News

Bleeping Computer
bleepingcomputer. com > news > security > us-and-canada-arrest-and-charge-suspected-kimwolf-botnet-admin

US and Canada arrest and charge suspected Kimwolf botnet admin

1+ hour, 37+ min ago  (636+ words) Hackers bypass Sonic Wall VPN MFA due to incomplete patching Flipper One project needs community help to build open Linux platform US and Canada arrest and charge suspected Kimwolf botnet admin Own this Luminar Neo editing bundle for $65 (reg. $682) through…...

Google News
bleepingcomputer. com > news > security > police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks

Police seize "First VPN" service used in ransomware, data theft attacks

21+ hour, 28+ min ago  (629+ words) Discord rolls out end-to-end encryption on voice, video calls Cybercrime service disrupted for abusing Microsoft platform to sign malware FBI: Americans lost over $388 million to scams using crypto ATMs in 2025 Police seize "First VPN" service used in ransomware, data theft…...

@Bleepin Computer
bleepingcomputer. com > news > security > hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching > amp

Hackers bypass Sonic Wall VPN MFA due to incomplete patching

1+ day, 13+ hour ago  (617+ words) Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on Sonic Wall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. During the intrusions, the hacker took between 30 and 60 minutes to log in, do network reconnaissance, test credential reuse…...

@Bleepin Computer
bleepingcomputer. com > news > security > tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing > amp

Tycoon2 FA hijacks Microsoft 365 accounts via device-code phishing

4+ day, 19+ hour ago  (661+ words) The Tycoon2 FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. Despite an international law enforcement operation disrupting the Tycoon2 FA phishing platform in March, the malicious operation was rebuilt on new infrastructure and…...

Bleeping Computer
bleepingcomputer. com > news > security > avada-builder-wordpress-plugin-flaws-allow-site-credential-theft

Avada Builder Word Press plugin flaws allow site credential theft

6+ day, 18+ hour ago  (560+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Funnel Builder Word Press plugin bug exploited to steal credit cards Microsoft Exchange, Windows 11 hacked…...

@Bleepin Computer
bleepingcomputer. com > news > security > hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin > amp

Hackers exploit auth bypass flaw in Burst Statistics Word Press plugin

1+ week, 13+ hour ago  (475+ words) Hackers are leveraging a critical authentication bypass vulnerability in the Word Press plugin Burst Statistics to obtain admin-level access to websites. Burst Statistics is a privacy-focused analytics plugin active on 200, 000 Word Press sites and marketed as a lightweight alternative to…...

Symbols: nginx-ui
Bleeping Computer
bleepingcomputer. com > news > security > new-critical-exim-mailer-flaw-allows-remote-code-execution

New critical Exim mailer flaw allows remote code execution

1+ week, 1+ day ago  (604+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak New critical Exim mailer flaw allows remote code execution This CISSP prep bundle is $20 for…...

Symbols: cwe-78
@Bleepin Computer
bleepingcomputer. com > news > security > signal-adds-security-warnings-for-social-engineering-phishing-attacks > amp

Signal adds security warnings for social engineering, phishing attacks

1+ week, 2+ day ago  (282+ words) Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud. The purpose is to introduce enough friction that users get the time to evaluate…...

Bleeping Computer
bleepingcomputer. com > offer > deals > get-5-years-of-adguard-vpn-access-across-70-plus-global-servers-for-40

Get 5 years of Ad Guard VPN access across 70+ global servers for $40

2+ week, 1+ day ago  (514+ words) Canvas login portals hacked in mass Shiny Hunters extortion campaign Ivanti warns of new EPMM flaw exploited in zero-day attacks Student hacked Taiwan high-speed rail to trigger emergency brakes New Cisco Do S flaw requires manual reboot to revive devices…...

Bleeping Computer
bleepingcomputer. com > news > security > hackers-abuse-google-ads-for-godaddy-managewp-login-phishing

Hackers abuse Google ads for Go Daddy Manage WP login phishing

2+ week, 1+ day ago  (573+ words) Student hacked Taiwan high-speed rail to trigger emergency brakes Instructure hacker claims data theft from 8, 800 schools, universities DAEMON Tools devs confirm breach, release malware-free version Hackers abuse Google ads for Go Daddy Manage WP login phishing Critical vm2 sandbox bug lets…...