From BleepingComputer · 40 stories
OnTrac notifies customers of data breach after network hack
OnTrac, a parcel delivery company, experienced a data breach between March 20 and 22, 2024, where hackers accessed its corporate network and potentially customer personal details. The company is offering 12 months of free credit monitoring and identity protection to affected customers.
Europol Flags 4,340 URLs for Removal in Crackdown on 'The Com' Extremist Network
Europol identified 4,340 URLs for removal during a multi-week operation in June and July 2026, targeting online content from "The Com," a network of nihilistic violent extremist groups. This action aims to disrupt the online ecosystem of these groups and limit the spread of content promoting self-harm, child sexual exploitation, and violence.
Man sentenced to six years for hacking 750 women's Snapchat accounts and distributing CSAM
An Illinois man received a 76-month prison sentence for hacking over 750 women's Snapchat accounts to steal nude photos, which he then traded or sold online. The investigation also uncovered his distribution of child sexual abuse material (CSAM), leading to charges and a conviction that highlights the severe consequences of cybercrime involving personal data and illicit content.
Microsoft Exchange Online Mailboxes Incorrectly Quarantined Due to Infrastructure Change
Microsoft is addressing an issue that has been incorrectly quarantining Exchange Online mailboxes since Sunday, preventing users from sending and receiving emails and accessing calendars. The problem stems from a recent infrastructure change causing excessive memory consumption and out-of-memory conditions, leading to mailboxes being mistakenly quarantined.
Eclypsium launches InfraTrust report for prioritizing infrastructure vulnerabilities
Eclypsium released InfraTrust and its inaugural Pulse report to help organizations prioritize infrastructure vulnerabilities. The report focuses on exploitability and real-world impact rather than just severity scores, highlighting flaws from key vendors that require urgent attention.
Microsoft to end security updates for Exchange 2016/2019 in October 2026
Microsoft will discontinue security updates for Exchange Server 2016 and 2019 in October 2026, as confirmed in a recent blog post. IT administrators are encouraged to upgrade to Exchange Server Subscription Edition to maintain support and receive future updates.
Microsoft Releases Fixes for WSUS Synchronization Issues
Microsoft addresses synchronization delays in Windows Server Update Services (WSUS) affecting update deployment since July 13, 2026. A manual fix involves database cleanup and configuration changes, while service-side mitigations help new server setups.
Microsoft Fixes Shutdown Issues on Some Dell PCs with Windows Update
Microsoft released KB5121767 and KB5121768 updates to fix shutdown and performance issues on some Dell PCs caused by a driver incompatibility after recent Windows 11 updates. The conflict arose between Intel's driver and the new Windows USB-C Connection Manager. The fix matters for users experiencing device instability and performance degradation.
Incode's Facial Age Estimation Now Processes On-Device, Not Server-Based
Incode Technologies has enhanced its facial age estimation model to operate entirely on users' devices, eliminating the need to transmit or store facial data. This transition comes amid rising concerns over biometric data security and compliance with global age verification laws.
Abbott Laboratories investigates two cybersecurity incidents amid extortion claims
Abbott Laboratories is investigating two cyber incidents involving unauthorized access to its internal systems. The investigations include claims by the ShinyHunters group regarding data breaches linked to its Cancer Diagnostics business and LabCentral portal.
Windows Server 2022 to End Mainstream Support in October 2026
Microsoft will end mainstream support for Windows Server 2022 on October 13, 2026, transitioning to extended support until October 14, 2031. Customers are encouraged to upgrade to Windows Server 2025 for continued support and security updates.
LastPass and Bitwarden users face phishing attacks with fake security alerts
LastPass has warned users of a phishing campaign using fake security alerts to redirect users to malicious websites. Similarly, Bitwarden users have also been targeted with similar phishing tactics, raising concerns over user security.
Nihon Kotsu shuts down systems following cyberattack
Nihon Kotsu, Japan's largest taxi operator, experienced a cyberattack that compromised its systems, including the taxi dispatch service. The disruption affects multiple operations, including booking and internal systems, prompting the company to engage cybersecurity experts for an investigation.
Varonis Launches Entra ID Training Experience 'Breach at the Beach'
Varonis Threat Labs introduced 'Breach at the Beach', a Capture The Flag (CTF) training on Entra ID. This training helps security practitioners understand data exfiltration threats linked to non-human identities amid evolving AI technology.
