New Koske Linux malware hides in cute panda images
Bill Toulas / bleepingcomputer - A new Linux malware named Koske may have been developed with artificial intelligence and is using seemingly benign JPEG images of panda bears to deploy malware directly into system memory. [...]
Back to Top / Thursday, July 24, 2025, 4:21 pm / permalink 10873 / 4 stories in 7 months
Hackers fooled Cognizant help desk, says Clorox in $380M cyberattack lawsuit
Bill Toulas / bleepingcomputer - Clorox is suing IT giant Cognizant for gross negligence, alleging it enabled a massive August 2023 cyberattack by resetting an employee's password for a hacker without first verifying their identity. [...]
Back to Top / Wednesday, July 23, 2025, 1:21 pm / permalink 10746 / 5 stories in 7 months
Mandiant: China-Linked Hackers Behind Recent Microsoft SharePoint Zero-Day Attacks
Markus Kasanmascheff / winbuzzer - Google's Mandiant links a China-nexus hacking group to attacks on a critical SharePoint zero-day (CVE-2025-53770), as Microsoft issues emergency patches.The post Mandiant: China-Linked Hackers Behind Recent Microsoft SharePoint Zero-Day Attacks appeared f…
Back to Top / Tuesday, July 22, 2025, 8:20 am / permalink 10608 / 13 stories in 7 months
Vibe coding dream turns to nightmare as Replit deletes developer's database
techspot - Jason Lemkin, founder of the SaaS-focused community SaaStr, initially had a positive experience with Replit but quickly changed his mind when the service started acting like a digital psycho. Replit presents itself as a platform trusted by Fortune 500 com…
Back to Top / Monday, July 21, 2025, 1:21 pm / permalink 10547 / 2 stories in 7 months
Alaska Airlines Flights Resume After IT Outage. What to Do if You Were Affected
Omar Gallaga / cnet - The outage affected Alaska Airlines and Horizon Air flights for several hours on Sunday.
Back to Top / Monday, July 21, 2025, 12:21 pm / permalink 10542 / 2 stories in 7 months
Worldwide cyberattack underway as hackers exploit Microsoft SharePoint zero-day vulnerability
techspot - "Anybody who's got a hosted SharePoint server has got a problem," Adam Meyers, senior vice president with CrowdStrike, told The Washington Post. "It's a significant vulnerability."Read Entire Article
Back to Top / Monday, July 21, 2025, 9:20 am / permalink 10525 / 9 stories in 7 months
Four new Android spyware samples linked to Iran's intel agency
Jessica Lyons / theregister - Persians added snooping capabilities to DCHSpy after Israeli bombs fell Four new samples of Android spyware linked to the Iranian Ministry of Intelligence and Security (MOIS) that collects WhatsApp data, records audio and video, and hunts for files by nam…
Back to Top / Monday, July 21, 2025, 8:20 am / permalink 10517 / 4 stories in 7 months
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
Iain Thomson / theregister - PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Infosec In Brief Microsoft has warned users of SharePoint Server that three on-prem versions of the product include a zero-day flaw that is under attack – and th…
Back to Top / Sunday, July 20, 2025, 8:20 pm / permalink 10499 / 10 stories in 7 months
Is Google Still Down? What We Know About the Gmail, Workspace and Drive Outage
Katie Collins / cnet - It appears Google has resolved the incident that caused a short-lived, but widespread outage.
Back to Top / Friday, July 18, 2025, 1:21 pm / permalink 10424 / 2 stories in 7 months
StrongestLayer Secures $5.2M for AI Email Security
In a clear sign that the spammer battleground remains heated, cybersecurity startup StrongestLayer has successfully raised $5.2 million in seed funding to bolster its AI-driven email threat protection platform. The fresh capital is aimed at enhancing automated defenses just as phishing and malware attacks continue to evolve—because clearly hackers never take a holiday.
Back to Top / Thursday, July 17, 2025, 10:20 pm / permalink 10382 / 1 stories in 7 months
Max severity Cisco ISE bug allows pre-auth command execution, patch now
Bill Toulas / bleepingcomputer - A critical vulnerability (CVE-2025-20337) in Cisco's Identity Services Engine (ISE) could be exploited to let an unauthenticated attacker store malicious files, execute arbitrary code, or gain root privileges on vulnerable devices. [...]
