From BleepingComputer · 40 stories
Microsoft Teams and Outlook Fail to Launch on ARM-based Windows PCs After August 2026 Updates
Microsoft is addressing an issue where Teams and New Outlook fail to launch or crash on ARM-based Windows 11 24H2 devices following August 2026 security updates. This problem primarily affects new or freshly imaged PCs that have not yet installed Microsoft Store updates, and a temporary workaround involves updating the Auto Super Resolution Package.
New Android Malware Mantax Otax Combines Ransomware and Spyware Capabilities
A new Android malware, Mantax Otax, encrypts files, steals data, and harasses victims, combining ransomware and spyware functions. This malware targets older Android versions (9 and below) and is distributed via malicious APKs outside Google Play, posing a threat to users who install apps from unofficial sources.
Skullcandy Dime 3 Earbuds Vulnerable to Bluetooth Hijacking Due to Unpatchable Firmware
The CERT Coordination Center (CERT/CC) reported that Skullcandy Dime 3 wireless earbuds with firmware version 1.0.0.28 are susceptible to a high-severity Bluetooth hijacking vulnerability (CVE-2025-20701). This flaw allows nearby unpaired devices to connect without user interaction, and affected users cannot update their earbuds to a patched firmware version.
Microsoft introduces new Windows Age APIs for age-appropriate app experiences
Microsoft is adding new Age APIs to Windows 11 that allow applications to determine a user's age range (e.g., under 10, 10-12, 18+) without exposing their exact date of birth. This feature enables apps to automatically adjust content and safeguards for different age groups, particularly for AI experiences, and integrates with Microsoft Age Verification for a single verification process.
DoppelCart Fraud Network Uses 119,000 Fake Shops to Steal Credit Card Data
A network named "DoppelCart" operates over 119,000 fake e-commerce sites to steal payment card details from shoppers. The sites impersonate legitimate brands and offer large discounts to lure victims, transmitting collected data in real time to command-and-control servers.
August 2026 Windows Server 2016 Update Causes 0xc0000409 Errors
Microsoft's August 2026 security update for Windows Server 2016 is causing 0xc0000409 errors and CompatTelRunner.exe crashes on systems with the Compatibility Appraiser diagnostic service enabled. This issue affects both physical and virtual machines, but Microsoft states it does not impact device functionality and a fix is in development.
Microsoft warns of app crashes on Windows Server 2025 due to memory management changes
Microsoft has issued a warning about application crashes on Windows Server 2025, stemming from recent memory management changes affecting apps that use Address Windowing Extensions (AWE). This issue primarily impacts applications like SQL Server when configured with the Lock Pages in Memory (LPIM) policy, potentially leading to access violations, memory corruption, or unexpected termination. A temporary workaround involves disabling the LPIM policy for SQL Server, though this may affect performance.
French Hospital Fined €500,000 for Data Breach Exposing 727,000 Records
France's data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a data breach exposed sensitive information of 727,000 patients and third parties. The fine was issued due to the hospital's failure to comply with GDPR obligations, including inadequate access controls and lack of real-time monitoring.
Microsoft Defender for Office 365 flags legitimate Google search links as malicious
Microsoft is investigating an issue where Defender for Office 365's Safe Links feature incorrectly flags legitimate Google search links as malicious, preventing users from accessing them. This issue impacts users attempting to open blocked hyperlinks and causes alerts for IT administrators, stemming from an inaccurate security classification.
Novocure data breach exposes information of over 1,400 cancer patients and employees
Healthtech company Novocure reported a data breach in mid-August that exposed ID numbers for over 1,400 U.S. cancer patients and identifying information for fewer than 50 other patients. The incident also compromised contact details for an undisclosed number of employees, highlighting ongoing cybersecurity challenges in the healthcare sector.
Nigerian Men Extradited to US on Sextortion Charges Linked to Teen Deaths
Two Nigerian men, Adebola Festus Adekunle and Mudasiru Afeez Olawale, were extradited to the U.S. and charged with involvement in sextortion schemes that led to the deaths of two minors. This action is part of an international law enforcement effort, "Operation Artemis," targeting sextortion rings preying on U.S. minors.
Microsoft resolves Windows Defender crashing bug after recent security update
Microsoft has fixed a bug causing Windows Defender to crash with 0xc0000005 access violation errors following a recent security update. This resolution is important as the crashes prevented the security software from functioning, leaving systems vulnerable.
ShinyHunters group leaks Carhartt data affecting 12.9 million accounts after failed ransom
The ShinyHunters extortion group published sensitive data from nearly 13 million Carhartt accounts after the company refused to pay a $3.3 million ransom. The breach, linked to Carhartt's Databricks analytics platform, exposed email addresses, names, phone numbers, and physical addresses of customers and employees. This incident highlights the ongoing threat of data extortion and the importance of securing cloud-based data platforms.
