BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Samsung Galaxy S10 Face Recognition Can Easily Be Bypassed

The face recognition-based screen lock feature in the Samsung Galaxy S10 can be easily fooled using a photo or a video of the owner as shown by multiple reports coming from customers, experts and tech reviewers. [...]

https://www.bleepingcomputer.com/news/security/samsung-galaxy-s10-face-recognition-can-easily-be-bypassed/
New "Final Warning" Sextortion Emails State Adult Sites Infected You

A new sextortion email campaign with a subject of "This is a final warning" is underway that states a hacker infected the recipient's computer while they were visiting an adult web site and demand an extortion payment or the video will be released to family and friends. [...]

https://www.bleepingcomputer.com/news/security/new-final-warning-sextortion-emails-state-adult-sites-infected-you/
Medical IoT Devices with Outdated Operating Sytems Exposed to Hacking

Medical IoT (IoMT) devices are in many cases left exposed to attacks because of outdated or legacy operating systems which, in many cases, are very easy to hack into and expose a throve of sensitive patient data, highly sought over on the black market. [...]

https://www.bleepingcomputer.com/news/security/medical-iot-devices-with-outdated-operating-sytems-exposed-to-hacking/
Google Chrome to Block Drive-By-Downloads from Ad Frames

Google is planning to add automated prevention of all downloads initiated from within ad frames which lack user activation, as part of an effort to boost the security of Chrome users by blocking possibly malicious drive-by-downloads. [...]

https://www.bleepingcomputer.com/news/security/google-chrome-to-block-drive-by-downloads-from-ad-frames/
Yatron Ransomware Plans to Spread Using EternalBlue NSA Exploits

A new Ransomware-as-a-Service called Yatron is being promoted on Twitter that plans on using the EternalBlue and DoublePulsar exploits to spread to other computer on a network. This ransomware will also attempt to delete encrypted files if a payment has not been made in 72 hours. [...]

https://www.bleepingcomputer.com/news/security/yatron-ransomware-plans-to-spread-using-eternalblue-nsa-exploits/
Microsoft Testing Android Screen Mirroring on Windows 10 PCs

Microsoft has added beta support Android app screen mirroring in Windows 10 Build 1803 or newer for the latest Insider builds. At the moment the feature is only compatible with a limited number of devices but it will be supported by all smartphones running Android version 7.0 or later. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-testing-android-screen-mirroring-on-windows-10-pcs/
Malware Spreads As a Worm, Uses Cryptojacking Module to Mine for Monero

A modular malware with worm capabilities exploits known vulnerabilities in servers running ElasticSearch, Hadoop, Redis, Spring, Weblogic, ThinkPHP, and SqlServer to spread from one server to another and mine for Monero cryptocurrency. [...]

https://www.bleepingcomputer.com/news/security/malware-spreads-as-a-worm-uses-cryptojacking-module-to-mine-for-monero/
Microsoft Releases the March 2019 Updates for Office

Microsoft released the March 2019 Office Update today, which consists of 6 security updates and 28 non-security updates. A some of these updates resolve critical vulnerabilities, it is strongly advised that you install them as soon as possible. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-the-march-2019-updates-for-office/
Windows 10 March 2019 Cumulative Updates Released With Fixes

Windows 10 March 2019 cumulative updates are now rolling out to the compatible devices with fixes and improvements for core components. The update includes both security and non-security improvements and fixes. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-march-2019-cumulative-updates-released-with-fixes/
Windows 10 Insider Preview Build 18356 Released Along With Phone Screen Feature

Microsoft has released Windows 10 Insider Preview Build 18356 (19H1) to Insiders in the Fast ring. This release is mostly bug fixes, including numerous Night Light bug fixes and a fix for KERNEL_SECURITY_VIOLATION GSODs. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-insider-preview-build-18356-released-along-with-phone-screen-feature/
North Korean Hackers Behind $571M Crypto Heists Says UN Report

North Korean backed hacking groups were behind multiple cyberattacks impacting financial institutions and cryptocurrency exchanges as detailed in a report issued by a panel of experts for the United Nations (UN) Security Council. [...]

https://www.bleepingcomputer.com/news/security/north-korean-hackers-behind-571m-crypto-heists-says-un-report/
CCleaner Professional Adds Software Updater Feature

Piriform has released CCleaner v5.55 today, which for Professional users now includes a Software Updater feature that will check if installed 3rd party applications are running the latest version. [...]

https://www.bleepingcomputer.com/news/security/ccleaner-professional-adds-software-updater-feature/
Unsecured API Leads to 'Yelp for Conservatives' App Data Leak

The API of the 63Red Safe mobile app known as "Yelp for conservatives" was found by French security researcher Robert Baptiste wide open, with no authentication needed to access and view the data stored within the app's database. [...]

https://www.bleepingcomputer.com/news/security/unsecured-api-leads-to-yelp-for-conservatives-app-data-leak/
Microsoft March 2019 Patch Tuesday Includes Fixes for 64 Vulnerabilities

Today is Microsoft's March 2019 Patch Tuesday, which means it is time to get those security updates installed. Included in this month's are fixed for two vulnerabilities that are known to be actively exploited in the wild. [...]

https://www.bleepingcomputer.com/news/security/microsoft-march-2019-patch-tuesday-includes-fixes-for-64-vulnerabilities/
Windows 7 Gets SHA-2 Support To Enable Future Updates

An update was released today that adds SHA-2 code signing support to Windows 7 SP1 and Windows Server 2008 R2 SP1. If this update is not installed, these Windows operating systems will no longer be able to receive Windows updates starting on July 16th, 2019. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-7-gets-sha-2-support-to-enable-future-updates/
Wordpress 5.1.1 Fixes XSS Vulnerability Leading to Website Takeovers

The WordPress team fixed a software flaw introduced in the 5.1 release that could allow potential attackers to perform stored cross-site scripting (XSS) attacks with the help of maliciously crafted comments on WordPress websites with the comments module enabled. [...]

https://www.bleepingcomputer.com/news/security/wordpress-511-fixes-xss-vulnerability-leading-to-website-takeovers/