Bulgarian man charged with stealing seized cryptocurrency from prison
Rossen G. Iossifov faces charges for allegedly stealing $290,000 in seized cryptocurrency while incarcerated. This case underscores ongoing issues in tracking and curbing cryptocurrency-related fraud and the challenges of the enforcement in maintaining control over seized assets.
OpenMandriva Linux faces internal sabotage incident from contributor
OpenMandriva Linux reported an attempted sabotage by a contributor involving deleting GitHub repositories and pushing an empty package that could harm users' systems. The incident followed disputes within the team, leading to a system audit and restoration efforts.
Summer IT Staffing Gaps Create Increased Cybersecurity Risks
Organizations face heightened cybersecurity risks during summer due to reduced IT staffing levels. Cybercriminals capitalize on slower response times, leading to increased vulnerabilities and potential for successful attacks.
Microsoft plans to retire OWA Light client in Exchange Server
Microsoft is set to disable the OWA Light client in an upcoming Exchange Server update. This decision is aimed at reducing legacy components and enhancing focus on modern web email experiences.
Microsoft to enable Windows settings backup by default for enterprise systems
Microsoft will enable the Windows settings backup tool by default for enterprise systems using Windows 11 version 26H2. This change aims to streamline the backup process for IT administrators managing device resets or upgrades.
Vietnam arrests seven suspects behind HiAnime piracy service
Vietnamese authorities arrested seven individuals linked to HiAnime, a major anime piracy service. This follows HiAnime's shutdown in June, where it gained significant traffic and revenue, impacting the legal anime streaming market.
Flipper Zero firmware to rely on community contributions amid team changes
Flipper Devices has announced a shift in firmware development for the Flipper Zero, now depending more on community input and less on its internal team. This change follows the completion of Flipper Zero Firmware 1.0 and the company’s focus on new products, triggering community backlash that the company aims to address through a new collaborative development model.
Claude Fable users report degraded performance and usage restrictions
Claude Fable has been relaunched but early user feedback indicates a drop in performance due to new restrictions. Users have noted increased instances of the model falling back to Opus 4.8 for tasks, particularly those involving sensitive language.
Microsoft resolves bug causing Copilot buttons to disappear in Outlook
Microsoft has fixed a bug that caused Copilot buttons to be missing in Classic Outlook for Windows users. The issue affected users with a Copilot Chat (Basic) license, leading to various UI problems, which the Outlook Team addressed with a service update.
Kubota reveals month-long hacker access to employee data
Kubota North America announced that hackers accessed employee data for over a month this year. The breach exposed sensitive information such as Social Security numbers and bank details, prompting the company to enhance its security measures.
Criminal IP Enhances OpenCTI with Contextual Cyber Threat Intelligence
Criminal IP integrates with OpenCTI to enrich IP addresses, domains, and URLs with intelligence data. This enhancement allows security teams to better investigate, correlate, and prioritize potential cyber threats.
Delta Investigates Fake Wi-Fi Network Incident on Flight from Las Vegas
Delta Air Lines is investigating an incident on Flight 591 from Las Vegas to Atlanta where an unauthorized Wi-Fi network, allegedly created by a passenger, appeared mid-flight. The network, named "Delta WiFi Fast," reportedly spoofed the legitimate in-flight Wi-Fi and may have attempted to phish for credentials, leading pilots to alert air traffic control and temporarily disable the aircraft's Wi-Fi.
Levi Strauss & Co. Reports Corporate Data Exfiltration After Social Engineering Attack
Levi Strauss & Co. disclosed that hackers accessed and exfiltrated corporate information from three employee computers through a social engineering attack. The company stated that the incident did not disrupt business operations and found no evidence of consumer data exposure, but the specific corporate data taken was not disclosed. The company believes the incident will not materially impact its business.
Analog Devices Discloses Data Breach, Files Exfiltrated
Semiconductor company Analog Devices reported a data breach detected on June 23, where an unauthorized party accessed systems and exfiltrated certain files. The company stated that operations were not disrupted and the incident is not expected to materially impact its business, though it is also assessing public reports of a separate cybersecurity matter from July 26.
Kubernetes YAML Misconfiguration Can Lead to Google Cloud Organization Takeover
A misconfigured Kubernetes YAML file, when used with Google Kubernetes Config Connector (KCC), can grant an attacker broad control over an entire Google Cloud organization. This vulnerability arises because KCC's service account often holds extensive permissions to manage infrastructure across multiple projects or the entire organization.
