From BleepingComputer · 40 stories
Dutch Police Probe Local Hackers in Odido Telecom Data Breach
The Dutch police are investigating local hackers in the February Odido data breach affecting 6.2 million customers. A suspect impersonated an Odido IT employee, facilitating unauthorized access through a customer contact system. Authorities are requesting public assistance to identify the caller.
AI Agents Expose Gaps in Enterprise Identity Governance Systems
AI agents are increasing machine identities in enterprises, highlighting gaps in identity governance. Traditional identity access management (IAM) systems were not designed for autonomous AI, often causing security risks due to over-privileged access. Addressing this issue is critical for secure enterprise operations.
Mount Royal University Hit by Ransomware Attack, Data Stolen and Deleted
Mount Royal University in Calgary experienced a ransomware attack that led to the theft and deletion of student and employee data from its 'H drive' file storage systems. The CMD Organization, the group responsible for the attack, demanded a $1.9 million ransom for over 10 terabytes of data. This incident, impacting various university systems, emphasizes the ongoing risk of ransomware threats in the education sector.
AssuranceAmerica Data Breach Exposes 6.9 Million Driver Records
AssuranceAmerica has suffered a data breach affecting 6.9 million individuals' driver’s license information, names, and contact details. Discovered on March 17, the breach is the largest known exposure of U.S. driver's license data this year, significantly impacting personal data security and prompting potential fraud concerns.
Suspected China-Linked Hackers Target Roundcube Vulnerabilities in U.S. and Canadian Universities
A China-linked threat group named UNK_MassTraction has exploited a critical Roundcube webmail vulnerability to infiltrate physics and engineering departments in U.S. and Canadian universities, stealing credentials and deploying malware. The targeted campaign, identified by Proofpoint, has significant implications for national security and academic research.
Accenture Confirms Data Breach as Hacker Offers Source Code for Sale
Accenture has confirmed a data breach involving the theft of 35 GB of sensitive data, including source code and Azure credentials. A hacker is offering the data for sale, raising concerns about potential future exploitation. Accenture stated there is no impact on their operations and they have addressed the breach's source.
Ubiquiti Releases Critical Security Patch Updates for UniFi OS Suite
Ubiquiti has issued patches for seven critical vulnerabilities in its UniFi OS software suite, affecting applications like UniFi Connect, Talk, Access, and Protect. These security flaws, including CVE-2026-50746, allow command injection and privilege escalation attacks. Users are strongly advised to update their systems to secure versions to mitigate potential breaches.
Spanish Police Arrest Suspected Member of Pro-Russian Hacktivist Groups
Spanish authorities arrested a man in Palencia linked to pro-Russian hacktivist groups CARR and Z-Pentest following an FBI tip. The suspect is accused of aiding a hacker's escape and supporting cyber activities against Ukraine. The arrest could impact international investigations into cyber threats.
Microsoft Tests Cloud Rebuild for Remote Windows 11 Recovery
Microsoft is testing Cloud Rebuild for Windows 11, allowing remote OS reinstalls from the cloud. This feature, in Insider Preview, provides a clean reinstall, handling device drivers and updates automatically without USB media, even if the OS won't boot. It enhances recovery options beyond 'Reset this PC', crucial for fixing persistent system issues.
Cordyceps Vulnerability Exposes Over 300 GitHub Repositories to Supply-Chain Attacks
Researchers from Novee Security have identified a CI/CD vulnerability, named Cordyceps, affecting over 300 GitHub repositories. This issue allows unauthenticated users to execute harmful code, potentially impacting major organizations like Microsoft, Google, Apache, and Cloudflare. The flaw, due to weak CI/CD configurations, raises significant supply chain security concerns.
BeyondTrust Patches Critical Vulnerabilities in Remote Support Products
BeyondTrust has patched critical vulnerabilities in its Remote Support and Privileged Remote Access software. These flaws, identified as CVE-2026-40138 and CVE-2026-40139, could allow unauthenticated attackers to bypass authentication controls and gain unauthorized access, risking elevated privilege accounts. The company urges users to apply the patches promptly.
DHS Investigates Cyber Breach on Homeland Security Information Network
The Department of Homeland Security is investigating a recent cyberattack on the Homeland Security Information Network (HSIN). The breach, suspected to occur between late May and early June, affected both HSIN servers and a SharePoint system, key for information sharing among government entities. The attack raises concerns over national security and vulnerabilities in government cybersecurity infrastructure.
Cisco Acknowledges Exploitation of Unified CM Vulnerability CVE-2026-20230
Cisco has confirmed active exploitation of a critical vulnerability (CVE-2026-20230) in its Unified Communications Manager (Unified CM). This flaw, found in systems with the WebDialer service enabled, allows attackers to execute server-side request forgery attacks and potentially gain root access. Cisco urges users to upgrade to patched versions immediately.
