BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Linux Kernel Spectre Protection Changes to Boost App Performance

The Speculative Store Bypass Disable (SSBD) bit will be toggled off for programs that do not require the extra protection against the Spectre Variant 4 hardware security issue according to a proposed Linux kernel patch [...]

https://www.bleepingcomputer.com/news/linux/linux-kernel-spectre-protection-changes-to-boost-app-performance/
Ethical Hacker Exposes Magyar Telekom Vulnerabilities, Faces 8 Years in Jail

An ethical hacker who discovered a security vulnerability in Magyar Telekom's IT systems during April 2018 is currently being investigated by the Hungarian Prosecution Service after the company filed a complaint and faces 8 years in prison, local Hungarian media reports. [...]

https://www.bleepingcomputer.com/news/security/ethical-hacker-exposes-magyar-telekom-vulnerabilities-faces-8-years-in-jail/
Microsoft Forcing Skype Classic Users to Upgrade to Version 8

See all those happy faces in the picture above? A lot of people are not feeling the same way now that Microsoft has decided to force users to upgrade from Skype 7.4, otherwise known as Skype Classic, to the much disliked Skype 8. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-forcing-skype-classic-users-to-upgrade-to-version-8/
Basecamp Successfully Defends Against Credential Stuffing Attack

Basecamp successfully blocked an hour-long credential stuffing attack targeting its platform on January 29, with only around 100 out of the company's advertised user base of approximately 3 million accounts being affected. [...]

https://www.bleepingcomputer.com/news/security/basecamp-successfully-defends-against-credential-stuffing-attack/
Google Outage Causing Google Charts and Other APIs to Not Work

If you use Google Charts, or other Google API libraries, as part of your web site then you may have noticed that they stopped working. This is being caused by an outage at Google that is causing the older jsapi library and causing the URL to return a 502 error. [...]

https://www.bleepingcomputer.com/news/google/google-outage-causing-google-charts-and-other-apis-to-not-work/
Mozilla Halts Firefox 65 Rollout Due to Insecure Certificate Errors

Mozilla has halted the automatic updates to Firefox 65 as users are unable to browse web sites due to certificate errors. These errors are being caused by conflicts between various antivirus program's HTTPS scanning and Firefox 65. [...]

https://www.bleepingcomputer.com/news/software/mozilla-halts-firefox-65-rollout-due-to-insecure-certificate-errors/
DHS Security Tech Innovation Program Means Big Money for SMBs

U.S. small businesses have until February 12 to submit their homeland security technology solutions proposals as part of the DHS FY 19 SBIR Solicitation program according to a press release issued by the U.S. Department of Homeland Security. [...]

https://www.bleepingcomputer.com/news/security/dhs-security-tech-innovation-program-means-big-money-for-smbs/
The Week in Ransomware - February 1st 2019 - LockerGoga, MalSpam, and More

The biggest ransomware news this week is the cyber attack on Altran that was supposedly hit by the LockerGoga Ransomware. In addition, huge malspam campaigns were pushing Troldesh on Russia and GandCrab on Japanese victims. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-february-1st-2019-lockergoga-malspam-and-more/
DHS Cyber Hunt Teams to Be Authorized by Reintroduced Bipartisan Bill

The bipartisan Department of Homeland Security (DHS) Cyber Hunt and Incident Response Teams Act which would require the DHS to authorize "cyber incident response" and "cyber hunt" teams was reintroduced on January 31. [...]

https://www.bleepingcomputer.com/news/legal/dhs-cyber-hunt-teams-to-be-authorized-by-reintroduced-bipartisan-bill/
New Scam Holds YouTube Channels for Ransom

Scammers are abusing the YouTube policy violation system by filing fake copyright infringements against content creators until their channel is close to being suspended. These scammers then hold the channel ransom by telling YouTubers to send a payment or they will file another copyright infringement to have the channel suspended. [...]

https://www.bleepingcomputer.com/news/security/new-scam-holds-youtube-channels-for-ransom/
Sextortion Scam Stating Xvideos Was Hacked to Record You Through Webcam

A sextortion scam variant is going around that states the popular adult site called Xvideos.com was hacked to include malicious script that records a visitor through their webcam and sends it to the hacker. The scam emails also states that this script was able to connect back to the visitors computer to steal their data and contacts. [...]

https://www.bleepingcomputer.com/news/security/sextortion-scam-stating-xvideos-was-hacked-to-record-you-through-webcam/
Chrome to Display Warnings About Similar or Lookalike URLs

Google is adding a new feature to Google Chrome that will warn users about similar, or lookalike, URLs that a user may visit thinking they are going to the normal site. This feature is designed to warn users when they visit typosquatting domains, IDN Homograph/unicode attacks, scams, and phishing sites. [...]

https://www.bleepingcomputer.com/news/software/chrome-to-display-warnings-about-similar-or-lookalike-urls/
New Malware Siphons Cryptocurrency Wallets and Credentials, Credit Cards

CookieMiner is a new malware strain capable of stealing and exfiltrating web browser cookies related to online wallet services and cryptocurrency exchange websites, as well as passwords, text messages, and credit card credentials. [...]

https://www.bleepingcomputer.com/news/security/new-malware-siphons-cryptocurrency-wallets-and-credentials-credit-cards/
Houzz Break-In: Data Breach Announced

The home improvement site Houzz announced a data breach this week involving third-parties gaining access to a file that contains publicly visible user data as well as private account information. [...]

https://www.bleepingcomputer.com/news/security/houzz-break-in-data-breach-announced/
New SpeakUp Backdoor Infects Linux and macOS with Miners

New SpeakUp Backdoor Trojan targets servers running six different Linux distributions and macOS by exploiting a number of known security vulnerabilities, while also managing to evade all anti-malware solutions in the process. [...]

https://www.bleepingcomputer.com/news/security/new-speakup-backdoor-infects-linux-and-macos-with-miners/
Google Working on Chrome Never-Slow Mode for Faster Browsing

According to a work in progress Chromium source code commit, Google Chrome might get a "Never-Slow Mode" flag in the future which, when enabled, would block the loading of website resources that exceed a pre-defined size limit. [...]

https://www.bleepingcomputer.com/news/google/google-working-on-chrome-never-slow-mode-for-faster-browsing/
Windows 3.0 File Manager Reborn in All Its Nostalgic Glory

In 2018, Microsoft open-sourced the original and first GUI-based Windows File Manager which debuted in Windows 3.0. The program, which is maintained on GitHub by Microsoft, is now available to download for Windows 10 devices from the Microsoft Store. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-30-file-manager-reborn-in-all-its-nostalgic-glory/