From BleepingComputer · 33 stories
AI Increases Efficiency of Account Takeover Attacks, Device Trust Becomes Crucial
AI is making existing identity attacks, such as phishing and credential theft, more efficient and scalable, rather than creating new attack types. This development necessitates a shift towards device trust as a critical Zero Trust measure to validate login legitimacy beyond just credentials. The increased automation of personalized attacks makes it harder to distinguish malicious logins from legitimate ones, highlighting the need for stronger authentication methods.
AI-powered phishing renders traditional blocklists ineffective due to rapid infrastructure rotation
Attackers are using AI to generate phishing pages and rapidly rotate infrastructure, making traditional blocklists and indicator-based detection methods obsolete. Phishing domains now have an average lifespan of less than two days, outpacing the ability of blocklists to track them. This shift necessitates new defense strategies against evolving phishing tactics.
BTMOB Android RAT Malware Ecosystem Expands Beyond Original Operator's Control
Research reveals the BTMOB Android Remote Access Trojan (RAT) has evolved into a complex underground business with multiple resellers and independent operators, making it difficult for the original creators to control. This expansion signifies a growing challenge in tracking and mitigating the spread of this malware-as-a-service.
Attackers Establish Persistence and Reconnaissance After Initial Breach, Huntress Reports
Huntress investigated a June incident where an attacker, after gaining initial access via SQL injection, spent time establishing persistence and performing reconnaissance rather than immediately exfiltrating data or deploying ransomware. This behavior highlights the importance of post-breach cleanup and understanding attacker dwell time to prevent further compromise.
FedRAMP 20X Shifts from Narrative-Based to Continuous, Machine-Readable Security Evidence
FedRAMP 20X is replacing the previous Rev5 framework, moving from narrative-heavy control descriptions to requiring continuous, machine-readable evidence for Key Security Indicators (KSIs). This change fundamentally alters how organizations demonstrate security posture, demanding systems capable of producing trustworthy evidence continuously rather than just for annual audits.
Research Reveals Evolving Use of Residential Proxies in Carding Operations
Flare researchers analyzed 2,889 underground posts to understand how carders are utilizing residential proxies. The findings indicate that while residential IP addresses are critical, they are increasingly seen as unreliable and require careful selection and combination with other digital identity tools.
AI Tools Facilitate Service Desk Attacks, Highlights Need for Enhanced Security
IBM's report indicates that 16% of data breaches involved AI tools, often for social engineering attacks at service desks. This trend makes it essential for organizations to improve identity verification processes to protect sensitive operations from AI-enabled impersonation.
Rise of Vibe Coding Increases Software Development Speed, Raises Security Concerns
The emergence of Vibe Coding has accelerated software development, allowing real-time application creation. This shift toward rapid development challenges organizations to ensure security measures keep pace with accelerated deployment practices.
Surfshark VPN reports breach of internal test and proxy servers due to misconfiguration
Surfshark disclosed that hackers accessed an internal test server and a separate proxy server after a configuration error exposed them to the internet. The company stated that no customer data or production VPN infrastructure was impacted, and users do not need to take action.
Windows 11 August 27 preview update causes mouse cursor, wallpaper, and font issues
Microsoft's optional Windows 11 preview update (KB5120998), released on August 27, is causing personalized mouse cursor settings to reset or change, and some users report wallpaper and font problems. Microsoft is investigating the cursor issue, and the only current workaround is to uninstall the update.
Brave Browser Adds Email Alias Feature for Enhanced User Privacy
Brave browser has introduced an email alias feature, allowing users to sign up for online services without revealing their primary email addresses. This feature aims to protect user privacy by preventing email-based tracking and reducing exposure in data breaches.
Microsoft to retire Microsoft 365 Companion apps on December 16, 2026
Microsoft will retire its Calendar, People, and Files Microsoft 365 companion apps on December 16, 2026, ceasing support and functionality. This decision comes after Microsoft began automatically installing these apps on Windows 11 enterprise devices with Microsoft 365 desktop client apps.
Microsoft fixes Defender Antivirus false alerts after recent updates
Microsoft has resolved an issue causing incorrect "Defender Antivirus is turned off" alerts after installing recent updates, with the fix included in Microsoft Defender Antivirus update version 4.18.26080.4. This matters because the false alerts affected all supported Windows client and server versions, creating confusion about system security status.
Microsoft Teams Desktop Client Experiences Opening Delays and Call Issues for Some Users
Microsoft is addressing an issue causing delays or preventing some Windows users from opening the Teams desktop client, with loading times up to two minutes. Concurrently, Mac users are unable to join Teams calls and meetings, and Microsoft is investigating the root cause.
UK man sentenced to over six years for operating illegal IPTV service
A 68-year-old man in the UK received a six-year prison sentence for running an illegal IPTV service that generated £980,812 ($1.3 million) over three years. The operation, which provided pirated broadcasts from major rights holders, was shut down by the Police Intellectual Property Crime Unit (PIPCU). This case highlights ongoing efforts by law enforcement and rights holders to combat digital piracy.
LACMA Data Breach Exposed Social Security and Medical Information from July 2025 Incident
The Los Angeles County Museum of Art (LACMA) disclosed that a data breach detected in July 2025 exposed customer and employee information, including Social Security numbers, driver's licenses, and medical data. The museum confirmed the network compromise a month after detection, but the full scope of exposed data was only determined over a year later in late February 2026. This incident highlights the extended timelines often involved in identifying the full impact of cyberattacks, even after initial detection.
Microsoft PowerToys adds Window Hopper for app-specific Alt+Tab switching
Microsoft has updated its PowerToys utility suite to version 0.101.2362.0, introducing "Window Hopper," a new feature that allows users to cycle through an individual application's open windows. This update provides a more focused window management option for users with multiple instances of the same application open, such as browser or terminal windows.