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized PoC Exploits
ChocoPoC, a Python-based remote access trojan, is being distributed through trojanized proof-of-concept (PoC) exploit repositories on GitHub. The malware targets cybersecurity researchers by installing malicious dependencies from PyPI, enabling attackers to execute commands and steal sensitive data. This highlights security risks associated with using unofficial PoCs in vulnerability research.
Password Spray Attack Targets Microsoft Azure CLI, Compromising 78 Accounts
An automated password spray attack on Microsoft's Azure CLI attempted over 81 million logins, affecting 78 accounts across 64 organizations. The attackers exploited a deprecated OAuth flow, bypassing security measures like Conditional Access policies and multi-factor authentication (MFA). This incident underscores vulnerabilities in prevalent security configurations within cloud environments.
Microsoft to Block Entra ID Script Injection Attacks Starting October
Microsoft will begin enforcing Content Security Policy (CSP) defenses in Entra ID starting mid-October 2026 to block external script injection attacks. This measure aims to protect users from cross-site scripting (XSS) by allowing only trusted Microsoft CDN scripts during sign-ins. The change is part of Microsoft's Secure Future Initiative to enhance security.
Zero Trust Architectures Vulnerable to Day-One Human Error and Fraudulent Identities
Zero Trust architectures face vulnerabilities from human error during onboarding and service desk processes, particularly when establishing initial trust for new users. Attackers exploit these gaps by using fraudulent identities to gain access to corporate networks, bypassing subsequent security controls. Organizations must implement robust identity verification during hiring and throughout employment to counter these threats.
Microsoft releases WSL Containers for running Linux containers on Windows
Microsoft has made WSL Containers generally available, allowing users to run Linux containers directly on Windows via the Windows Subsystem for Linux. This update introduces a new command-line tool and an API, enabling programmatic interaction with containers and offering performance improvements for accessing Windows files from Linux environments.
Comcast Activates Wi-Fi Motion Sensing on Xfinity Routers for Home Activity Monitoring
Comcast has launched Xfinity Shield, a new home security platform that includes Wi-Fi Motion, a feature enabling compatible Xfinity routers to detect movement by analyzing disruptions in Wi-Fi signals. This update, available through the Xfinity Internet app, allows customers to monitor home activity without additional hardware, providing an added layer of awareness for Xfinity Internet users.
Signal completes encrypted local backup rollout across all platforms with version 8.30
Signal released version 8.30, completing the rollout of encrypted local backup support across all its supported operating systems, including iOS and desktop. This update allows users to create end-to-end encrypted backups of chats and restore them, standardizing the backup format and improving media handling.
Vietnamese National Charged in $16 Million 'Pig Butchering' Crypto Scam
A Vietnamese national was charged with money laundering for his role in a "pig butchering" cryptocurrency scam that defrauded one victim of $16 million. The defendant's crypto wallets received over $53 million from wire fraud schemes, with at least $24 million linked to known pig butchering operations.
Japan's Keio Corporation confirms ransomware attack on business systems
Keio Corporation, a major Japanese railway operator, experienced a ransomware attack over the weekend that disrupted some of its business systems, primarily affecting its hospitality division. The company is investigating the extent of the impact and whether customer or business partner information was accessed. This incident highlights ongoing cybersecurity threats to critical infrastructure and large corporations.
Times Car confirms data breach impacting 6.6 million user accounts
Japanese car-sharing service Times Car confirmed a cyberattack compromised approximately 6.6 million user accounts, including personal details and driver's license information. The breach affects current and former members of Times Car and Times Business Service, prompting the company to advise caution regarding phishing attempts.
Infostealer Logs Pose Evolving Operational Security Challenge for Organizations
Infostealer logs, containing compromised corporate credentials and session cookies, are increasingly challenging organizational security teams. These logs often originate from unmanaged personal devices, complicating incident response beyond simple password resets. The growing volume of these exposures necessitates advanced strategies for identifying active threats amidst numerous stale credentials.
Identity Verification Flaws in Onboarding and Account Recovery Pose Growing Security Risk
Organizations face increasing security risks from vulnerabilities in identity verification during new employee onboarding and account recovery processes, even with strong authentication methods like MFA. Attackers exploit these weaknesses through social engineering to gain unauthorized access, as seen with North Korean IT worker impersonations and groups like Scattered Spider.
Fake Remote Workers Exploit Hiring Processes to Infiltrate Corporate Networks
Security teams face a growing threat from fraudulent remote workers who exploit hiring processes to gain legitimate access to corporate networks. These individuals, sometimes linked to state-sponsored groups like those from North Korea, use various tactics to impersonate legitimate hires and exfiltrate sensitive data or conduct cybercriminal activities. This issue highlights a gap in identity verification during remote hiring, where traditional checks do not confirm the actual user of an account or device.
