BleepingComputer
10.5K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Patches Available for Dangerous Bugs in Popular Brand of IP Cameras

Chinese firm Foscam has published firmware updates to address three vulnerabilities in multiple models of IP-based cameras. The flaws, when exploited, allow an attacker to take control of vulnerable cameras, and especially those left connected online via a public IP address. [...]

https://www.bleepingcomputer.com/news/security/patches-available-for-dangerous-bugs-in-popular-brand-of-ip-cameras/
Google Changing the Look of Their Sign-In Screens

Google has announced that they are changing the look of their sign-in screens on June 14th 2018. These changes are purely cosmetic, but as some may be concerned that they are at the wrong site or are being phished, it is important to recognize what is being changed. [...]

https://www.bleepingcomputer.com/news/google/google-changing-the-look-of-their-sign-in-screens/
LOL: BabaYaga WordPress Malware Updates Your Site

Security researchers have spotted a malware strain targeting WordPress sites that includes some pretty clever self-preservation techniques, such as removing competing malware and updating the victim's site. [...]

https://www.bleepingcomputer.com/news/security/lol-babayaga-wordpress-malware-updates-your-site/
Firmware Vulnerabilities Disclosed in Supermicro Server Products

Security researchers have uncovered vulnerabilities affecting the firmware of Supermicro server products. Discovered by the Eclypsium team, these vulnerabilities affect both older and newer models of Supermicro products, but the vendor is working on addressing the issues. [...]

https://www.bleepingcomputer.com/news/security/firmware-vulnerabilities-disclosed-in-supermicro-server-products/
You Can File Complaints About Cryptojacking With the FTC

The US Federal Trade Commission (FTC) is now open to taking complaints from US users about cryptojacking β€”the practice of using JavaScript code to mine cryptocurrencies inside users' browsers without notifying them in advance or requesting permission. [...]

https://www.bleepingcomputer.com/news/security/you-can-file-complaints-about-cryptojacking-with-the-ftc/
Malspam Campaigns Using IQY Attachments to Bypass AV Filters and Install RATs

Malspam campaigns, such as ones being distributed by Necurs, are utilizing a new attachment type that is doing a good job in bypassing antivirus and mail filters.  These IQY attachments are called Excel Web Query files and when opened will attempt to pull data from external sources.  [...]

https://www.bleepingcomputer.com/news/security/malspam-campaigns-using-iqy-attachments-to-bypass-av-filters-and-install-rats/
Cisco Removes Backdoor Account, Fourth in the Last Four Months

For the fourth time in as many months, Cisco has removed hardcoded credentials that were left inside one of its products, which an attacker could have exploited to gain access to devices and inherently to customer networks. [...]

https://www.bleepingcomputer.com/news/security/cisco-removes-backdoor-account-fourth-in-the-last-four-months/
The Week in Ransomware - June 8th 2018 - CryBrazil, CryptConsole, and Magniber

This week we have seen a lot of CryptConsole variants, Magniber activity, & smaller variants released. Ransomware continues to decline as developers move toward more profitable miners and information stealing Trojans. Ransomware is not going away, instead of mass malspam campaigns, ransomware is moving to more targeted attacks. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-june-8th-2018-crybrazil-cryptconsole-and-magniber/
Microsoft Store Brings Remote App Install to Windows 10 With "Install on my devices"

Microsoft has added a new feature to the web version of the Microsoft Store called called "Install on my devices" that allows you to install an app on Windows 10 devices where you have an account. Similar to Google Play, this allows you to install apps on devices from the web, even if your not accessing the store from Windows 10. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-store-brings-remote-app-install-to-windows-10-with-install-on-my-devices/
Weight Watchers IT Infrastructure Exposed via No-Password Kubernetes Server

Just like many companies before it, weight loss program Weight Watchers suffered a small security breach after security researchers found a crucial server exposed on the Internet that was holding the configuration info for some of the company's IT infrastructure. [...]

https://www.bleepingcomputer.com/news/security/weight-watchers-it-infrastructure-exposed-via-no-password-kubernetes-server/
CryptoCurrency Miner Plays Hide-and-seek with Popular Games and Tools

When the CPU utilization on a computer is high, games become less responsive, frame rate goes down, and gameplay stutters. To diagnose these problems, users will commonly open process manager utilities such as Task Manager, Process Explorer, or Process Hacker to determine if any processes are using too much of the CPU power. [...]

https://www.bleepingcomputer.com/news/security/cryptocurrency-miner-plays-hide-and-seek-with-popular-games-and-tools/
Apple Bans Apps That Mine Cryptocurrencies

Apple has updated its review guidelines to specifically prohibit iOS and Mac apps uploaded on the company's official App Store from utilizing users' devices for cryptocurrency mining operations. [...]

https://www.bleepingcomputer.com/news/apple/apple-bans-apps-that-mine-cryptocurrencies/