Skip to main content

Security News

Filter by:

Ransomware hackers dwell time drops to 5 days, RDP still widely used

Ransomware threat actors are spending less time on compromised networks before security solutions sound the alarm. In the first half of the year the hackers' median dwell time dropped to five days from nine in 2022 [...]
Bleepingcomputer 25 Aug 2023 1804 Views

Google Workspace will require two admins to sign off on critical changes

Google announced today new cybersecurity defense controls that will allow security teams to thwart account takeover attempts and social engineering attacks targeting Workspace users. [...]
Bleepingcomputer 24 Aug 2023 1958 Views

Over 3,000 Openfire servers vulnerable to takover attacks

Thousands of Openfire servers remain vulnerable to CVE-2023-32315, an actively exploited and path traversal vulnerability that allows an unauthenticated user to create new admin accounts. [...]
Bleepingcomputer 24 Aug 2023 1793 Views

Windows 10 KB5029331 update introduces a new Backup app

Microsoft has released the optional KB5029331 Preview cumulative update for Windows 10 22H2 with sixteen improvements or fixes, including the introduction of a new Backup app. [...]
Bleepingcomputer 24 Aug 2023 2036 Views

Akira ransomware targets Cisco VPNs to breach organizations

There's mounting evidence that Akira ransomware targets Cisco VPN (virtual private network) products as an attack vector to breach corporate networks, steal, and eventually encrypt data.
Bleeping Computer 23 Aug 2023 1794 Views

Carderbee hacking group hits Hong Kong orgs in supply chain attack

A previously unidentified APT hacking group named 'Carderbee' was observed attacking organizations in Hong Kong and other regions in Asia, using legitimate software to infect targets' computers with the PlugX malware.
Bleeping Computer 23 Aug 2023 1778 Views

Scraped data of 2.6 million Duolingo users released on hacking forum

The scraped data of 2.6 million DuoLingo users was leaked on a hacking forum, allowing threat actors to conduct targeted phishing attacks using the exposed information.
Bleeping Computer 23 Aug 2023 1890 Views

Microsoft DNS boo-boo breaks Hotmail for users around the globe

ALSO: NYC says kthxbye to TikTok, slain Microsoft exec's wife indicted, and some ASAP patch warnings Infosec in brief  Someone at Microsoft has some explaining to do after a messed-up DNS record caused emails sent from accounts using Microsoft's...
The Register 22 Aug 2023 7995 Views

This AI-generated crypto invoice scam almost got me, and I'm a security pro

Even a tech pro can fall for a well-laid phishing trap. Here's what happened to me - and how you can avoid a similar fate, too.
ZDnet 22 Aug 2023 2145 Views

TP-Link smart bulbs can let hackers steal your WiFi password

Researchers from Italy and the UK have discovered four vulnerabilities in the TP-Link Tapo L530E smart bulb and TP-Link's Tapo app, which could allow attackers to steal their target's WiFi password. [...]
Bleepingcomputer 22 Aug 2023 1975 Views