Browser Security Gap Widens as Enterprise Work and AI Shift to Web Interfaces
Enterprise work increasingly occurs within web browsers, making them a primary target for cyberattacks. Traditional endpoint and network security architectures are insufficient for protecting browser sessions, especially with the rise of AI-assisted hacking and the use of third-party AI models.
Microsoft to deprecate Windows Deployment Services (WDS) in next Windows Server release
Microsoft announced the deprecation of Windows Deployment Services (WDS) starting with the next Windows Server release, with plans for full removal in the future. This change impacts IT administrators who use WDS for remote operating system installations and requires migration to alternative deployment solutions like Microsoft Configuration Manager.
Microsoft confirms desktop loading issues after August 2026 Windows preview updates
Microsoft confirmed that August 2026 preview updates and subsequent updates cause desktop loading issues, including black screens, primarily affecting Azure Virtual Desktop (AVD) hosts using FSLogix. The company provided a temporary manual fix and a Known Issue Rollback (KIR) for enterprise customers to mitigate the problem.
MacSync Malware Uses Public iCloud Calendars for Payload Delivery
A new variant of the MacSync info-stealing malware for macOS now uses public iCloud calendar events to deliver subsequent payloads. This evolution allows the malware to retrieve additional components and a new Objective-C backdoor, enhancing its persistence and data exfiltration capabilities.
FedRAMP VDR and VER Rules Mandate Daily Scans and Stricter Remediation by 2026
FedRAMP's new Vulnerability Detection and Response (VDR) and Verification (VER) rules become mandatory on December 7, 2026, replacing the monthly scan model with more frequent, tiered scanning requirements. These changes introduce tighter remediation deadlines, shift the burden of proof for exploitability, and classify process failures as vulnerabilities, significantly altering engineering work for certified cloud service offerings.
September Windows Updates Break Always On VPN Connections
Microsoft's September 2026 Windows 11 security updates are causing Always On VPN connection issues for users. The problem occurs when VPNs are configured for automatic protocol selection, leading to connections remaining in a 'Connecting' state or failing with an error.
Rogue external MFA providers can steal passwords during Microsoft Entra logins
Security researchers developed TrustSink, an attack that allows hackers with privileged access to register a rogue external MFA provider to steal user passwords during legitimate login attempts. This technique works with external authentication models, demonstrated using Microsoft Entra, and captures plaintext passwords without disrupting the login process.
Sweden fines Miljödata $183,000 for GDPR violations after 2025 data breach
Sweden's data privacy regulator, IMY, fined IT provider Miljödata $183,000 for inadequate security measures that led to a data breach affecting 2.2 million people in August 2025. The company failed to check new software and lacked real-time monitoring, violating GDPR Article 32(1). This fine highlights regulatory enforcement against insufficient cybersecurity practices, especially for providers handling sensitive personal data.
Microsoft Excel KB5002914 Update Breaks Copy/Paste and Formula Dragging for Some Users
Microsoft's KB5002914 security update for Office, released as part of September 2026 Patch Tuesday, is causing copy-and-paste and formula dragging functionality to fail for some Excel users. Affected users report that uninstalling or rolling back the update restores normal functionality, indicating a direct impact on productivity for those relying on these core Excel features.
FBI Releases CJIS Security Policy v6.1 with Stricter Encryption and Vulnerability Scanning
The FBI released version 6.1 of its CJIS Security Policy on June 25, 2026, updating encryption requirements and increasing the frequency of vulnerability scanning. This update refines the control-based structure introduced in v6.0, impacting security teams responsible for Criminal Justice Information (CJI) compliance.
Microsoft urges Entra ID admins to migrate users to passkeys before SMS sign-in retirement
Microsoft has reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, as SMS first-factor sign-in will be retired starting February 2027. This change aims to enhance security by moving away from methods vulnerable to phishing, requiring organizations to adopt stronger authentication protocols for user access.
Microsoft Teams to allow custom blocking of file extensions for security
Microsoft Teams will introduce a feature allowing administrators to customize blocked file extensions within its Weaponizable File Protection. This update, rolling out in November 2026, enables organizations to tailor security policies for file attachments in chats and channels.
Microsoft Investigates, Then Provides Workaround for Windows 11 Domain Trust Issues
Microsoft is investigating reports that the Windows 11 KB5124008 and KB5124012 security updates are breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. The issue is linked to the Machine Identity Isolation security feature being set to enforcement mode after the updates. Microsoft has provided a temporary workaround involving disabling Machine Identity Isolation on affected devices.
September Windows Server Updates Cause Remote Desktop Services Failures
Microsoft's September 2026 cumulative updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025, preventing user connections and sometimes requiring hard resets. Rolling back the updates resolves the issue but removes security fixes, impacting server stability and security.