For you Ai Security Dev Cloud Hardware Startups Releases General

From BleepingComputer · 40 stories

3 sources 3 reports 36d ago

Large DDoS Attack Disrupts Norwegian Government Services for Over a Day

A large-scale distributed denial-of-service (DDoS) attack targeted the infrastructure of Norway's Digitalisation Agency (Digdir), disrupting multiple public services for over 24 hours. This incident highlights the vulnerability of critical government digital infrastructure to cyberattacks and the potential for widespread disruption to citizen services.

security ddos cybersecurity government norway
3 sources 3 reports 37d ago

Global Cybercrime Crackdown Arrests 58, Identifies 263 Suspects in Operation Jackal IV

Law enforcement agencies from 22 countries arrested 58 individuals and identified 263 suspects linked to cybercrime networks, primarily targeting West African groups like Black Axe, during "Operation Jackal IV." This operation disrupted financial fraud schemes, including romance and investment scams, and highlighted the use of Crime-as-a-Service by these syndicates.

security cybercrime law enforcement fraud interpol
3 sources 3 reports 37d ago

Hackers Exploit miniOrange SAML SSO WordPress Plugin Vulnerabilities

Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.

security wordpress vulnerability sso saml
3 sources 4 reports 42d ago

Head Mare Exploits TrueConf Server Flaws to Distribute Backdoored Client Installers

The hacktivist group Head Mare exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace legitimate client installers with malicious versions containing PhantomCore and PhantomGraph backdoors. These attacks, discovered by Kaspersky in July, targeted Russian organizations across various sectors, allowing attackers to gain persistent remote access and exfiltrate data.

security vulnerability malware russia backdoor
3 sources 3 reports 42d ago

Over 14,500 Dahua Devices Compromised via Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers at Hunt.io uncovered "Operation CameraSwarm," which compromised over 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a P2P relay technique. This compromise highlights the ongoing risk posed by unpatched vulnerabilities and weak credentials in IoT devices, particularly in critical infrastructure or surveillance contexts.

security cybersecurity vulnerability iot dahua
3 sources 4 reports 43d ago

New Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs

Researchers have discovered a new attack, named Interrupt Injection or TONTOU, that bypasses existing Spectre v2 mitigations on Intel and AMD CPUs. This vulnerability allows an unprivileged local attacker to leak kernel memory, such as Linux password hashes, by exploiting a timing window during branch predictor neutralization. AMD has released a kernel patch for Linux, while Intel states no mitigation is necessary.

security cpu vulnerability spectre cloudflare
3 sources 3 reports 43d ago

US Charges 17 Iranian Hackers, Offers $10 Million Rewards for Five Individuals

The US has charged 17 members of Iran's Mabna Institute for hacking into hundreds of organizations globally, including universities, companies, and government agencies. This action highlights ongoing cyber espionage efforts attributed to state-sponsored groups and the US government's response to intellectual property theft.

security cybersecurity iran hacking intellectual property
3 sources 5 reports 44d ago

Shell investigates potential data theft after Clop ransomware gang claims 89GB stolen

Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. This incident is linked to the exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM instances, a vulnerability that CISA has confirmed is actively exploited.

security ransomware vulnerability data breach cybersecurity
3 sources 4 reports 45d ago

City-Forum Campaign Targets Salesforce and ServiceNow Guest Users with Custom Tools

A campaign named 'City-Forum' is exploiting guest user access in Salesforce Experience Cloud (Aura and LWR implementations) and ServiceNow customer portals to steal data. The attacks use a custom multi-platform toolset and target telecommunications, banking, financial services, enterprise software vendors, and public-sector portals globally.

security salesforce servicenow vulnerability data breach
3 sources 3 reports 45d ago

French Tax Authority Investigates Data Breach After Hacker Claims 600,000 Victims

France's Directorate General of Public Finances (DGFiP) confirmed a data breach in late June where an attacker accessed and extracted data on individuals and businesses. The incident became public after a hacker claimed responsibility, stating they obtained data on over 600,000 people, including personal and tax identification information.

security cybersecurity data breach government france
3 sources 3 reports 46d ago

New Mirai Variant "Evooo1Bot" Adds Stealth and Proxy Capabilities to Botnet Code

A new Mirai botnet variant, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, according to FortiGuard Labs. This variant includes enhanced stealth features like SSH honeypot detection and a SOCKS proxy function, allowing attackers to conceal their origin and pivot into internal networks. The added capabilities make Evooo1Bot more sophisticated than previous Mirai-derived malware, posing a greater threat to network security.

