in cash awards….