§Source · Bleeping Computer
Bleeping Computer
Every dispatch we have aggregated from Bleeping Computer.
All dispatches
Loading
§Source · Bleeping Computer
Every dispatch we have aggregated from Bleeping Computer.
All dispatchesMedical Computer Business Services breach exposed sensitive records of over 1.26 million patients from billing systems.
Qilin ransomware exploits critical Palo Alto PAN-OS GlobalProtect authentication bypass to breach networks and deploy ransomware.
Windows LegacyHive local privilege escalation zero-day allows attackers to gain elevated privileges on up-to-date Windows systems.
Off-chain infrastructure compromise at Ostium enabled attackers to steal $23.75M in cryptocurrency from liquidity vaults.
SharePoint CVE-2026-50522 exploited to steal machine keys enabling persistent access even after patching.
Active exploitation of wp2shell (CVE-2026-63030, CVE-2026-60137) enables webshell installation and site takeover on many WordPress hosts.
Russia-linked Laundry Bear leveraged a Zimbra zero-click vulnerability to steal emails, prompting international advisories and urgent patching.
Check Point patched an actively exploited SmartConsole zero-day used against customer admin panels; immediate patching recommended.
Microsoft reports a surge in ACR Stealer attacks exfiltrating browser credentials, tokens, and sensitive documents from customers.
Threat actors abused ViPNet update mechanism to push malicious updates targeting Russian government organizations.
LegacyHive Windows zero-day exploit enables privilege escalation to admin on up-to-date Windows systems via registry hive flaws.
EY discloses breach of a third-party support ticket system, with client tax documents accessed and downloaded.
CISA mandated urgent patching for actively exploited Fortinet FortiSandbox vulnerabilities with near-term federal deadlines.
Russian actor UAT-11795 trojanized WebEx and Zoom installers to deploy Starland RAT, stealing credentials and crypto.
Spirals ransomware completes intrusion-to-encryption in under 24 hours, stressing the need for rapid detection and response.
CISA issued an emergency order forcing federal agencies to patch an actively exploited Oracle E-Business Suite vulnerability immediately.
SonicWall discloses CVE-2026-15409 and CVE-2026-15410 in SMA1000 actively exploited in zero-day attacks; customers urged to patch immediately.
Jalisco and OmegaLord phishing kits target Microsoft 365, using MFA-evasion techniques to steal credentials and session tokens.
Japan's Nihon Kotsu halts systems after cyberattack impacting dispatch and operations, showing transport-sector operational risks from intrusions.
Get these articles delivered to your inbox.
Subscribe free