security mirai botnet malware cybersecurity
3 sources 3 reports 51d ago

Russian Sandworm Hackers Target Ukrainian IT Workers with Malicious VPNs via Fake Job Offers

Russian military intelligence hackers, identified as Sandworm (UAC-0145), are posing as recruiters on Ukrainian job sites to trick IT professionals into installing malicious software. Active since at least May, the campaign aims to compromise systems by having victims download a modified VPN application during a fake recruitment process, allowing for command execution and further payload delivery.

security cybersecurity malware russia ukraine
3 sources 3 reports 58d ago

Adform Ad Platform Compromised to Steal Cryptocurrency via Malicious JavaScript

Online advertising firm Adform experienced a supply-chain attack where its JavaScript tracking script, 'trackpoint-async.js' served from 's2.adform.net', was compromised. The malicious code replaced Bitcoin, Ethereum, or TRON wallet addresses copied to users' clipboards or entered into form fields with attacker-controlled addresses, potentially redirecting cryptocurrency payments. Adform detected the incident on July 27, 2026, removed the code, and notified clients.

security supply-chain cryptocurrency adtech javascript
3 sources 3 reports 59d ago

UK Police and Education Data Breached by ExfilSquad, Ransom Demanded

The UK's Police National Legal Database (PNLD) and Department for Education (DfE) experienced separate data breaches, with the ExfilSquad extortion group claiming responsibility. The PNLD breach exposed contact information for over 100,000 police officers and criminal justice professionals, while the DfE incident involved over 600,000 lines of data from two portals. ExfilSquad is demanding a ransom for the data.

security cybersecurity data breach government extortion
3 sources 3 reports 63d ago

Amazon Attributes Multiple npm Package Hijacks to North Korea's Sapphire Sleet

Amazon Threat Intelligence has attributed the September 2025 hijacks of the npm packages debug and chalk, along with the March 2026 axios compromise and an earlier typo-crypto incident, to North Korea's Sapphire Sleet group. This attribution connects previously separate incidents of crypto theft and package compromise under a single threat actor, highlighting a consistent pattern of social engineering and supply chain attacks affecting widely used JavaScript libraries.

security npm north korea supply chain supply chain attack
3 sources 5 reports 65d ago

Ernst & Young Discloses Data Breach: Client Tax Information Compromised

Ernst & Young experienced a data breach via a third-party support system, compromising clients' personal and financial data. The breach, spanning March 28 to April 12, included sensitive tax information, with notifications sent to affected clients and state regulators. The incident underscores the vulnerabilities associated with third-party IT services.

security data breach ernst & young cybersecurity client data
3 sources 3 reports 66d ago

Fastjson 1.x RCE Vulnerability Actively Exploited, No Patch Available

Attackers are targeting a critical remote code execution (RCE) vulnerability in Alibaba's Fastjson 1.x library, affecting Spring Boot applications. The flaw, CVE-2026-16723, allows unauthenticated code execution and currently has no official patch from Alibaba for the 1.x branch. This impacts organizations using Fastjson 1.x in specific Spring Boot configurations, requiring immediate mitigation or migration to Fastjson2.

security fastjson rce vulnerability java
3 sources 3 reports 66d ago

Apple Sued for $1.8M After Fake Crypto Wallet App Appears on App Store

Three individuals are suing Apple, alleging that a fraudulent Sparrow Wallet application downloaded from the App Store led to the theft of approximately $1.8 million in Bitcoin. The lawsuit, filed on July 24 in California, claims Apple failed to adequately review and monitor applications, despite promoting the App Store as a secure source for software.

security apple app store cryptocurrency lawsuit
3 sources 3 reports 66d ago

Clop Ransomware Exploits PTC Windchill and FlexPLM Vulnerability for Data Theft

The Clop ransomware group is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM to exfiltrate data from targeted companies. This exploitation has led to extortion campaigns and prompted urgent warnings from cybersecurity agencies and authorities.

security ransomware vulnerability data theft ptc
3 sources 3 reports 73d ago

HollowGraph Malware Utilizes Microsoft 365 Calendars for C2 Communications

HollowGraph, a new malware, uses Microsoft 365 calendar events dated to 2050 for command-and-control and data exfiltration. This method disguises traffic as legitimate, targeting Israeli entities and linked to Iranian threat actors.

security malware microsoft365 espionage microsoft
3 sources 3 reports 73d ago

DOJ Seizes Over 1,000 Domains for Illegal World Cup Streaming

The U.S. Department of Justice seized and blocked over 1,000 domains during the World Cup for illegal streaming. This action aims to protect intellectual property and consumers from potential security threats associated with unauthorized streaming sites.

