Category: Bleeping Computer

Plugins on WordPress.org backdoored in supply chain attack
25
Jun
2024

Plugins on WordPress.org backdoored in supply chain attack

A threat actor modified the source code of at least five plugins hosted on WordPress.org to include malicious PHP scripts that…

Supply chain attack
25
Jun
2024

Polyfill.io JavaScript supply chain attack impacts over 100K sites

Over 100,000 sites have been impacted in a supply chain attack by the Polyfill.io service after a Chinese company acquired the domain…

New Medusa malware variants target Android users in seven countries
25
Jun
2024

New Medusa malware variants target Android users in seven countries

The Medusa banking trojan for Android has re-emerged after almost a year of keeping a lower profile in campaigns targeting…

Neiman Marcus
25
Jun
2024

Neiman Marcus confirms data breach after Snowflake account hack

Luxury retailer Neiman Marcus confirmed it suffered a data breach after hackers attempted to sell the company’s database stolen in…

FBI warns of fake law firms targeting crypto scam victims
25
Jun
2024

FBI warns of fake law firms targeting crypto scam victims

The FBI is warning of cybercriminals posing as law firms and lawyers that offer cryptocurrency recovery services to victims of…

P2PInfect botnet targets REdis servers with new ransomware module
25
Jun
2024

P2PInfect botnet targets REdis servers with new ransomware module

P2PInfect, originally a dormant peer-to-peer malware botnet with unclear motives, has finally come alive to deploy a ransomware module and…

CISA red flare
25
Jun
2024

Chemical facilities warned of possible data theft in CISA CSAT breach

CISA is warning that its Chemical Security Assessment Tool (CSAT) environment was breached in January after hackers deployed a webshell…

Chrome
24
Jun
2024

Chrome for Android tests feature that securely verifies your ID with sites

Google is testing a new feature called “Digital Credential API” for Chrome on Android that allows websites to securely request identity…

Windows
24
Jun
2024

New attack uses MSC files and Windows XSS flaw to breach networks

A novel command execution technique dubbed ‘GrimResource’ uses specially crafted MSC (Microsoft Saved Console) and an unpatched Windows XSS flaw…

Windows
24
Jun
2024

New attack uses MSC files and Windows XSS flaw to breach networks

A novel command execution technique dubbed ‘GrimResource’ uses specially crafted MSC (Microsoft Saved Console) and an unpatched Windows XSS flaw…

Justice
24
Jun
2024

Four FIN9 hackers indicted for cyberattacks causing $71M in losses

Four Vietnamese nationals linked to the international cybercrime group FIN9 have been indicted for their involvement in a series of computer…

Cards
23
Jun
2024

Facebook PrestaShop module exploited to steal credit cards

Hackers are exploiting a flaw in a premium Facebook module for PrestaShop named pkfacebook to deploy a card skimmer on…