BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 8hbleepingcomputer.comTeamViewer urges users to patch severe flaws “as soon as possible”Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 9hbleepingcomputer.comBitget hacked via zero-day in third-party security productsCryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 20hbleepingcomputer.comMicrosoft is rolling out Linux container support to WSLMicrosoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 23hbleepingcomputer.comSignal adds encypted local backup support to iOS, desktop appsSignal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 23hbleepingcomputer.comCustom ChatGPTs push ClickFix attacks to deploy RAT malwareCustom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...] 022
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 29/09/2026bleepingcomputer.comFBI tells ShinyHunters members to turn themselves in after recent arrestThe FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026bleepingcomputer.comJadePuffer agentic AI attacks target Azure, destroy cloud resourcesThe JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026bleepingcomputer.comCISA orders feds to patch exploited Citrix flaws by WednesdayThe Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 28/09/2026bleepingcomputer.comOpenAI is preparing “o,” an always-on ChatGPT assistant that could handle emailOpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 27/09/2026bleepingcomputer.comCloudflare fixes Containers cross-tenant flaw exposing customer dataCloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 27/09/2026bleepingcomputer.comAnthropic turns Claude into an AI marketplace with 2,000+ plugins and connectorsAnthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 26/09/2026bleepingcomputer.comMicrosoft pauses KB5002907 update after Office license deactivationsMicrosoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comNew Carbonato malware uses AI agents to hijack exposed Docker hostsA new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comExposed GitLab project email addresses let attackers push codePrivate GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comFedRAMP VDR & VER: Daily Scans Are Only the BeginningFedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comHackers now exploit critical Roundcube flaw in code injection attacksA high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...] 010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comWindows 11 KB5124010 update released with 46 changes and fixesMicrosoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comCISA: Ransomware gangs now exploiting critical TeamCity flawThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 24/09/2026bleepingcomputer.comMicrosoft fixes bug that broke Windows File History backup featureMicrosoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026bleepingcomputer.comNew ClosedQuorum Windows malware uses AI for attack decisionsA new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026bleepingcomputer.comReducing shadow IT visibility gaps with WazuhShadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026bleepingcomputer.comEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026bleepingcomputer.comWebinar tomorrow: Inside real-world Google Workspace breachesTomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 22/09/2026bleepingcomputer.comD-Link warns of max severity zero-day bug in DIR-822A routersD-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...] 011
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026bleepingcomputer.comBigCommerce alerts merchants of data breach linked to Ribon appsEcommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026bleepingcomputer.comGoogle fined €403 million over location data privacy violationsIreland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...] 012
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026bleepingcomputer.comMicrosoft fixes broken Excel copy and paste for all Office usersMicrosoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 21/09/2026bleepingcomputer.comMicrosoft: September updates break File History backup featureMicrosoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 20/09/2026bleepingcomputer.comResearchers escape OpenAI Codex sandbox to run commands on hostResearchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both. [...] 034
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 19/09/2026bleepingcomputer.comViral AI actress' hotline face-scans every caller, watches their moodAI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026bleepingcomputer.comGyazo server flaw exploited to steal 23.6 million user recordsThe Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026bleepingcomputer.comSecure enterprise sharing with access reviews for Microsoft 365Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 18/09/2026bleepingcomputer.comMicrosoft Teams will let admins block custom file extensionsMicrosoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 17/09/2026bleepingcomputer.comWindows 11 24H2 Home and Pro reach end of support in OctoberMicrosoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 17/09/2026bleepingcomputer.comAnthropic wants Claude to analyze your bank account and financial dataAnthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comWindows 11 KB5124008 update breaks domain trust for some usersMicrosoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...] 010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comIranian hackers use CHOSEN BRICK Windows malware to spy on targetsGovernment agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comSpain's data agency gets first report of AI-powered data breachThe Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comThe true cost of a ransomware attack, with and without BCDRThe ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...] 010
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comMicrosoft says Copilot buttons still missing in classic OutlookMicrosoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comWebinar: What happens in the first hours of a Google Workspace breachThe first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comWindows Server 2022 reaches end of mainstream support next monthMicrosoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 16/09/2026bleepingcomputer.comGoogle fixes actively exploited Android zero-day on Pixel devicesGoogle has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 15/09/2026bleepingcomputer.comAcronis warns of actively exploited flaw in its cPanel backup pluginAcronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 15/09/2026bleepingcomputer.comMalcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sitesMalicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026bleepingcomputer.comMicrosoft releases emergency Windows updates to fix RDS failuresMicrosoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026bleepingcomputer.comJapan's Digital Agency says VPN flaw exposed 246,000 personnel recordsJapan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...] 001
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026bleepingcomputer.comHomebrew 7.0.0 gets built-in GUI, better security controlsHomebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026bleepingcomputer.comTwitch extension with 30K installs exposes users’ OAuth tokensA browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...] 000
BleepingComputer [Unofficial] @bleepingcomputer.com.web.brid.gy · 14/09/2026bleepingcomputer.comHackers hijack HBO Max Reddit account to push malware in ClickFix adsHackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...] 000