security streaming cybersecurity piracy intellectual property
3 sources 4 reports 73d ago

Critical ServiceNow Flaw Exploited Despite Patch Release

A critical remote code execution vulnerability (CVE-2026-6875) in ServiceNow's AI Platform is being actively exploited, allowing attackers to execute code remotely. Despite the July patches, attacks were observed shortly thereafter. This issue highlights the urgency for self-hosted customers to apply updates promptly to prevent system compromise.

security vulnerabilities patches software servicenow
3 sources 3 reports 73d ago

OpenSSL HollowByte Flaw Exposes Servers to Memory Exhaustion with Minimal Payload

A vulnerability in OpenSSL, known as HollowByte, allows attackers to trigger a denial-of-service condition by sending an 11-byte payload. The flaw causes vulnerable servers to pre-allocate memory for incomplete TLS handshake messages. Fixed versions without official CVEs or advisories include OpenSSL 4.0.1 and others released on June 9. Upgrading is crucial to prevent potential server freezes.

security openssl vulnerability dos
3 sources 3 reports 77d ago

Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions

A vulnerability in Claude for Chrome allows rogue extensions to trigger sensitive tasks without user consent. Discovered by Manifold Security, the flaw enables malicious extensions to access Gmail, Google Docs, Calendar, and Salesforce, posing a significant security risk. This issue persists in version 1.0.80, with no current patch.

security chrome vulnerabilities data exposure cloud
3 sources 3 reports 78d ago

Zoom Patches Critical Vulnerability Allowing Account Takeovers

Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows applications, rated 9.8 on the CVSS scale, which enabled potential account takeovers. The flaw affected Zoom Workplace, Zoom VDI Client, and Zoom Meeting SDK for Windows prior to version 7.0.0. This vulnerability impacts user security and necessitates immediate updates to prevent unauthorized account access.

security zoom vulnerability account takeover windows
3 sources 5 reports 79d ago

Progress Software Confirms Zero-Day Vulnerability in ShareFile Storage Zone Controllers

Progress Software advised ShareFile users to shut down Storage Zone Controllers due to a zero-day vulnerability. The high-severity path traversal flaw, affecting versions 5.x and 6.x, led to precautionary account access suspension and patches release. No customer data compromise has been reported.

security cloud general sharefile software
3 sources 4 reports 79d ago

Microsoft 365 Users Targeted in Voice Phishing Campaign for Fake Entra Passkey Enrollment

A voice phishing campaign is exploiting Microsoft 365 users to unwittingly enroll fake Entra passkeys, giving attackers unauthorized account access and facilitating potential data extortion. Initiated by the group O-UNC-066, the campaign began in April and spans multiple industries, highlighting vulnerabilities in the passkey adoption process Microsoft implemented. Okta reported the attacks, which utilize convincing phishing kits mimicking Microsoft's passkey enrollment portal.

security microsoft phishing cybersecurity passkey
3 sources 3 reports 80d ago

US and Allied Nations Warn of Russian Router-Based Cyberattacks on Critical Infrastructure

US and several allied nations have issued a warning regarding Russian state-backed attempts to exploit poorly secured routers to breach critical infrastructure. The FSB's hacking groups target sectors including energy, healthcare, and communications by using known vulnerabilities and SNMP exploits. The warning underscores the need for immediate security enhancements in affected sectors.

security cybersecurity russia infrastructure attacks
3 sources 3 reports 80d ago

U.S. Sanctions VPN and Malware Providers for Ransomware Support

The U.S. Treasury sanctioned First VPN Service and its administrator for aiding ransomware activities against American infrastructure. Ukrainian Dmytro Rashevskyi, associated with the VPN, and Belarusian Yegeniy Silayev, a cryptor seller, were named in the sanctions. The sanctions prevent U.S. entities from transacting with them, underscoring a broader crackdown on cybercriminal support networks.

security vpn ransomware cybersecurity government
3 sources 3 reports 80d ago

UK and EU Sanction Russia's FSB and GRU for Cyberattacks Involving Critical Infrastructure

The UK and EU have imposed joint cyber sanctions targeting Russia's FSB and GRU following a cyberattack on Poland's energy grid that nearly caused a major blackout last winter. The coordinated sanctions, the first of their kind, address ongoing Russian-led cyber espionage campaigns against EU member states. These actions reflect growing international concerns regarding Russia's capacity to destabilize Europe’s critical infrastructure.

