§Source · Bleeping Computer
Bleeping Computer
Every dispatch we have aggregated from Bleeping Computer.
All dispatches
Loading
§Source · Bleeping Computer
Every dispatch we have aggregated from Bleeping Computer.
All dispatchesCISA confirms ransomware groups are exploiting a high-severity Windows Task Host vulnerability previously flagged as actively exploited.
CISA confirms active exploitation of a high-severity Microsoft SharePoint RCE now used in ransomware intrusions and lateral movement.
US and South Korean agencies warn of Gunra exploiting firewall and VPN flaws to hit government and critical infrastructure.
Microsoft released massive August updates covering hundreds of CVEs, including multiple zero-days — prioritize exploited and high-impact fixes.
Threat actors exploited unpatched TrueConf servers to replace client installers with trojanized backdoors for remote access.
Cyberattack disrupted gates and operations across three North Carolina ports, drawing Coast Guard attention.
ChainDrop poisoned 1,300+ npm packages, threatening developer supply chains and downstream applications.
Active exploitation of N-able N-central CVE-2026-18577 allows attackers admin access to RMM servers; urgent patching recommended.
CISA warns of rising attacks on internet-exposed PLCs in water/wastewater systems and recommends removing public exposure.
COLDCARD RNG/firmware flaw enabled rapid sweeping of Bitcoin wallets, linked to tens of millions in stolen funds.
JetBrains warns of a critical authentication bypass in TeamCity on-premises that could lead to remote code execution if exploited.
ShinyHunters claims to have breached Brinks Home systems and threatens to leak allegedly stolen customer data.
Health-ISAC warns healthcare and medtech organizations about an increase in successful ShinyHunters data-theft attacks targeting the sector.
vBulletin released patches for critical pre-auth PHP template RCE; public exploit demonstrating eval() usage is available.
Researchers found 24,650 internet-exposed BMC/IPMI interfaces disclosing password-derived hashes before login, enabling offline cracking.
CubePilot reports DNS hijack disrupted drone flight-controller developer services and intercepted customer traffic and updates.
U.S. and Australian guidance from CISA advises critical infrastructure to prepare for isolating OT systems during cyber incidents.
Get these articles delivered to your inbox.
Subscribe free