BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Locky Ransomware switches to the Ykcol Extension for Encrypted Files

Today a new Locky Ransomware variant was discovered by Stormshield malware analyst coldshell that switches to the .ykcol extension for encrypted files. It is important to note that if you are infected with this ransomware, you are not infected with the Ykcol Ransomware, but rather Locky. [...]

https://www.bleepingcomputer.com/news/security/locky-ransomware-switches-to-the-ykcol-extension-for-encrypted-files/
Chinese Mobile Antivirus App Caught Siphoning User Data

Google removed β€” and then reinstated β€” one of the most popular mobile antivirus apps on the Play Store after security firm Check Point discovered that the app was secretly collecting device data from users' smartphones. [...]

https://www.bleepingcomputer.com/news/security/chinese-mobile-antivirus-app-caught-siphoning-user-data/
Russian Authorities Announce Takedown of RAMP Dark Web Marketplace

Russian police acknowledged today that they were responsible for taking down RAMP [Russian Anonymous Marketplace] β€” a Tor-based market that primarily sold drugs β€” a Russian Interior Ministry official told Russian news agency TASS today. [...]

https://www.bleepingcomputer.com/news/security/russian-authorities-announce-takedown-of-ramp-dark-web-marketplace/
Chrome Extension Embeds In-Browser Monero Miner That Drains Your CPU

The authors of SafeBrowse, a Chrome extension with more than 140,000 users, have embedded a JavaScript library in the extension's code that mines for the Monero cryptocurrency using users' computers and without getting their consent. [...]

https://www.bleepingcomputer.com/news/security/chrome-extension-embeds-in-browser-monero-miner-that-drains-your-cpu/
Windows 10 Insider Build 16291 for PC Lets you Finish Articles Started on Your Phone

Today Microsoft released Insider Preview Build 16291 for PC to insiders on the fast ring that includes the ability for Cortana to transfer the current spot you are on in news articles or news listings to your PC. This allows you to read an article when on your phone and then continue reading it on your computer. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-insider-build-16291-for-pc-lets-you-finish-articles-started-on-your-phone/
iTerm2 Leaks Everything You Hover in Your Terminal via DNS Requests

iTerm2, a popular Mac application that comes as a replacement for Apple's official Terminal app, just received a security fix minutes ago for a severe security issue that leaked terminal content via DNS requests. [...]

https://www.bleepingcomputer.com/news/security/iterm2-leaks-everything-you-hover-in-your-terminal-via-dns-requests/
Optionsbleed Bug Leaks Apache Server Memory

Certain Apache server configurations can leak server memory content via a vulnerability called Optionsbleed β€” tracked as CVE-2017-9798 β€” and detailed on Monday by security researcher Hanno BΓΆck. [...]

https://www.bleepingcomputer.com/news/security/optionsbleed-bug-leaks-apache-server-memory/
Attackers Can Use HVAC Systems to Control Malware on Air-Gapped Networks

Heating, ventilation, and air conditioning (HVAC) systems can be used as a means to bridge air-gapped networks with the outside world, allowing remote attackers to send commands to malware placed inside a target's isolated network. [...]

https://www.bleepingcomputer.com/news/security/attackers-can-use-hvac-systems-to-control-malware-on-air-gapped-networks/
The Shark CryptoMix Ransomware Variant Smells Blood in the Water

Today, I discovered a new variant of the CryptoMix ransomware that is appending the .SHARK extension to encrypted file names. This family of ransomware usually releases a new version almost every week, if not sooner, so it is a bit surprising to see them take almost three weeks to release this variant. [...]

https://www.bleepingcomputer.com/news/security/the-shark-cryptomix-ransomware-variant-smells-blood-in-the-water/
IT Contractor Tried to Extort Company by Redirecting Website to Porn Site

An Arizona court sentenced a local man to four years of federal probation after what the judge described as a "one-time lapse in judgment" when the man redirected a company's website to a gay porn portal after a failed extortion attempt. [...]

https://www.bleepingcomputer.com/news/legal/it-contractor-tried-to-extort-company-by-redirecting-website-to-porn-site/
Attackers Take Over WordPress, Joomla, JBoss Servers to Mine Monero

Attacks aimed at delivering cryptocurrency mining tools on enterprise networks have gone up as much as six times, according to telemetry data collected by IBM's X-Force team between January and August 2017. [...]

https://www.bleepingcomputer.com/news/security/attackers-take-over-wordpress-joomla-jboss-servers-to-mine-monero/