security russia cybersecurity sanctions poland
3 sources 3 reports 83d ago

Critical Gitea Docker Vulnerability CVE-2026-20896 Faces Active Exploitation

Gitea Docker images are subject to a critical authentication bypass vulnerability (CVE-2026-20896) now under active exploitation. The flaw allows attackers to impersonate any user, including administrators, via reverse proxy authentication with default configurations. It affects versions before 1.26.3 and about 6,200 instances globally.

security devops docker vulnerabilities gitea
3 sources 3 reports 84d ago

Microsoft Utilizes AI to Enhance Windows Security Updates Frequency and Efficiency

Microsoft announced the integration of AI to improve the frequency and effectiveness of Windows security updates. Using advanced AI models, Microsoft seeks to accelerate the detection of vulnerabilities in its codebase. This change aims to improve protections against increasingly AI-driven cyber threats.

security microsoft windows ai
3 sources 3 reports 85d ago

12 Million Affected in KDDI Data Breach, Exploiting Zero-Day Vulnerability

KDDI, a major Japanese telecom provider, confirmed a breach affecting 12.2 million email addresses and 7.6 million passwords via a compromised email system used by five ISPs. The breach exploited a zero-day vulnerability in third-party software. KDDI has implemented security measures and coordinated password resets to prevent future incidents.

security cybersecurity data breach kddi japan
3 sources 3 reports 85d ago

DuckDuckGo Browser Now Blocks YouTube Video Ads Using Community Filters

DuckDuckGo has released a feature that blocks video ads, including those on YouTube, on its browser. This feature, based on community-maintained filter lists and additional rules for compatibility, is enabled by default on iOS, Windows, and Mac, with Android support to follow. Users can enjoy ad-free video playback while maintaining privacy, but may experience longer buffering times.

security duckduckgo youtube adblocking browsers
3 sources 3 reports 85d ago

Chinese APT UAT-7810 Develops New Malware to Expand ORB Network

Chinese APT group UAT-7810 has advanced its Operational Relay Box (ORB) network with new malware, including LONGLEASH, DOGLEASH, and JARLEASH. These tools exploit known router vulnerabilities to enhance the group's cyber espionage capabilities, posing potential risks to critical infrastructure.

security malware cybersecurity threat UAT-7810
3 sources 3 reports 87d ago

Medtronic Hack Exposes Data of Nearly 4 Million People in ShinyHunters Breach

Medtronic suffered a data breach in April 2026, compromising the personal and medical information of over 3.8 million individuals, with some sources claiming 9 million records affected. The ShinyHunters group accessed Medtronic's corporate IT systems, despite the company's reassurance about device safety. Medtronic is offering credit monitoring and support services to those impacted, highlighting security vulnerabilities in healthcare technology.

security data breach healthcare cybersecurity shinyhunters
3 sources 3 reports 91d ago

FortiBleed Campaign Compromises Fortinet Devices, Linked to Ransomware Groups

The FortiBleed campaign has been connected to the INC and Lynx ransomware groups, compromising credentials from Fortinet devices. Researchers found the operation entailed scanning 11,250 FortiGate portals and compromised 354 targets, leading to 12 ransomware deployments. The breach highlights significant cybersecurity risks, affecting organizations globally.

security ransomware credential-theft fortinet fortibleed
2 sources 3 reports 65d ago

AI Technology Reduces Vulnerability Exploitation Time, Increasing Security Concerns

The rapid increase in newly reported vulnerabilities, and the use of AI in exploit development, has significantly reduced the time it takes for cyber threats to be operationalised. This has created a larger 'exposure window' between vulnerability discovery and remediation, placing pressure on security teams. With CVEs published at an unprecedented rate, prompt response times are becoming crucial to mitigate potential breaches.

security vulnerabilities CVE pentesting exploitation
1 source 1 report 24d ago

220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak

An Advance Passenger Information System (APIS) database, containing over 220 million passenger and crew records, was publicly accessible due to security misconfigurations. This exposure includes passport numbers and flight details for travelers to, from, or through Vietnam from 2017 to 2026, posing a significant privacy risk for a large number of individuals.

security data breach privacy vietnam
1 source 1 report 36d ago

FBI disrupts proxy network used for Chinese cyber espionage against US critical infrastructure

The FBI has disrupted a proxy network infrastructure that facilitated Chinese cyber espionage operations targeting U.S. critical infrastructure. This infrastructure, tracked by Black Lotus Labs, provided reconnaissance, proxy management, and operational routing capabilities for data theft from various U.S. organizations. The disruption impacts China-linked espionage actors who have increasingly used such networks since 2024.

security cybersecurity fbi china espionage
More stories →