For you Ai Security Dev Cloud Hardware Startups Releases General

From BleepingComputer · 40 stories

4 sources 4 reports 30d ago

Sality P2P Botnet Dismantled After 23 Years of Operation

The Sality peer-to-peer (P2P) botnet, active since 2003, has been disrupted through an international law enforcement effort involving the U.S. Department of Justice, Europol, Eurojust, and private partners like CrowdStrike and the Shadowserver Foundation. The operation, which took place on August 31, 2026, included a P2P sinkhole and domain seizures, effectively neutralizing a long-standing threat that infected over 15,000 devices and distributed various malware, including the EggJagger clipjacking tool.

security botnet malware cybercrime cybersecurity
4 sources 5 reports 32d ago

Boston Scientific reports cyberattack disrupting global operations and order processing

Medical technology company Boston Scientific experienced a cyberattack on August 25 that disrupted its IT systems, causing a network outage and affecting its ability to process and ship customer orders globally. The incident impacts a major medical device manufacturer, potentially affecting the supply chain for critical medical equipment worldwide.

security cybersecurity data breach medical devices supply chain
4 sources 4 reports 34d ago

ATF confirms "major incident" after Qilin ransomware group claims breach

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a "major incident" involving a breach of one of its standalone systems, following claims by the Qilin ransomware group. The agency stated that its main enterprise network, eForms system, and other ATF systems were not affected, and operations remain uninterrupted.

security ransomware government breach cybersecurity
4 sources 5 reports 45d ago

Ransom Cartel Creator Sentenced to 16 Years for Ransomware-as-a-Service Operation

Maksim Silnikau, the 40-year-old Belarusian creator and administrator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison in Virginia. Silnikau developed the ransomware and recruited affiliates to attack at least 18 companies globally between 2021 and 2023, providing them with tools and infrastructure for intrusions and ransom negotiations.

security ransomware cybercrime sentencing doj
4 sources 4 reports 45d ago

SafePal data breach exposes order information for 39,798 customers

Cryptocurrency hardware wallet provider SafePal reported a data breach affecting approximately 39,798 customers, exposing names, email addresses, shipping addresses, phone numbers, and purchase information. A threat actor is now claiming to sell this stolen data on a cybercrime forum. This breach could lead to targeted phishing and social engineering attacks against affected customers.

security data breach cryptocurrency hardware wallet
4 sources 6 reports 46d ago

New 'ShieldBreak' Zero-Day Exploit Bypasses Microsoft Defender Patch, Grants SYSTEM Privileges

Security researcher Nightmare Eclipse released "ShieldBreak," a new zero-day exploit for Microsoft Defender that bypasses a previous patch for the RoguePlanet vulnerability (CVE-2026-50656). This exploit allows SYSTEM privileges on fully updated Windows 10, Windows 11, and Windows Server systems, highlighting an incomplete patch for a privilege escalation flaw.

security vulnerability microsoft defender zero-day windows
4 sources 4 reports 50d ago

FBI Warns of Cybercriminals Hacking Accounts to Steal Explicit Images for Extortion

The FBI has issued a public warning about cybercriminals hacking into social media and online accounts of adults and children to steal explicit images and videos. These stolen materials are then used for blackmail, sold on criminal marketplaces, or shared with other criminals to facilitate further sextortion, with student-athletes and young boys frequently targeted.

security cybersecurity fbi social engineering extortion
4 sources 4 reports 51d ago

Mozilla Replaces GPG Signing Key for Firefox and Thunderbird After Accidental Exposure

Mozilla has replaced the GPG signing subkey used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files. The previous key was inadvertently committed in an unencrypted copy to a private GitHub repository. This change primarily affects users who manually verify GPG signatures or use Firefox RPM packages on older Linux distributions, who will need to import the new key and the old key's revocation.

security mozilla firefox thunderbird gpg
4 sources 4 reports 55d ago

UNC6671 Extortion Group Rebrands and Continues Vishing Attacks on Financial Firms

The UNC6671 extortion group has rebranded its operations under new names including Redact, Pink, Helix, and Falcon, despite an alleged retirement of its previous BlackFile brand. The group continues to use voice phishing (vishing) to target enterprise employees, particularly in financial services, private equity, and professional services, leading to data theft from cloud environments like Microsoft 365 and Okta.

security vishing extortion cloud cybersecurity
4 sources 4 reports 57d ago

Over 24,000 Internet-Exposed Servers Leak BMC Password Hashes via Decades-Old Flaw

