Sign in

BleepingComputer [Unofficial]

@bleepingcomputer.com.web.brid.gy
2.3K followers 0 following 2.9K posts

BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and […] 🌉 bridged from 🌐 bleepingcomputer.com: fed.brid.gy/web/bleepingcomputer.com

PostsRepliesMedia
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 6h
bleepingcomputer.com
TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 7h
bleepingcomputer.com
Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 17h
bleepingcomputer.com
Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21h
bleepingcomputer.com
Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21h
bleepingcomputer.com
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
022
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22h
bleepingcomputer.com
FBI tells ShinyHunters members to turn themselves in after recent arrest
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026
bleepingcomputer.com
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026
bleepingcomputer.com
CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026
bleepingcomputer.com
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 27/09/2026
bleepingcomputer.com
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 27/09/2026
bleepingcomputer.com
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 26/09/2026
bleepingcomputer.com
Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
FedRAMP VDR & VER: Daily Scans Are Only the Beginning
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
CISA: Ransomware gangs now exploiting critical TeamCity flaw
​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026
bleepingcomputer.com
Microsoft fixes bug that broke Windows File History backup feature
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026
bleepingcomputer.com
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026
bleepingcomputer.com
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026
bleepingcomputer.com
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026
bleepingcomputer.com
Webinar tomorrow: Inside real-world Google Workspace breaches
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026
bleepingcomputer.com
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]
011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026
bleepingcomputer.com
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026
bleepingcomputer.com
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]
012
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026
bleepingcomputer.com
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026
bleepingcomputer.com
Microsoft: September updates break File History backup feature
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 20/09/2026
bleepingcomputer.com
Researchers escape OpenAI Codex sandbox to run commands on host
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...]
034
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 19/09/2026
bleepingcomputer.com
Viral AI actress' hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026
bleepingcomputer.com
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026
bleepingcomputer.com
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026
bleepingcomputer.com
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 17/09/2026
bleepingcomputer.com
Windows 11 24H2 Home and Pro reach end of support in October
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 17/09/2026
bleepingcomputer.com
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Spain's data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Windows Server 2022 reaches end of mainstream support next month
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026
bleepingcomputer.com
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 15/09/2026
bleepingcomputer.com
Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 15/09/2026
bleepingcomputer.com
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026
bleepingcomputer.com
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026
bleepingcomputer.com
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026
bleepingcomputer.com
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026
bleepingcomputer.com
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026
bleepingcomputer.com
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
000