BleepingComputer

bleepingcomputer.com · EN

BleepingComputer - All Stories

Latest posts

  1. MacSync malware uses public iCloud calendars to deliver new payloads

    · bleepingcomputer.com · Bill Toulas

    A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

  2. New Carbonato malware uses AI agents to hijack exposed Docker hosts

    · bleepingcomputer.com · Bill Toulas

    A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

  3. Exposed GitLab project email addresses let attackers push code

    · bleepingcomputer.com · Bill Toulas

    Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

  4. FedRAMP VDR & VER: Daily Scans Are Only the Beginning

    · bleepingcomputer.com · Sponsored by Anecdotes

    FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated…

  5. Hackers now exploit critical Roundcube flaw in code injection attacks

    · bleepingcomputer.com · Sergiu Gatlan

    A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

  6. Windows 11 KB5124010 update released with 46 changes and fixes

    · bleepingcomputer.com · Sergiu Gatlan

    Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

  7. CISA: Ransomware gangs now exploiting critical TeamCity flaw

    · bleepingcomputer.com · Sergiu Gatlan

    ​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]

  8. OpenAI hacked Australian Medicare govt site, probed data providers

    · bleepingcomputer.com · Bill Toulas

    OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]

  9. Microsoft fixes bug that broke Windows File History backup feature

    · bleepingcomputer.com · Sergiu Gatlan

    Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]

  10. Placeholder domain used in dev docs now serves ClickFix attacks

    · bleepingcomputer.com · Lawrence Abrams

    The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]

  11. New RemControl Android banking malware targets users in Europe and Canada

    · bleepingcomputer.com · Bill Toulas

    A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]

  12. Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    · bleepingcomputer.com · Bill Toulas

    Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

  13. Hackers start exploiting critical WordPress flaw for code execution

    · bleepingcomputer.com · Bill Toulas

    Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

  14. Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

    · bleepingcomputer.com · Bill Toulas

    A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]

  15. InfraTrust report warns network management systems under attack

    · bleepingcomputer.com · Lawrence Abrams

    Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

In the directory since 25 Sept 2026 · last checked 25 Sept 2026 · RSS

Report a problem with this feed