More than 24,000 internet-exposed servers are leaking authentication password hashes due to CVE-2013-4786, a 20-year-old vulnerability in the Intelligent Platform Management Interface (IPMI) v2.0 specification. This flaw allows remote attackers to obtain password hashes before login and conduct offline password guessing attacks, potentially leading to full control over physical servers and broader management plane compromise.

security vulnerability bmc ipmi datacenter
4 sources 6 reports 59d ago

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.

security phishing dns microsoft365 wi-fi
4 sources 5 reports 66d ago

Origin Energy Confirms Customer Data Breach Affecting Personal and Partial Banking Details

Origin Energy confirmed a data breach affecting its 4.8 million customer accounts, compromising personal details and partial banking information. This incident exposes customers to potential identity theft and phishing, highlighting ongoing cybersecurity risks for critical service providers.

security data breach cybersecurity australia origin energy
4 sources 4 reports 70d ago

Symlink Vulnerability in AI Coding Assistants Poses Security Threat

Researchers discovered that a vulnerability in six AI coding assistants allows malicious repositories to execute code on developers' machines. By exploiting symbolic link (symlink) flaws, attackers could bypass user consent and access sensitive files, raising significant security concerns.

security ai dev coding vulnerability
4 sources 4 reports 71d ago

Adobe Acrobat Integration in WhatsApp Web Exposes User Data Through Chrome Extension Vulnerability

Adobe Acrobat tools are now available within WhatsApp Web and Windows app, allowing users to handle PDFs easily. However, a critical vulnerability in the Adobe Acrobat Chrome extension, affecting 329 million users, could enable unauthorized access to WhatsApp Web chats. The flaw has been patched, ensuring data security moving forward.

security whatsapp adobe acrfat pdf
4 sources 5 reports 73d ago

Researcher Releases Windows Zero-Day Exploit 'LegacyHive' Post-Patch Tuesday

Security researcher Chaotic Eclipse released a zero-day exploit for Windows shortly after Microsoft's Patch Tuesday. The exploit, called LegacyHive, targets the Windows User Profile Service and allows privilege escalation on all supported Windows versions. This revelation underscores ongoing security challenges and may necessitate urgent updates from Microsoft.

security windows vulnerabilities exploit vulnerability
4 sources 4 reports 78d ago

US Charges Russians for Operating 'Bulletproof' Hosting Services Linked to $62M in Cybercrime Losses

U.S. prosecutors have unsealed charges against three Russian nationals linked to bulletproof hosting providers Media Land and ML.Cloud. The Russians allegedly supported ransomware attacks through these services, causing over $62 million in damages. A $10 million reward is offered for information leading to their arrests.

security cybercrime indictment law enforcement ransomware
4 sources 4 reports 79d ago

Microsoft Removes Ads from Windows 11 Search Box for Cleaner Experience

Microsoft is testing a refined Windows 11 Search Box through the Windows Insider program, featuring a decluttered interface and the removal of advertisements in web searches. These changes aim to enhance user experience by prioritizing recent searches and presenting relevant local content without promotional clutter, addressing user feedback.

releases windows search microsoft ui
4 sources 4 reports 84d ago

Microsoft Patches Windows Defender 'RoguePlanet' Vulnerability CVE-2026-50656

Microsoft has patched the 'RoguePlanet' vulnerability (CVE-2026-50656) affecting Windows Defender on Windows 10 and 11, which allowed SYSTEM privileges escalation. The vulnerability was disclosed by researcher Nightmare Eclipse, and a month later Microsoft released the patch in Malware Protection Engine update version 1.1.26060.3008. The flaw's potential use in privilege escalation makes its resolution important for system security.

security windows vulnerabilities microsoft defender
4 sources 5 reports 87d ago

Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices

Google, the FBI, Lumen, and others disrupted the NetNut residential proxy network involving over 2 million devices used for malicious activities. The operation disabled command-and-control features, protecting home devices from being exploited. This action significantly reduces cybercriminals' ability to mask their activities using residential IPs.