AI Actress Tilly Norwood's "Talking Tilly" Service Requires Face Scan and Emotional Monitoring
The "Talking Tilly" service, which allows users to video call the AI actress Tilly Norwood, now requires a face scan for age verification and continuously monitors user emotions during calls. These requirements, added this month, raise privacy concerns as they cannot be opted out of and rely on "legitimate interests" rather than user consent.
Ransomware Attack Costs Exceed Ransom Payments Due to Downtime and Recovery
The total cost of a ransomware attack averages $5.08 million, significantly higher than the median ransom payment of $139,875. This disparity is primarily due to expenses from downtime, remediation, legal work, and business disruption. A robust business continuity and disaster recovery (BCDR) strategy can mitigate these post-attack costs.
Prophet Security Identifies Session Hijacking as Top Threat in Q2 2026 Threat Report
Prophet Security's Q2 2026 threat report, based on investigations of all customer alerts, found that identity was the target in roughly half of all confirmed malicious activity. Session hijacking, using already-authenticated sessions, was the most successful attack method, bypassing standard security controls that block password-based attempts.
Account Recovery Processes Emerge as a Primary Attack Vector Against MFA
Multi-factor authentication (MFA) has significantly improved account security, but attackers are now targeting account recovery processes as a bypass. This shift means that the service desk, responsible for managing account recovery, has become a critical part of an organization's identity security boundary. The security of an account during recovery depends more on the process itself than on the MFA technology protecting it.
EU Cyber Resilience Act's Vulnerability Reporting Requirements Take Effect September 2026
The EU Cyber Resilience Act (CRA) will require manufacturers selling products with digital elements into the EU to report actively exploited vulnerabilities within 24 hours of discovery, starting September 11, 2026. This initial phase focuses on visibility, preceding the December 2027 enforcement of engineering requirements for product security, creating a gap where companies must report issues before full compliance with building secure products is mandated.
Researchers Identify 39 Methods to Compromise Passkey Authentication
New research has documented at least 39 methods and attack paths that can compromise passkey authentication, despite the underlying FIDO2 cryptography remaining secure. These vulnerabilities often target the surrounding infrastructure and user interaction rather than the cryptographic keys themselves, highlighting a shift in attack vectors for passkey-protected accounts.
Named Pipes in Windows Pose Security Risks Due to Misconceptions About Local Trust
Named pipes, a common interprocess communication method in Windows, are often mistakenly treated as inherently trusted because they operate locally. This assumption creates security vulnerabilities, especially when privileged services communicate with less privileged applications, as any process with access rights can connect and potentially exploit exposed functionality. Developers must implement explicit identity verification, access control, and data validation for named pipe communications.
AI-powered phishing campaigns bypass traditional email filters with personalized, polymorphic attacks
AI is making phishing attacks more sophisticated, enabling attackers to generate highly personalized emails that bypass traditional email filters. These AI-driven campaigns use public information for reconnaissance, create convincing content, and employ polymorphic techniques to evade detection, posing a significant challenge for Managed Service Providers (MSPs) in protecting clients.
Picus Labs' Blue Report 2026 Shows Declining Malware Prevention and Behavioral Blind Spots
Picus Labs' Blue Report 2026 indicates that enterprise prevention effectiveness rose to 69% but masks significant vulnerabilities, particularly in behavioral detection. The report highlights a decline in IOC-based malware download prevention rates and a general inability of controls to stop quieter variants of known attack techniques. This matters because it reveals a critical gap in security defenses, where systems are effective against recognized threats but fail against behavioral deviations, leaving organizations exposed to sophisticated attacks.
Certighost Vulnerability (CVE-2026-54121) Allows Low-Privilege Users to Impersonate Domain Controllers
A vulnerability named Certighost (CVE-2026-54121) in Microsoft's Active Directory Certificate Services allows a low-privileged Active Directory user to obtain a valid authentication certificate for a Domain Controller. This flaw enables attackers to impersonate a Domain Controller, gaining significant control over an Active Directory environment. Microsoft released a fix for this issue on July 14, 2026.
Modern Attack Chains Bypass Email as Primary Entry Point in Google Workspace
Recent breaches, including Vercel and Composio, demonstrate a shift in attack methodology where email is no longer the sole entry point into Google Workspace. Attackers are now using OAuth grants to access accounts, read sensitive data, and move laterally within the workspace, a pattern that also describes how AI agents operate.