BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Cryptojacking Still a Foreign Concept for Many Security Pros

For over 57% of the 150 cybersecurity professionals surveyed by Exabeam the concept of cryptojacking is not something they are acquainted with, while roughly 65% said that they are also unfamiliar with shadow mining. [...]

https://www.bleepingcomputer.com/news/security/cryptojacking-still-a-foreign-concept-for-many-security-pros/
Dozens of Credit Card Info Skimming Scripts Infect Thousands of Sites

Malicious web code that Magecart groups use to steal payment card data from online stores is bustling business on underground forums. There are at least 38 unique families of such scripts, some more advanced than others, but each with multiple custom variants under their belt. [...]

https://www.bleepingcomputer.com/news/security/dozens-of-credit-card-info-skimming-scripts-infect-thousands-of-sites/
Georgia Tech Data Breach Exposes Info for 1.3 Million People

Georgia Tech announced yesterday that a vulnerability in a web application allowed an attacker to gain access to the personal information of up to 1.3 million students, college applications, staff, and faculty members. [...]

https://www.bleepingcomputer.com/news/security/georgia-tech-data-breach-exposes-info-for-13-million-people/
Insider Attacks More Common, Harder to Detect After Cloud Migration

Insider attacks are becoming more and more prevalent each year as 73% of information of IT professionals told Bitglass, while 59% also stated that their companies have also gone through at least one such incident during the past year. [...]

https://www.bleepingcomputer.com/news/security/insider-attacks-more-common-harder-to-detect-after-cloud-migration/
NVIDIA Fixes Flaws in Linux4Tegra Driver for Jetson AI Supercomputers

NVIDIA released a security update for the Jetson TX1 and TX2 to patch vulnerabilities discovered in the Linux for Tegra driver package that could enable local attackers with basic user privileges to elevate privileges and to perform privilege escalation, denial-of-service (DoS) or information disclosure attacks. [...]

https://www.bleepingcomputer.com/news/security/nvidia-fixes-flaws-in-linux4tegra-driver-for-jetson-ai-supercomputers/
540 Mllion Facebook User Records Leaked by Public Amazon S3 Buckets

More than 540 million records of Facebook users were exposed by publicly accessible Amazon S3 buckets used by two third-party apps to store user data such as plain text app passwords, account names, user IDs, interests, relationship status, and more. [...]

https://www.bleepingcomputer.com/news/security/540-mllion-facebook-user-records-leaked-by-public-amazon-s3-buckets/
Financial Mobile Apps Fail to Follow Proper Security Standards

Financial mobile apps come with large numbers of vulnerabilities stemming from a dangerous lack of security controls and insecure coding practices, according to a report prepared by advisory firm Aite Group for Arxan. [...]

https://www.bleepingcomputer.com/news/security/financial-mobile-apps-fail-to-follow-proper-security-standards/
New Xwo Web Scanner Helps MongoLock Ransomware Find Victims

Code and infrastructure from two known malware families have been observed with a new threat named Xwo, which helps operators of the MongoLock ransomware discover unprotected web services reachable over the internet. [...]

https://www.bleepingcomputer.com/news/security/new-xwo-web-scanner-helps-mongolock-ransomware-find-victims/
CIA Exortion Scams Using SatoshiBox to Sell Alleged Proof for $500

The CIA extortion scams continue to evolve in order to squeeze as much money out of a victim as they can. In a new variant discovered by researchers, the extortion emails are now selling alleged proof on Satoshi Box for $500 that show you are part of the CIA investigation. [...]

https://www.bleepingcomputer.com/news/security/cia-exortion-scams-using-satoshibox-to-sell-alleged-proof-for-500/
London Blue Scammers Extend Operation, Attack Targets in Asia

Over the past five months, the London Blue cybercriminal group has been running business email compromise (BEC) scams against employees in Asia working for companies based mostly in the United States, Australia or Europe. [...]

https://www.bleepingcomputer.com/news/security/london-blue-scammers-extend-operation-attack-targets-in-asia/
Windows 10 1809 Changed the Default Removal Policy for External Drives

The default removal policy for external storage media was changed by Microsoft in Windows 10 version 1809 from "Better performance" to "Quick removal" which, for some users, may translate into faster removal times with degraded performance. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-1809-changed-the-default-removal-policy-for-external-drives/
Windows 10 May 2019 Update Announced, Insiders Get it First

Microsoft has officially announced that the Windows 10 build 1903 feature update will be called the May 2019 Update. This update will be released to Windows Insiders first, who will test it for a month before it is made publicly available in May. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-may-2019-update-announced-insiders-get-it-first/
Microsoft Is Redesigning the Windows 10 Update Experience

The Windows 10 May 2019 Update will be available in the Release Preview Ring of the Windows Insider Program starting next week and will add a number of new features designed to put its users in control of how monthly and features updates are installed. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-is-redesigning-the-windows-10-update-experience/