security google proxy malware cybercrime
3 sources 3 reports 2d ago

New Spectre v2 Variant (BTR) Affects Intel, AMD, Arm CPUs, Leaks Sensitive Data

Researchers from VUSec and Scuola Superiore Sant'Anna have discovered a new Spectre v2 variant, named Branch Target Reuse (BTR), impacting Intel, AMD, and Arm CPUs. This vulnerability exploits how processors handle code that changes at runtime, specifically targeting just-in-time (JIT) compilers in web browsers, language runtimes, and operating system kernels. BTR can lead to sensitive data leaks, such as root password hashes from Intel Linux systems, and fixes for CVE-2026-64507 and CVE-2026-64508 have been merged into the Linux kernel.

security spectre cpu vulnerability linux
3 sources 5 reports 3d ago

Claude Opus 5.5 Released, Offering Improved Performance and Reduced Cost

Claude Opus 5.5, the first model in the Claude 5.5 family, has been released, performing at the level of Claude Fable 5.1 on most tasks while costing 40% less than Opus 5. This new model demonstrates significant performance improvements in complex tasks like code migration and software optimization, alongside enhanced safety features.

ai llm claude model release microsoft
3 sources 3 reports 3d ago

Former US Soldier Sentenced to 70 Months for Extorting Tech and Telecom Firms

A former U.S. Army soldier received a 70-month prison sentence for hacking and extorting at least 10 U.S. technology and telecommunications companies. He and accomplices stole login credentials, extorted companies for over $1 million, and sold stolen data, impacting sensitive customer records and leading to SIM-swapping fraud.

security cybercrime extortion hacking telecom
3 sources 3 reports 4d ago

Cloudflare remediates cross-tenant data exposure vulnerability in Containers

Cloudflare fixed a vulnerability in its Containers and Sandboxes services that could have exposed residual disk blocks from other tenants. A security researcher reported the issue, which allowed Workers Paid account users to potentially recover data from previously used storage blocks on the same host. Cloudflare found no evidence of malicious exploitation and applied a fix across its Container fleet.

security cloudflare vulnerability containers cloud
1 source 1 report 1d ago Updated 1d ago

Microsoft enables Windows settings backup by default for Entra-joined organizations

Microsoft has enabled Windows settings backup and restore by default for all Microsoft Entra-joined or hybrid-joined enterprise systems upgrading to Windows 11 26H2. This change ensures that user settings are backed up automatically, simplifying device recovery, replacement, or upgrades for organizations.

releases windows microsoft backup enterprise
3 sources 4 reports 6d ago

ShinyHunters Breaches Clop Ransomware Leak Site, Claims Data and Private Key Theft

The ShinyHunters extortion group breached the Clop ransomware operation's data leak site, defacing it and claiming to have stolen server data and the private keys for its onion service. This incident highlights the ongoing conflict between different cybercriminal groups and could impact Clop's future operations if the claims of private key theft are verified.

security cybersecurity ransomware data breach tor
3 sources 3 reports 7d ago

Rydox Cybercriminal Marketplace Operator Pleads Guilty After Brother's Deportation

Ardit Kutleshi, an operator of the Rydox cybercriminal marketplace, pleaded guilty to aggravated identity theft and money laundering charges. This development follows the deportation of his brother, who was also involved in running the illicit platform that facilitated the sale of stolen personal information and fraud tools.

security cybercrime identity theft money laundering law enforcement
3 sources 3 reports 8d ago

Ryuk Ransomware Member Sentenced to 24 Months in Prison for Hacking US Companies

Karen Serobovich Vardanyan, a member of the Ryuk ransomware group, received a 24-month prison sentence for hacking US companies and deploying ransomware. Vardanyan specialized in gaining initial access to corporate networks, contributing to attacks that extorted over $15 million in Bitcoin from victims.

security ransomware cybercrime sentencing ryuk
3 sources 10 reports 9d ago

Nightmare Eclipse Releases 'HardBreacher' Exploit for Kaspersky Endpoint Security

Security researcher Nightmare Eclipse released a proof-of-concept exploit, dubbed "HardBreacher," targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. Kaspersky stated that the underlying issue has been resolved via an automatic update, or users can trigger a database update manually. This exploit highlights ongoing concerns about endpoint security product vulnerabilities and the impact of public zero-day disclosures.

security vulnerability exploit kaspersky crowdstrike
3 sources 4 reports 10d ago

WordPress Patches Click2Shell Vulnerability Allowing Forced Theme Installs

WordPress released patches for a vulnerability, dubbed Click2Shell by pwn.ai, that allows a logged-in administrator to install a theme from the official directory via a crafted web link. This flaw can be chained with a separate theme vulnerability to achieve remote code execution on the server.

