Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

BleepingComputer

@BleepingComputer@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Breaking technology news, security guides, and tutorials that help you get the most from your computer.

Feel free to send us story tips at press@bleepingcomputer.com.

Sometimes a bot, sometimes not.

18376 Followers
7 Following
50 Posts
Joined November 08, 2022
Website:
https://www.bleepingcomputer.com/
Twitter:
https://twitter.com/BleepinComputer
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1d ago
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-max-severity-ssrf-flaw-in-sma1000-gateways/
SonicWall warns of max severity SSRF flaw in SMA1000 gateways
BleepingComputer

SonicWall warns of max severity SSRF flaw in SMA1000 gateways

SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances.

1
0
1
1
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1w ago
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. https://www.bleepingcomputer.com/news/microsoft/microsoft-365-kb5002907-update-paused-after-office-license-deactivations/
Microsoft pauses KB5002907 update after Office license deactivations
BleepingComputer

Microsoft pauses KB5002907 update after Office license deactivations

Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.

26
4
24
3
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 3w ago
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/
Anthropic wants Claude to analyze your bank account and financial data
BleepingComputer

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money."

23
21
19
14
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
BleepingComputer

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.

11
1
11
3
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.

10
0
7
1
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 4w ago
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BleepingComputer

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.

16
1
12
5
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 6d ago
Boosted by @kcarruthers@infosec.exchange
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. https://www.bleepingcomputer.com/news/security/autonomous-ai-agents-tried-to-hack-us-canadian-government-websites/
Autonomous AI agents tried to hack US, Canadian government websites
BleepingComputer

Autonomous AI agents tried to hack US, Canadian government websites

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics.

1
0
4
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 6d ago
Boosted by @kcarruthers@infosec.exchange
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/
Microsoft says threat actors are ahead in the early AI race
BleepingComputer

Microsoft says threat actors are ahead in the early AI race

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.

1
0
3
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
BleepingComputer

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records.

3
1
8
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
BleepingComputer

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.

2
0
4
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 3w ago
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
Spain's data agency gets first report of AI-powered data breach
BleepingComputer

Spain's data agency gets first report of AI-powered data breach

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).

3
0
1
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
BleepingComputer

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems.

6
2
10
1
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing-firefox-thunderbird-releases-after-exposure/
Mozilla updates GPG signing key for Firefox releases after exposure
BleepingComputer

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.

12
1
21
1
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product.

1
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 4w ago
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
BleepingComputer

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.

3
1
4
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
Security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) has released another Microsoft Defender zero-day exploit that blocks antivirus updates. https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
New Windows Defender zero-day blocks Microsoft antivirus updates
BleepingComputer

New Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.

1
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
Malicious npm packages evade install-script defenses at runtime
BleepingComputer

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.

1
0
1
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes/
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
BleepingComputer

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines.

1
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
BleepingComputer

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information.

1
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack." https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
BleepingComputer

Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack

The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 30 community water systems in "a coordinated cyberattack."

1
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system. https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5101684-update-released-with-42-changes-and-fixes/
Windows 11 KB5101684 update released with 42 changes and fixes
BleepingComputer

Windows 11 KB5101684 update released with 42 changes and fixes

​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face. https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-misconfigured-cyber-test/
Meta AI model hacked a company during misconfigured cyber test
BleepingComputer

Meta AI model hacked a company during misconfigured cyber test

Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached Hugging Face.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 4d ago
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. https://www.bleepingcomputer.com/news/google/google-gemini-could-soon-get-full-access-to-your-macs-files-apps-and-the-web/
Google Gemini could soon get full access to your Mac’s files, apps and the web
BleepingComputer

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time.

0
0
1
1
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
BleepingComputer

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 3d ago
Boosted by @oxy@social.bsdlab.au
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. https://www.bleepingcomputer.com/news/google/google-halts-open-source-bug-bounty-program-amid-ai-spam-surge/
Google halts open-source bug bounty program amid AI spam surge
BleepingComputer

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports.

0
0
1
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
BleepingComputer

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
N-able warns of N-central auth bypass flaw exploited in attacks
BleepingComputer

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.

0
1
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale. https://www.bleepingcomputer.com/news/security/these-near-mint-asus-chromebook-refurbs-are-only-145/
These near-mint ASUS Chromebook refurbs are only $145
BleepingComputer

These near-mint ASUS Chromebook refurbs are only $145

Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade "A" rating, but it still only costs $144.97 (reg. $369.99) on sale.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-allowing-hackers-to-breach-networks/
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
BleepingComputer

TP-Link patches Omada ZTP flaws allowing hackers to breach networks

TP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE).

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
VMware fixes three critical flaws allowing auth bypass, VM escapes
BleepingComputer

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-says-operations-unaffected/
Analog Devices discloses data breach, says operations unaffected
BleepingComputer

Analog Devices discloses data breach, says operations unaffected

American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
Massive ChainDrop npm supply-chain attack infects hundreds of packages
BleepingComputer

Massive ChainDrop npm supply-chain attack infects hundreds of packages

Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
McKesson discloses breach after ShinyHunters claims patient data theft
BleepingComputer

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-astra-is-now-rolling-out-to-20-plus-subscription/
ChatGPT Astra is now rolling out to $20 Plus subscription
BleepingComputer

ChatGPT Astra is now rolling out to $20 Plus subscription

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access..

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1w ago
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
Elementor WordPress flaw lets attackers create admin accounts
BleepingComputer

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/
Critical Progress LoadMaster flaw now actively exploited in attacks
BleepingComputer

Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/
Cisco warns of FMC static credential flaw exploited in zero-day attacks
BleepingComputer

Cisco warns of FMC static credential flaw exploited in zero-day attacks

Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
New Pass-ta-key attacks let malware hijack Google-synced passkeys
BleepingComputer

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys.

0
0
3
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Claude uploaded malware to PyPI in Anthropic's botched test - @Ax_Sharma https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-pypi-in-anthropics-botched-test/
bleepingcomputer.com
0
1
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberattack-disrupting-operations/
North Carolina Ports confirms cyberattack disrupting operations
BleepingComputer

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw/
JetBrains warns of critical TeamCity remote code execution flaw
BleepingComputer

JetBrains warns of critical TeamCity remote code execution flaw

JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
BleepingComputer

OpenAI agent used exposed credentials at 4 services in Hugging Face breach

In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.

0
1
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
BleepingComputer

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
CISA orders feds to patch Zyxel flaw exploited for data theft
BleepingComputer

CISA orders feds to patch Zyxel flaw exploited for data theft

​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2w ago
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
New RatHat Android malware uses AI to automate device control
BleepingComputer

New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices.

0
0
2
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
Anthropic confirms Claude is down worldwide
BleepingComputer

Anthropic confirms Claude is down worldwide

Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely on its API.

0
1
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 19h ago
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records. https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/
Hackers hijack Google domains after breaching ccTLD registries
BleepingComputer

Hackers hijack Google domains after breaching ccTLD registries

Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party operators and modifying authoritative DNS records.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 2mo ago
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
BleepingComputer

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. https://www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/
Microsoft says Windows 11 KB5120998 update resets mouse settings
BleepingComputer

Microsoft says Windows 11 KB5120998 update resets mouse settings

Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update.

0
0
0
0
Open post
BleepingComputer @BleepingComputer@infosec.exchange
· 1mo ago
Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
Valve notifies Steam hardware customers of a data breach
BleepingComputer

Valve notifies Steam hardware customers of a data breach

Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 16:03:07 UTC