Snowflake to deprecate password-based authentication for service accounts by October 2026
Snowflake is deprecating password-based authentication for legacy service accounts, migrating them to a new SERVICE type that does not store passwords. This change, prompted by a security incident involving compromised credentials, aims to improve security by eliminating long-standing identity vulnerabilities.
Microsoft tests new privacy controls for Windows 11 desktop apps
Microsoft is testing new privacy controls in Windows 11 Insider Preview Build 26340.9233, allowing users to manage camera, microphone, and location access for individual desktop applications. This update provides granular control over app permissions, addressing concerns about applications accessing sensitive resources without explicit user consent.
Microsoft Teams Admins Can Now Block External Bots from Meetings
Microsoft Teams is rolling out a new policy that allows administrators to automatically block external bots from joining meetings. This update enhances meeting security by preventing unauthorized third-party bots and malicious applications from accessing Teams meetings, addressing a rise in Teams-based social engineering attacks.
South Korean Startup Platform Breach Exposes Encryption Key Management Failure
South Korea's government-backed startup platform, Modu-ui Changup, experienced a data breach in July that exposed personal information and startup ideas of approximately 5,000 applicants. The incident was caused by an encryption key being exposed through an API, allowing encrypted data to be decrypted and accessed by external parties.
Microsoft August .NET Framework Updates Break Printing and PDF Export in WPF Apps
Microsoft's August 2026 .NET Framework updates are causing printing and PDF export failures in applications built with the Windows Presentation Foundation (WPF) UI framework. This issue affects various Windows client and server versions, prompting Microsoft to provide a temporary workaround that disables security protections.
Over 9,300 Leaked AWS Keys Remain Active, Granting Full Corporate Account Control
Truffle Security identified over 9,300 publicly exposed Amazon Web Services (AWS) access keys that are still active and valid, with 817 linked to companies and 242 granting administrator access. This exposure allows full control over affected AWS accounts, posing significant data and infrastructure security risks. The findings highlight widespread issues with key rotation and security practices among AWS users.
Sakura Internet discloses data breach affecting up to 1.36 million accounts
Japanese cloud provider Sakura Internet reported that hackers accessed its sales management system, potentially exposing data for up to 1.36 million customer accounts. This incident follows a separate, less severe breach and impacts a strategic provider for Japan's Government Cloud program.
Microsoft 365 search outage affects Outlook, SharePoint Online, and OneDrive users
Microsoft confirmed an outage affecting search functionality in Microsoft 365 applications, including Outlook, SharePoint Online, and OneDrive. The issue stemmed from a recent deployment that caused resource utilization problems, impacting some users attempting to search for content.
Microsoft removes WMIC tool from Windows 11 24H2 and 25H2 to enhance security
Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2, and beta builds. This removal aims to improve operating system security by eliminating a tool frequently abused by malware and threat actors.
Windows Server 2022 Mainstream Support Ends October 2026, Microsoft Advises Upgrade to 2025
Microsoft announced that Windows Server 2022 will reach its mainstream end of support on October 13, 2026, transitioning to extended support until October 2031. The company recommends administrators upgrade to Windows Server 2025, which is now generally available, to maintain full mainstream support.
Ukraine Shuts Down 94 Fraudulent Call Centers, Seizes Millions in Cash and Assets
Ukrainian authorities, in collaboration with German police, shut down 94 fraudulent call centers that engaged in investment scams and attempted to gain access to bank accounts. This operation led to the seizure of millions in cash, computer equipment, and the identification of 26 suspects, significantly disrupting a widespread cybercrime network.
Akira Ransomware Affiliate Bypasses EDR by Booting into Safe Mode, Steals Data
An Akira ransomware affiliate disabled endpoint detection and response (EDR) by restarting a compromised system into Safe Mode with Networking, allowing data exfiltration. Although the ransomware payload failed to execute due to low virtual memory, the attackers successfully stole credentials and files. This incident highlights a known tactic, previously seen with other ransomware families, now observed in an Akira attack.
Signal Introduces Automatic Key Verification to Prevent Man-in-the-Middle Attacks
Signal has launched Automatic Key Verification, a new security feature that uses third-party auditors Cloudflare and Trail of Bits to verify the integrity of encrypted chats. This system ensures the consistency of public encryption keys, protecting against scenarios where a key might be swapped without the user's knowledge.
Chrome's anti-abuse systems blocked 7 billion unwanted Android notifications daily in Q1 2026
Google's Chrome browser for Android blocked over 7 billion unwanted notifications per day in Q1 2026 through new anti-abuse systems. These measures combat the use of notifications for scams, malware, and phishing, improving user security and device performance.
