BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Chrome to Display Warnings About Similar or Lookalike URLs

Google is adding a new feature to Google Chrome that will warn users about similar, or lookalike, URLs that a user may visit thinking they are going to the normal site. This feature is designed to warn users when they visit typosquatting domains, IDN Homograph/unicode attacks, scams, and phishing sites. [...]

https://www.bleepingcomputer.com/news/software/chrome-to-display-warnings-about-similar-or-lookalike-urls/
New Malware Siphons Cryptocurrency Wallets and Credentials, Credit Cards

CookieMiner is a new malware strain capable of stealing and exfiltrating web browser cookies related to online wallet services and cryptocurrency exchange websites, as well as passwords, text messages, and credit card credentials. [...]

https://www.bleepingcomputer.com/news/security/new-malware-siphons-cryptocurrency-wallets-and-credentials-credit-cards/
Houzz Break-In: Data Breach Announced

The home improvement site Houzz announced a data breach this week involving third-parties gaining access to a file that contains publicly visible user data as well as private account information. [...]

https://www.bleepingcomputer.com/news/security/houzz-break-in-data-breach-announced/
New SpeakUp Backdoor Infects Linux and macOS with Miners

New SpeakUp Backdoor Trojan targets servers running six different Linux distributions and macOS by exploiting a number of known security vulnerabilities, while also managing to evade all anti-malware solutions in the process. [...]

https://www.bleepingcomputer.com/news/security/new-speakup-backdoor-infects-linux-and-macos-with-miners/
Google Working on Chrome Never-Slow Mode for Faster Browsing

According to a work in progress Chromium source code commit, Google Chrome might get a "Never-Slow Mode" flag in the future which, when enabled, would block the loading of website resources that exceed a pre-defined size limit. [...]

https://www.bleepingcomputer.com/news/google/google-working-on-chrome-never-slow-mode-for-faster-browsing/
Windows 3.0 File Manager Reborn in All Its Nostalgic Glory

In 2018, Microsoft open-sourced the original and first GUI-based Windows File Manager which debuted in Windows 3.0. The program, which is maintained on GitHub by Microsoft, is now available to download for Windows 10 devices from the Microsoft Store. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-30-file-manager-reborn-in-all-its-nostalgic-glory/
ExileRat Targeting Tibetan Supporters via Malicious PowerPoint Docs

A targeted attack against pro-Tibetan supporters has been discovered that installs the ExileRat remote access Trojan through malicious PowerPoint attachments. Once infected, the RAT will allow attackers to retrieve information, execute commands, and steal data from the infected computers. [...]

https://www.bleepingcomputer.com/news/security/exilerat-targeting-tibetan-supporters-via-malicious-powerpoint-docs/
RDP Clients Exposed to Reverse RDP Attacks by Major Protocol Issues

Multiple major vulnerabilities were discovered in the Remote Desktop Protocol (RDP) protocol which can allow bad actors to take control of computers connecting to a malicious server using remote code execution and memory corruption. [...]

https://www.bleepingcomputer.com/news/security/rdp-clients-exposed-to-reverse-rdp-attacks-by-major-protocol-issues/
Mozilla Resumes Firefox 65 Rollout After AVs Disable HTTPS Scanning

Last week Mozilla halted the rollout of Firefox 65 for Windows after users started reporting insecure certificate errors due to antivirus software conflicts. Now that antivirus vendors have disabled HTTPS scanning for Firefox, Mozilla has enabled the automatic update of Firefox 65 again. [...]

https://www.bleepingcomputer.com/news/software/mozilla-resumes-firefox-65-rollout-after-avs-disable-https-scanning/
OpenOffice Vulnerable to Remote Code Execution, LibreOffice Patched

The latest version of OpenOffice is exposed to a remote code execution vulnerability that can be triggered using automated macro execution when users move the mouse over a maliciously crafted ODT document. The issue was patched in LibreOffice 6.0.7/6.1.3. [...]

https://www.bleepingcomputer.com/news/security/openoffice-vulnerable-to-remote-code-execution-libreoffice-patched/
Microsoft Confirms Windows Update Problems Were Caused by DNS Issues

In a new update last night to the Windows 10 and Windows Server 2019 update history support article, Microsoft has confirmed that this problem was caused by data corruption at an external DNS service provider. This caused incorrect records to be pushed to downstream DNS servers at other ISPs. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-windows-update-problems-were-caused-by-dns-issues/
Microsoft Released the February 2019 Non-Security Office Updates

Microsoft released the February Non-Security Microsoft Office updates containing improvements and fixes for MSI-based editions of Office 2010, Office 2013, and Office 2016. These updates do not apply to the Click-to-Run versions of the apps, such as Microsoft Office 365 Home. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-released-the-february-2019-non-security-office-updates/
Cryptojacking Overtakes Ransomware, Malware-as-a-Service on the Rise

Cryptominers infected roughly ten times more organizations during 2018 than ransomware did, however only one in five security professionals knew that their company's systems have been impacted by a malware attack as reported by Check Point Research. [...]

https://www.bleepingcomputer.com/news/security/cryptojacking-overtakes-ransomware-malware-as-a-service-on-the-rise/
Power Company Has Security Breach Due to Downloaded Game

South African energy supplier Eskom Group has been hit with a double security breach consisting of an unsecured database containing customer information and a corporate computer infected with the Azorult information-stealing Trojan. [...]

https://www.bleepingcomputer.com/news/security/power-company-has-security-breach-due-to-downloaded-game/