Microsoft rolls out Classic Outlook theme for New Outlook users
Microsoft is rolling out a Classic Outlook theme for Outlook on the web and the New Outlook for Windows, providing a familiar interface for users transitioning from the older client. This update aims to ease the migration process for users moving to the New Outlook experience.
Threema secure messaging service disrupted by large-scale DDoS attacks
The Threema secure messaging service experienced severe disruptions due to multiple large-scale distributed denial-of-service (DDoS) attacks. The attacks were difficult to mitigate because the threat actor constantly changed patterns and targeted both Threema and its colocation partner. This incident highlights the persistent challenge of defending against sophisticated DDoS campaigns, even for services focused on security.
Former Brightly Software Analyst Sentenced to Prison for Data Theft and Extortion
A former data analyst contractor for Brightly Software received a two-year prison sentence for stealing sensitive company data and attempting to extort $2.5 million from his employer. The individual threatened to leak payroll information and personally identifiable information (PII) after his contract was not extended, leading to a federal investigation and conviction.
Webinar Highlights Behavioral AI for Modern Email Security Threats
BleepingComputer is hosting a webinar on July 8, 2026, focused on the limitations of traditional email security against evolving threats like phishing and business email compromise. Experts will discuss how behavioral AI can automate the detection and response process, addressing attacks that leverage trusted identities and legitimate workflows.
Microsoft 365 Sharing Poses Security Challenges for Enterprises
Unmanaged cloud sharing in Microsoft 365 creates security risks for enterprises, as access to shared files often remains active longer than intended. Security teams struggle to identify who has access to sensitive information, highlighting a gap in built-in governance tools.
Edge Security Controls Struggle with High-Risk Sessions Due to Lack of Infrastructure Context
Existing edge security controls, including CDNs, WAFs, bot management, and identity systems, often fail to detect sophisticated attackers because they lack context about the underlying network infrastructure. Attackers exploit gaps between these individual controls by using residential IPs or commercial VPNs, making malicious traffic appear legitimate. This highlights a need for an additional layer of security intelligence focused on infrastructure context to improve detection of high-risk sessions.
Threat Research and MDR Offer Defensive Edge for SMBs Against Evolving Cyber Threats
Small and medium-sized businesses (SMBs) can utilize Managed Detection and Response (MDR) services, supported by threat research, to enhance their cybersecurity defenses. This approach provides proactive threat monitoring and hunting capabilities without the high cost of an in-house Security Operations Center (SOC).
Online Privacy Erodes as Surveillance Capitalism and AI Intensify Data Tracking
The internet's business model relies on tracking user data, leading to a system where personal information is monetized by data brokers. Artificial intelligence exacerbates this issue by enabling more sophisticated linking and profiling of user actions, making online privacy increasingly difficult to maintain.
FileJump offers lifetime 2TB cloud storage plan for $59
FileJump has launched a lifetime plan providing 2TB of cloud storage for a one-time fee of $59. This plan includes zero-knowledge encryption and a drag-and-drop interface, making it an affordable option for new users seeking secure data storage.
Claude Code weekly usage limits temporarily increased by 50% for select plans
Claude Code is offering a temporary 50% increase in weekly usage limits for Pro, Max, Team, and legacy seat-based Enterprise plans from May 13, 2026, to August 19, 2026. This promotion provides eligible users with more capacity for coding assistance during the specified period.
Wazuh Helps Identify Shadow IT and Visibility Gaps
Wazuh, an open-source security platform, helps organizations identify shadow IT by collecting system inventory data directly from monitored endpoints. This method allows for comparison with network scan data to uncover unmanaged assets, unapproved software, and monitoring blind spots. The approach addresses limitations of traditional network discovery, which often misses powered-off devices or software not exposing network ports.
Six-point checklist for MSPs to improve ransomware recovery
A six-point checklist outlines essential outcomes for Managed Service Providers (MSPs) to enhance ransomware protection and accelerate recovery processes. The checklist addresses reducing exposure, early detection, 24/7 response, isolated recovery points, clean recovery, and consistent operation across tenants. This guidance aims to help MSPs improve their resilience against ransomware attacks, which affected 143 MSPs and IT service providers in 2025 according to the Acronis Cyberthreats Report.
Secure File Server Management: Best Practices for Access Governance
Organizations continue to use on-premises file servers due to factors like cloud costs and data sovereignty. Effective access governance is crucial for securing these file servers, which remain an IT mainstay. One key best practice involves assigning permissions to security groups rather than directly to individual users.
Securing Single Sign-On Against Credential Attacks
Single Sign-On (SSO) systems, while convenient, concentrate risk, as demonstrated by the 2025 University of Pennsylvania breach where a compromised SSO account led to data theft. Organizations must secure SSO by implementing strong password policies and multi-factor authentication to mitigate these risks. This matters because proper SSO security is crucial for protecting multiple systems and user data from credential-based attacks.
tenfold Introduces Real-time Identity Telemetry for Proactive Threat Detection
tenfold announced a new event auditing platform that ingests and analyzes identity event logs in real time. This platform aims to provide proactive defense against sophisticated attacks by monitoring identity events as they happen, moving beyond traditional identity governance.
BleepingComputer to Host Webinar on Google Workspace Breach Autopsies with Material Security
BleepingComputer will host a webinar on September 23, 2026, featuring Material Security and Fireside Consulting LLC, to discuss how Google Workspace breaches occur and effective response strategies. The event will analyze real-world incidents to provide practical security controls for fast-growing companies using Google Workspace.