security wordpress vulnerability patch csrf
3 sources 3 reports 10d ago

Fake GitHub Repositories Distribute Rapuncel Infostealer and Kernel Driver

A malware campaign uses SEO-optimized GitHub repositories impersonating legitimate companies to distribute a new infostealer called Rapuncel and a Microsoft-signed kernel driver. The kernel driver, Alinubx.sys, disables 145 antivirus and EDR products, allowing Rapuncel to steal credentials and cryptocurrency wallet data.

security malware infostealer github kernel-driver
3 sources 3 reports 10d ago

New RatHat Android Malware Uses AI for Automated Device Control

A new Android malware named RatHat has been discovered, utilizing an AI-powered subsystem to automate remote navigation and control of compromised devices. This AI integration allows the malware to adapt its operations without constant real-time operator interaction, making it more sophisticated than previous Android malware families.

security android malware ai mobile-security
3 sources 3 reports 13d ago

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Gyazo, an image-sharing service, experienced a security breach that exposed approximately 23.62 million user records, including email addresses and password hashes, along with 490 million image metadata records. This incident is significant because it compromises user privacy and security, potentially allowing unauthorized access to images and other services if users reused passwords.

security data breach gyazo image sharing cybersecurity
3 sources 3 reports 14d ago

U.S. Seizes NightmareStresser Domains, Disrupting DDoS-for-Hire Service

The U.S. Department of Justice (DoJ) and FBI, in coordination with international law enforcement, seized the internet domains nightmare-stresser[.]com and nightmarestresser[.]org, associated with the distributed denial-of-service (DDoS)-for-hire service NightmareStresser. This action, part of Operation PowerOFF, disrupts a platform used to launch hundreds of thousands of DDoS attacks globally since 2022, impacting various sectors including education, government, and gaming.

security ddos cybercrime law enforcement fbi
3 sources 3 reports 18d ago

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group, UNC3569, exploited a vulnerability in Sogou Input Method for Windows to install the GRAYRABBIT backdoor on victim computers. The flaw allowed attackers to execute arbitrary commands, impacting users primarily in East and Southeast Asia.

security sogou unc3569 grayrabbit vulnerability
3 sources 15 reports 18d ago

GitLab RCE PoC Published for Authenticated Users on Unpatched Servers

A security researcher published a proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab servers, allowing authenticated users to run commands as git. This vulnerability affects multiple GitLab Community Edition and Enterprise Edition versions and requires self-managed operators to upgrade to patched releases.

security gitlab rce vulnerability gitea
3 sources 3 reports 21d ago

Conti Ransomware Member Sentenced to Four Years in Prison for Wire Fraud Conspiracy

A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, received a four-year prison sentence for his involvement in Conti ransomware attacks between 2021 and 2022. This sentencing highlights ongoing law enforcement efforts against cybercrime groups and their members.

security ransomware cybercrime conti sentencing
3 sources 3 reports 24d ago

Attackers Exploit MikroTik Routers via Internet-Exposed SSH for Unauthorized Access

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication, according to CERT Polska. MikroTik has released security updates for RouterOS to address these vulnerabilities, and users are advised to install them immediately.

security routeros mikrotik vulnerability vulnerabilities
3 sources 3 reports 30d ago

China-Linked Fire Ant Group Compromises Cisco Routers to Steal Credentials and Blind Logs

The China-nexus cyber espionage group Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. This allows the group to capture network traffic, steal credentials, and disable security logging, providing a vantage point into high-value networks, including critical infrastructure.

security cybersecurity espionage cisco router
3 sources 4 reports 31d ago

Venezuelan National Sentenced to 8 Years for ATM Jackpotting Scheme

A Venezuelan national received an 8-year federal prison sentence for his involvement in an ATM jackpotting scheme that resulted in over $3.5 million in losses. This sentence is reportedly the longest federal term for an individual's role in ATM jackpotting, highlighting ongoing efforts to combat this type of financial crime.

security cybercrime atm jackpotting sentencing atm
3 sources 6 reports 36d ago

Microsoft Investigates August Windows Updates Causing Gaming Issues on Windows 11

Microsoft is investigating reports that the August 2026 Windows updates (KB5121003) are preventing some games from launching or causing crashes on Windows 11, versions 25H2 and 24H2. This issue affects titles like ARC Raiders and MARVEL Tōkon: Fighting Souls, leading to freezes, unexpected closures, and errors for affected users.

releases windows gaming updates bugs
More stories →