Back to Top / Thursday, July 17, 2025, 2:21 pm / permalink 10338 / 2 stories in 7 months
Roblox is adding an 'age estimation' feature for teens
Karissa Bell / engadget - Roblox is joining the growing ranks of online platforms that are trying to better understand the ages of their teen users. The company is rolling out a new "age estimation" feature for teens 13 and older.With the update, teens will be prompted for an age …
Back to Top / Thursday, July 17, 2025, 7:20 am / permalink 10279 / 12 stories in 7 months
Microsoft Offers Last-Chance Security Updates for Aging Exchange and Skype Servers
Markus Kasanmascheff / winbuzzer - Microsoft reverses course, offering a paid, six-month Extended Security Update (ESU) program for Exchange and Skype servers facing a 2025 support deadline.The post Microsoft Offers Last-Chance Security Updates for Aging Exchange and Skype Servers appeared…
Back to Top / Thursday, July 17, 2025, 5:20 am / permalink 10276 / 2 stories in 7 months
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack
Bill Toulas / bleepingcomputer - To quash speculation of a cyberattack or BGP hijack incident causing the recent 1.1.1.1 Resolver service outage, Cloudflare explains in a post mortem that the incident was caused by an internal misconfiguration. [...]
Back to Top / Wednesday, July 16, 2025, 12:20 pm / permalink 10214 / 3 stories in 7 months
SonicWall SMA devices hacked with OVERSTEP rootkit tied to ransomware
Ionut Ilascu / bleepingcomputer - A threat actor has been deploying a previously unseen malware called OVERSTEP that modifies the boot process of fully-patched but no longer supported SonicWall Secure Mobile Access appliances. [...]
Back to Top / Wednesday, July 16, 2025, 11:21 am / permalink 10201 / 6 stories in 7 months
Ex-US soldier who Googled 'can hacking be treason' pleads guilty to extortion
Jessica Lyons / theregister - File this one under what not to search if you've committed a crime A former US Army soldier, who reportedly hacked AT&T, bragged about accessing President Donald Trump's call logs, and then Googled "can hacking be treason," and "US military personnel defe…
Back to Top / Tuesday, July 15, 2025, 6:21 pm / permalink 10155 / 4 stories in 7 months
CISA orders agencies to immediately patch Citrix Bleed 2, saying bug poses ‘unacceptable risk’
therecord - The one-day deadline issued by CISA on Thursday appears to be the shortest one ever issued. Federal civilian agencies are typically given three weeks to patch bugs added to the known exploited vulnerability catalog.
Back to Top / Friday, July 11, 2025, 10:20 am / permalink 9867 / 7 stories in 7 months
Chatbot used by McDonald's to hire workers leaked data for 64 million people after researchers guessed system password was '123456' — once inside, a second flaw turned up 'every chat interaction [from anyone who] ever applied for a job at McDonald’s'
tomshardware - A pair of security researchers has revealed vulnerabilities in the McHire chatbot Olivia, developed by Paradox.ai for McDonald's, that could have been exploited to reveal personal information about roughly 64 million people.
Back to Top / Friday, July 11, 2025, 8:21 am / permalink 9861 / 6 stories in 7 months
M&S says Dragon Force threat group behind April cyberattack
Suhasini Srinivasaragavan / siliconrepublic - The retailer estimates that the attack will cost the company £300m in profits this year.Read more: M&S says Dragon Force threat group behind April cyberattack
Back to Top / Tuesday, July 8, 2025, 10:21 am / permalink 9600 / 4 stories in 7 months
OpenAI tightens the screws on security to keep away prying eyes
Connie Loizos / techcrunch - OpenAI has reportedly overhauled its security operations to protect against corporate espionage. According to the Financial Times, the company accelerated an existing security clampdown after Chinese startup DeepSeek released a competing model in January,…
Back to Top / Tuesday, July 8, 2025, 3:20 am / permalink 9584 / 5 stories in 7 months