Sign in

BleepingComputer

@bleepingcomputer.com
6.8K followers 9 following 3.8K posts

Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!

PostsRepliesMedia
BleepingComputer @bleepingcomputer.com · 5h
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available.
bleepingcomputer.com
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available.
043
BleepingComputer @bleepingcomputer.com · 8h
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
bleepingcomputer.com
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
071
BleepingComputer @bleepingcomputer.com · 8h
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
bleepingcomputer.com
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
031
BleepingComputer @bleepingcomputer.com · 9h
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.
bleepingcomputer.com
FBI tells ShinyHunters members to turn themselves in after recent arrest
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.
062
BleepingComputer @bleepingcomputer.com · 11h
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
bleepingcomputer.com
Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
051
BleepingComputer @bleepingcomputer.com · 11h
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns.
bleepingcomputer.com
Former US Air Force members sent to prison over BEC attacks
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns.
030
BleepingComputer @bleepingcomputer.com · 12h
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it.
bleepingcomputer.com
Windows 11 2026 Update released, here's everything you need to know
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it.
143
BleepingComputer @bleepingcomputer.com · 12h
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
bleepingcomputer.com
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
082
BleepingComputer @bleepingcomputer.com · 18h
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency.
bleepingcomputer.com
Vietnamese man charged in $16 million 'pig butchering' crypto scam
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency.
011
BleepingComputer @bleepingcomputer.com · 20h
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
bleepingcomputer.com
Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
021
BleepingComputer @bleepingcomputer.com · 22h
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
bleepingcomputer.com
Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
064
BleepingComputer @bleepingcomputer.com · 28/09/2026
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting  some of its business systems.
bleepingcomputer.com
Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting  some of its business systems.
062
BleepingComputer @bleepingcomputer.com · 28/09/2026
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.
bleepingcomputer.com
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.
011
BleepingComputer @bleepingcomputer.com · 28/09/2026
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
bleepingcomputer.com
Dutch police confirm arrest in ShinyHunters hacking investigation
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
042
BleepingComputer @bleepingcomputer.com · 28/09/2026
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.
bleepingcomputer.com
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.
042
BleepingComputer @bleepingcomputer.com · 28/09/2026
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
034
BleepingComputer @bleepingcomputer.com · 28/09/2026
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.
bleepingcomputer.com
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.
051
BleepingComputer @bleepingcomputer.com · 28/09/2026
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
bleepingcomputer.com
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
061
BleepingComputer @bleepingcomputer.com · 28/09/2026
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
bleepingcomputer.com
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
094
BleepingComputer @bleepingcomputer.com · 28/09/2026
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website.
bleepingcomputer.com
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website.
011
BleepingComputer @bleepingcomputer.com · 27/09/2026
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.
bleepingcomputer.com
Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches expected next week.
031
BleepingComputer @bleepingcomputer.com · 27/09/2026
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
bleepingcomputer.com
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
154
BleepingComputer @bleepingcomputer.com · 27/09/2026
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.
bleepingcomputer.com
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.
053
BleepingComputer @bleepingcomputer.com · 26/09/2026
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
bleepingcomputer.com
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
063
BleepingComputer @bleepingcomputer.com · 26/09/2026
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.
bleepingcomputer.com
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.
064
BleepingComputer @bleepingcomputer.com · 26/09/2026
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
bleepingcomputer.com
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
012
BleepingComputer @bleepingcomputer.com · 26/09/2026
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.
bleepingcomputer.com
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.
032
BleepingComputer @bleepingcomputer.com · 25/09/2026
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
bleepingcomputer.com
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
013
BleepingComputer @bleepingcomputer.com · 25/09/2026
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
bleepingcomputer.com
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.
022
BleepingComputer @bleepingcomputer.com · 25/09/2026
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
bleepingcomputer.com
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.
051
BleepingComputer @bleepingcomputer.com · 25/09/2026
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
bleepingcomputer.com
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
061
BleepingComputer @bleepingcomputer.com · 25/09/2026
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out.
bleepingcomputer.com
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out.
031
BleepingComputer @bleepingcomputer.com · 25/09/2026
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release.
bleepingcomputer.com
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release.
031
BleepingComputer @bleepingcomputer.com · 25/09/2026
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.
bleepingcomputer.com
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools.
022
BleepingComputer @bleepingcomputer.com · 25/09/2026
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates.
bleepingcomputer.com
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates.
073
BleepingComputer @bleepingcomputer.com · 25/09/2026
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
bleepingcomputer.com
Hackers steal $351.6 million in Bitget crypto exchange hack
​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets.
033
BleepingComputer @bleepingcomputer.com · 24/09/2026
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads.
bleepingcomputer.com
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads.
042
BleepingComputer @bleepingcomputer.com · 24/09/2026
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
bleepingcomputer.com
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control.
121
BleepingComputer @bleepingcomputer.com · 24/09/2026
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.
bleepingcomputer.com
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.
042
BleepingComputer @bleepingcomputer.com · 24/09/2026
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
bleepingcomputer.com
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security.
012
BleepingComputer @bleepingcomputer.com · 24/09/2026
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key.
bleepingcomputer.com
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key.
032
BleepingComputer @bleepingcomputer.com · 24/09/2026
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
bleepingcomputer.com
CISA: Ransomware gangs now exploiting critical TeamCity flaw
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
041
BleepingComputer @bleepingcomputer.com · 24/09/2026
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
bleepingcomputer.com
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
192
BleepingComputer @bleepingcomputer.com · 24/09/2026
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates.
bleepingcomputer.com
Microsoft fixes bug that broke Windows File History backup feature
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates.
071
BleepingComputer @bleepingcomputer.com · 23/09/2026
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands.
bleepingcomputer.com
Placeholder domain used in dev docs now serves ClickFix attacks
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands.
171
BleepingComputer @bleepingcomputer.com · 23/09/2026
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
bleepingcomputer.com
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application.
004
BleepingComputer @bleepingcomputer.com · 23/09/2026
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
bleepingcomputer.com
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.
031
BleepingComputer @bleepingcomputer.com · 23/09/2026
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
bleepingcomputer.com
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
052
BleepingComputer @bleepingcomputer.com · 23/09/2026
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
bleepingcomputer.com
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.
041
BleepingComputer @bleepingcomputer.com · 23/09/2026
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.
bleepingcomputer.com
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.
011