BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Microsoft February 2019 Patch Tuesday Includes Fixes for 70 Vulnerabilities

Today is Microsoft's February 2019 Patch Tuesday, which means it is time to get those security updates installed. Included in this month's security updates is one for an actively exploited Internet Explorer vulnerability and another remote code execution vulnerability in DHCP. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2019-patch-tuesday-includes-fixes-for-70-vulnerabilities/
Weird Phishing Campaign Uses Links With Almost 1,000 Characters

A targeted phishing campaign is underway that states your email has been blacklisted and then asks you to confirm it by entering your credentials. For some reason, this campaign is using phishing links that can contain almost 1,000 characters, which is enough to make anyone suspicious. [...]

https://www.bleepingcomputer.com/news/security/weird-phishing-campaign-uses-links-with-almost-1-000-characters/
Microsoft Releases the February 2019 Updates for Office

Microsoft released the February 2019 Office Update containing a list of 19 security updates and 28 non-security updates, while also updating the Click-To-Run Office 2013 version to 15.0.5111.1001 in the process. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-february-2019-updates-for-office/
The Scarlet Widow Gang Entraps Victims Using Romance Scams

We often hear about sextortion, business email compromise (BEC), and inheritance scams, but the often overlooked "Romance Scams" could be the most insidious of them all. Not only do victims lose money, but  the emotional entanglement ultimately leads to heartbreak. [...]

https://www.bleepingcomputer.com/news/security/the-scarlet-widow-gang-entraps-victims-using-romance-scams/
Canonical Snapd Vulnerability Gives Root Access in Linux

A researcher has discovered a new vulnerability called "Dirty_Sock" in the REST API for Canonical's snapd daemon that can allow attackers to gain root access on Linux machines. To illustrate how these vulnerabilities can be exploited, the researcher has released to PoCs that use different methods to elevate privileges. [...]

https://www.bleepingcomputer.com/news/security/canonical-snapd-vulnerability-gives-root-access-in-linux/
Cisco Network Assurance Engine Bug Allows Login with Old Passwords

Cisco has issue a security advisory for Cisco Network Assurance Engine (NAE) Release 3.0(1) for a bug that causes password changes done via NAE to not be synchronized to the CLI of the associated device. This would allow a user to be able to gain access to a device via its CLI using the previous password. [...]

https://www.bleepingcomputer.com/news/security/cisco-network-assurance-engine-bug-allows-login-with-old-passwords/
OpenOffice Zero-Day Code Execution Flaw Gets Free Micropatch

A micropatch is now available for a zero-day OpenOffice code execution vulnerability which can be triggered via automated macro execution following a mouseover event when viewing a maliciously crafted ODT document. [...]

https://www.bleepingcomputer.com/news/security/openoffice-zero-day-code-execution-flaw-gets-free-micropatch/
Shlayer Malware Disables macOS Gatekeeper to Run Unsigned Payloads

A new variant of the multi-stage Shlayer malware known to target macOS users has been observed in the wild, now being capable to escalate privileges using a two-year-old technique and to disable the Gatekeeper protection mechanism to run unsigned second stage payloads. [...]

https://www.bleepingcomputer.com/news/security/shlayer-malware-disables-macos-gatekeeper-to-run-unsigned-payloads/
Ransomware Attacks Target MSPs to Mass-Infect Customers

Ransomware distributors have started to target managed service providers (MSPs) in order to mass-infect all of their clients in a single attack. Recent reports indicate that multiple MSPs have been hacked recently, which has led to hundreds, if not thousands, of clients being infected with the GandCrab Ransomware. [...]

https://www.bleepingcomputer.com/news/security/ransomware-attacks-target-msps-to-mass-infect-customers/
Microsoft Releases First Windows 10 20H1 Build 18836 To Skip Ahead Users

Microsoft has released the Windows 10 Insider Preview Build 18836, which is the first insider build in the 20H1 development branch. This build is available to Insiders in the Skip Ahead ring and is just a general bug fix without any new features. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-first-windows-10-20h1-build-18836-to-skip-ahead-users/
Coffee Meets Bagel Dating App Discloses Data Breach on Valentine's Day

As a Valentine's Day gift to all its users, online dating app Coffee Meets Bagel disclosed a data breach that contained user's email addresses and names. This data breach was discovered as part of a compilation of leaked credentials that was being sold on criminal marketplaces. [...]

https://www.bleepingcomputer.com/news/security/coffee-meets-bagel-dating-app-discloses-data-breach-on-valentines-day/
Collection of 127 Million Stolen Accounts Up for Sale on the Dark Web

A batch of 127 million records stolen in data breaches affecting eight companies was put up for sale on the Dream Market marketplace by a seller who goes by the name of "gnosticplayers" and asking the equivalent of $14,500 in bitcoin for the entire collection. [...]

https://www.bleepingcomputer.com/news/security/collection-of-127-million-stolen-accounts-up-for-sale-on-the-dark-web/