BleepingComputer
10.6K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
YouTube Cryptocurrency Videos Pushing Info-Stealing Trojan

A scam and malware campaign is underway on YouTube that uses videos to promote a "bitcoin generator" tool that promises to generate free bitcoins for its users. In reality, this scam is pushing the Qulab information-stealing and clipboard hijacking Trojan. [...]

https://www.bleepingcomputer.com/news/security/youtube-cryptocurrency-videos-pushing-info-stealing-trojan/
Windows 10 1903 Cumulative Update KB4497935 Released With Fixes

Microsoft has started to roll out a new cumulative update for Windows 10 version 1903 that includes numerous fixes for the operating system. This update was released to Windows Insiders last week to test before being made publicly available today. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-1903-cumulative-update-kb4497935-released-with-fixes/
Bitcoin Blender Exits Cryptocurrency Mixing On Its Own Terms

The long run of Bitcoin Blender cryptocurrency mixing service has reached an end this week as the business quickly shut down after a short announcement on the website's front page that asked customers to withdraw their funds. [...]

https://www.bleepingcomputer.com/news/security/bitcoin-blender-exits-cryptocurrency-mixing-on-its-own-terms/
POS Malware Steals Payment Info From 103 Checkers Restaurants

The Checkers and Rally's chain of double drive-thru restaurants disclosed a security breach which allowed attackers to steal payment card data from customers after infecting the point-of-sale (POS) systems in 103 locations from 20 states with malware. [...]

https://www.bleepingcomputer.com/news/security/pos-malware-steals-payment-info-from-103-checkers-restaurants/
Google Targeting Deceptive Install Tactics for Chrome Extensions

Google has announced that they will be removing extensions from the Chrome Web Store that are installed using misleading and deceptive installation tactics. This is being done to further protect Chrome users from the unending barrage of unwanted extensions being promoted online. [...]

https://www.bleepingcomputer.com/news/google/google-targeting-deceptive-install-tactics-for-chrome-extensions/
Compromised Docker Hosts Use Shodan to Infect More Victims

Hackers are scanning for Docker hosts with exposed APIs to use them for cryptocurrency mining by deploying malicious self-propagating Docker images infected with Monero miners and scripts that make use of Shodan to find other vulnerable targets. [...]

https://www.bleepingcomputer.com/news/security/compromised-docker-hosts-use-shodan-to-infect-more-victims/
Windows 10 v1903 Upgrade Blocked Due to Some Intel Drivers

Installing the Windows 10 May 2019 Update is blocked on some computers with Intel display and display audio drivers after Microsoft and Intel discovered driver compatibility issues with the Windows 10 version 1903 release. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-v1903-upgrade-blocked-due-to-some-intel-drivers/
Phishing Email States Your Office 365 Account Will Be Deleted

A new phishing campaign is underway that pretends to be from the "Office 365 Team" warning you that your email account cancellation has been approved and that all your email will be deleted unless you cancel the request within the hour. [...]

https://www.bleepingcomputer.com/news/security/phishing-email-states-your-office-365-account-will-be-deleted/
Microsoft Warns Users Again to Patch Wormable BlueKeep Flaw

Microsoft issued a second warning for users of older Windows releases to patch their systems to block potential attackers from abusing the critical Remote Desktop Services (RDS) remote code execution vulnerability dubbed BlueKeep. [...]

https://www.bleepingcomputer.com/news/security/microsoft-warns-users-again-to-patch-wormable-bluekeep-flaw/
85.4GB Database Exposes Hotels' Internal Security Information

An unprotected server exposed for an unknown period security-related event logs and records of various hotel brands. The info originated from open-source intrusion detection systems (IDS) Wazuh handled by a hotel and resort management company. [...]

https://www.bleepingcomputer.com/news/security/854gb-database-exposes-hotels-internal-security-information/
Zero-Day Flaw in Windows 10 Task Scheduler Gets Micropatch

An unpatched local privilege escalation zero-day vulnerability in Windows 10 received a temporary patch today. The fix is delivered through the 0patch platform and can be applied on systems without rebooting them.. [...]

https://www.bleepingcomputer.com/news/security/zero-day-flaw-in-windows-10-task-scheduler-gets-micropatch/
Citrix Sued For Not Securing Employee Info Before Data Breach

A class action complaint was filed by an ex-employee of Citrix for damages suffered following the security breach which allowed hackers to access Citrix's internal assets for roughly six months and to steal sensitive personal information of both current and former employees. [...]

https://www.bleepingcomputer.com/news/security/citrix-sued-for-not-securing-employee-info-before-data-breach/
Sodinokibi Ransomware Pushed via Foreclosure Warning Spam

A malspam campaign targeting potential German victims is actively distributing Sodinokibi ransomware via spam emails disguised as foreclosure notifications with malicious attachments which pose as foreclosure notifications. [...]

https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-pushed-via-foreclosure-warning-spam/
NVIDIA Fixes High Severity GeForce Experience Vulnerabilities

NVIDIA issued a security update for the Windows NVIDIA GeForce Experience (GFE) software to patch two vulnerabilities that could make it possible for potential local attackers to launch attacks that may lead to code execution, escalation of privileges, and denial-of-service (DoS). [...]

https://www.bleepingcomputer.com/news/security/nvidia-fixes-high-severity-geforce-experience-vulnerabilities/
What do you think of this channel? Asking for a friend.
Maze Ransomware Says Computer Type Determines Ransom Amount

A variant of the Maze Ransomware, otherwise known as the ChaCha Ransomware, has been spotted being distributed by the Fallout exploit kit. An interesting feature of this ransomware is that it says the ransom amount will be different depending on whether the victim is a home computer, server, or workstation. [...]

https://www.bleepingcomputer.com/news/security/maze-ransomware-says-computer-type-determines-ransom-amount/
The Facebook CTF 2019 Event is Starting in 30 Minutes

Tonight at 8 PM EST, Facebook will be kicking off their 2019 Capture the Flag event where security researchers, professionals, and enthusiasts compete to be the fastest to solve the most puzzles in order to win cash prizes and prestige. [...]

https://www.bleepingcomputer.com/news/security/the-facebook-ctf-2019-event-is-starting-in-30-minutes/