Wesco confirms cybersecurity incident after ExfilSquad claims data theft from cloud CRM
Wesco, a global supply chain and distribution company, confirmed it is investigating a cybersecurity incident involving its cloud CRM environment after the ExfilSquad data extortion group claimed to have stolen 2.6 million records and published them. Wesco states it found no evidence of ransomware or malicious software and believes sensitive customer or employee data is not at risk, despite the group's claims of PII exfiltration.
LexisNexis takes Diligence, Metabase API, and Newsdesk services offline due to suspicious activity
LexisNexis disconnected its Diligence, Metabase API, and Newsdesk services after detecting unusual activity on servers managed by a third-party vendor. The company is investigating the incident with a cybersecurity forensic firm and rebuilding systems in a new environment before restoring services. This incident impacts users of LexisNexis's risk research, data feed, and media monitoring platforms.
Google Blogger locks hundreds of legitimate blogs due to malware false positive
Google's automated systems incorrectly flagged and locked hundreds of legitimate Blogger websites for violating its "Malware and Similar Malicious Content" policy, with some sites subsequently deleted. This incident has prevented blog owners from accessing their dashboards and managing their content, causing widespread frustration among users.
TP-Link Patches 15 Omada ZTP Vulnerabilities Allowing Network Breaches
TP-Link has released patches for 15 vulnerabilities found in the zero-touch provisioning (ZTP) mechanism of its Omada network devices. These flaws, when chained with previously disclosed command-injection vulnerabilities, could enable remote code execution and allow attackers to infiltrate networks. The vulnerabilities affect TP-Link's business networking product line, Omada, which is used by small to medium-sized businesses and enterprises.
New XCSSET v40 malware targets macOS developers via compromised Xcode projects
A new version of the XCSSET malware, v40, is infecting macOS users by injecting downloader scripts into Xcode projects within vulnerable GitHub repositories. This updated variant includes enhanced evasion techniques and new modules for Chrome hijacking and Telegram trojanizing, allowing for credential theft, data exfiltration, and cryptocurrency manipulation.
Varonis Introduces Agent IBAC for AI Agent Security in Atlas Platform
Varonis has launched Agent Intent-Based Access Control (IBAC) within its Atlas platform, designed to prevent AI agents from performing unauthorized or out-of-policy actions when accessing enterprise data. This new capability addresses the security risks associated with AI agents needing broad data access by enforcing permissions at runtime and responding to deviations in real time.
Google Chrome to Block New Tab and Search Engine Hijacking by Policy-Installed Extensions
Google is implementing a new security feature in Chrome that will block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged consumer devices. This change addresses malware abuse that uses enterprise policy features to force-install malicious extensions, improving user control and browser security.
ESET H1 2026 Threat Report details rise in malicious AI skills and adaptable malware
ESET's H1 2026 Threat Report indicates a growing trend of attackers using AI to enhance efficiency and scalability, identifying tens of thousands of suspicious AI skills and the first Android malware, PromptSpy, leveraging generative AI. This development signifies an expanding attack surface and increased flexibility in future threats, alongside continued growth in social engineering tactics like QR code phishing and ransomware activity.
South Korea fines KT Corporation $39 million for 11-month data breach
South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation $39 million for data protection violations stemming from an 11-month internal network compromise. The breach exposed personal information of 16,647 subscribers and led to fraudulent mobile payments, highlighting significant security inadequacies in KT's network management.
Health-ISAC warns healthcare sector of increased ShinyHunters data theft attacks
Health-ISAC has issued a warning to healthcare and medical technology organizations about a rise in successful data theft attacks by the ShinyHunters extortion gang. ShinyHunters primarily uses supply chain and identity attacks, often involving social engineering, to breach cloud SaaS and storage platforms, leading to data exfiltration and extortion. This increase in attacks highlights the ongoing vulnerability of healthcare data to sophisticated cybercriminal groups.
CubePilot drone software developer suffers DNS hijacking attack, user credentials potentially exposed
CubePilot, an Australian firm developing flight controllers for drones, experienced a DNS hijacking attack on July 24, allowing an attacker to intercept traffic and obtain TLS certificates for its subdomains. This incident potentially exposed user credentials entered on CubePilot services and led to the company taking several services offline for investigation.
ShinyHunters data leaks exploited in $2,000 Bitcoin sextortion email scam
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters group to send sextortion emails demanding $2,000 in Bitcoin. These emails falsely claim to be from ShinyHunters and allege device compromise, leveraging previously leaked data to appear legitimate.
OnTrac notifies customers of data breach after network hack
OnTrac, a parcel delivery company, experienced a data breach between March 20 and 22, 2024, where hackers accessed its corporate network and potentially customer personal details. The company is offering 12 months of free credit monitoring and identity protection to affected customers.