BleepingComputer
10.5K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
New Game Boy Emulator Has a Remote 'Cloud Gaming' Mode

A new Game Boy emulator written in Go has been released that offers the interesting ability of making your games accessible over the Internet using Telnet. While the online games are rendered using ANSI and are not as visually appealing, it illustrates how emulator developers can extend their features to the Internet. [...]

https://www.bleepingcomputer.com/news/gaming/new-game-boy-emulator-has-a-remote-cloud-gaming-mode/
U.S. Govt Issues Microsoft Office 365 Security Best Practices

The Cybersecurity and Infrastructure Security Agency (CISA) issued a set of best practices designed to help organizations to mitigate risks and vulnerabilities associated with migrating their email services to Microsoft Office 365. [...]

https://www.bleepingcomputer.com/news/security/us-govt-issues-microsoft-office-365-security-best-practices/
Fxmsp Chat Logs Reveal the Hacked Antivirus Vendors, AVs Respond

A report last week about Fxmsp hacker group claiming access to the networks and source code of three antivirus companies with offices in the U.S. generated from alleged victims statements that are disputed by the firm that sounded the alarm. [...]

https://www.bleepingcomputer.com/news/security/fxmsp-chat-logs-reveal-the-hacked-antivirus-vendors-avs-respond/
Adobe Says Upgrade Creative Cloud Apps or Risk 3rd Party Claims

On May 8th, 2019, Creative Cloud users have started receiving emails from Adobe stating that older versions of the products they are using have been discontinued and that users are no longer licensed to use them. For many of these developers, this not a reasonable request as they need to utilize older versions for certain projects. [...]

https://www.bleepingcomputer.com/news/software/adobe-says-upgrade-creative-cloud-apps-or-risk-3rd-party-claims/
Hackers Access Over 461,000 Accounts in Uniqlo Data Breach

Fast Retailing, the company behind multiple Japanese retail brands, announced that the UNIQLO Japan and GU Japan online stores have been hacked and third parties accessed 461,091 customer accounts following a credential stuffing attack. [...]

https://www.bleepingcomputer.com/news/security/hackers-access-over-461-000-accounts-in-uniqlo-data-breach/
Microsoft Fixes Critical Remote Desktop Flaw, Blocks Worm Malware

Microsoft patched today a critical Remote Code Execution vulnerability found in the Remote Desktop Services platform which can allow malicious actors to create malware designed to propagate between computers running vulnerable RDS installations. [...]

https://www.bleepingcomputer.com/news/security/microsoft-fixes-critical-remote-desktop-flaw-blocks-worm-malware/
New RIDL and Fallout Attacks Impact All Modern Intel CPUs

Multiple security researchers have released details about a new class of speculative attacks against all modern Intel processors. The attacks are different from and more dangerous than Meltdown and Spectre and their variations because they can leak data from CPU buffers, which is not necessarily present in caches. [...]

https://www.bleepingcomputer.com/news/security/new-ridl-and-fallout-attacks-impact-all-modern-intel-cpus/
Microsoft Releases May 2019 Office Updates With Security Fixes

Microsoft released the May 2019 Office Update today, which consists of 9 security updates and 25 non-security updates. As some of the Microsoft Office security updates resolve critical vulnerabilities, it is strongly advised to install them as soon as possible. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-may-2019-office-updates-with-security-fixes/
Microsoft's May 2019 Patch Tuesday Fixes 79 Vulnerabilities

Today is Microsoft's May 2019 Patch Tuesday, which means Windows admins are pouring themselves a drink (maybe two) and getting ready ti pull their hair out while testing the new patches and security updates released by Microsoft. Included in this month's updates are fixes for publicly disclosed or exploited vulnerabilities. [...]

https://www.bleepingcomputer.com/news/microsoft/microsofts-may-2019-patch-tuesday-fixes-79-vulnerabilities/
List of MDS Speculative Execution Vulnerability Advisories & Updates

Four new vulnerabilities have been discovered in Intel processors that can be exploited via speculative execution side-channel attacks called RIDL, Fallout, and ZombieLoad. These vulnerabilities allow attackers to steal passwords, cryptographic keys, or any other type of data to be loaded or stored in the memory of the CPU buffers. [...]

https://www.bleepingcomputer.com/news/security/list-of-mds-speculative-execution-vulnerability-advisories-and-updates/
Windows 10 Spectre 2 Mitigation Now Uses Retpoline By Default

If you currently have mitigations enabled for the Spectre Variant 2 (CVE-2017-5715) vulnerability, Microsoft has now enabled the Retpoline Spectre mitigation feature by default in Windows 10 version 1809 (October 2018 Update) for better performance. [...]

https://www.bleepingcomputer.com/news/security/windows-10-spectre-2-mitigation-now-uses-retpoline-by-default/
Google Hides Payment Privacy Settings Behind Special URL

It has been discovered that Google is hiding three Google Pay privacy settings unless you access the service's Settings screen through a special URL. These settings allow you to restrict whether Google Pay shares your creditworthiness, personal information, or Google Pay account information. [...]

https://www.bleepingcomputer.com/news/google/google-hides-payment-privacy-settings-behind-special-url/
Attackers Evade Detection By Randomizing TLS Handshake Ciphers

Cybercriminals are using a new method to evade detection to make sure that the traffic generated by their malicious campaigns is not being detected, a technique based on SSL/TLS signature randomization and dubbed cipher stunting. [...]

https://www.bleepingcomputer.com/news/security/attackers-evade-detection-by-randomizing-tls-handshake-ciphers/