BleepingComputer
10.4K subscribers
41 photos
24.6K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Critical Infrastructure & Supply Chain Remain Highly Vulnerable to Attacks

Additionally, cybercriminals have been targeting the commercial sector with as much aggression and skill as their attacks against the government. Unfortunately, some attacks against the government. Unfortunately, some attacks against corporations have national security ramifications, a fact not yet fully realized by all businesses. [...]

https://www.bleepingcomputer.com/news/security/critical-infrastructure-and-supply-chain-remain-highly-vulnerable-to-attacks/
Windows 10 Build 18267 Released With a New Enhanced Mode for Search Indexer

Microsoft has released the Windows 10 Insider Preview Build 18267 (19H1) to insiders in both the Fast and Skip Ahead rings. This build contains input and accessibility improvements. It also contains a new feature called "Enhanced Mode" for the Search Indexer. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-build-18267-released-with-a-new-enhanced-mode-for-search-indexer/
Unusual Remote Execution Bug in Cisco WebEx Discovered by Researchers

While remote code execution vulnerabilities are pretty common, a new one discovered in Cisco's WebEx online and video collaboration software is definitely different. That is because users can remotely execute commands through a component of the WebEx client even when WebEx does not listen for remote connections. [...]

https://www.bleepingcomputer.com/news/security/unusual-remote-execution-bug-in-cisco-webex-discovered-by-researchers/
Windows 10 KB4462933 Cumulative Update Released With Fixes and Improvements

Windows 10 Build 17134.376 is currently rolling out via Windows Update or you can download the patch directly from Microsoft's Update Catalog website. Windows 10 Build 17134.376 comes with a huge changelog and it includes several improvements that you may not notice.  [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-kb4462933-cumulative-update-released-with-fixes-and-improvements/
Malware Distributors Adopt DKIM to Bypass Mail Filters

A US-CERT alert provided recommendations on how businesses can mitigate their exposure to the Emotet Trojan. Unfortunately, it looks like criminals also reading the US-CERT's warnings as they have adopted new techniques to bypass these recommendations. [...]

https://www.bleepingcomputer.com/news/security/malware-distributors-adopt-dkim-to-bypass-mail-filters/
Microsoft Acknowledges Zip File Overwrite Bug - Fix Coming in November

In a post to the Microsoft Answers forum, Microsoft has acknowledged the built-in zip bug and has stated that it will be fixed in an early November. This fix will most likely be pushed out via a cumulative update or via Microsoft's November Patch Tuesday updates. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-acknowledges-zip-file-overwrite-bug-fix-coming-in-november/
Trivial Bug in X..Org Gives Root Permission on Linux and BSD Systems

A vulnerability that is trivial to exploit allows privilege escalation to root level on Linux and BSD distributions using X.Org server, the open source implementation of the X Window System that offers the graphical environment. [...]

https://www.bleepingcomputer.com/news/security/trivial-bug-in-xorg-gives-root-permission-on-linux-and-bsd-systems/
The Week in Ransomware - October 26th 2018 - Decryptors, RaaS, and More

We have had quite a bit of interesting news this week regarding ransomware. First we had the Kraken Cryptor deciding to connect to BleepingComputer.com during different stages of the encryption process, then we had a decryptor released by Bitdefender for GandCrab v1, v4, and v5, and finally a new FilesLocker rasnomware as a service. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-october-26th-2018-decryptors-raas-and-more/
Exposed Docker APIs Continue to Be Used for Cryptojacking

Trend Micro has recently spotted an attacker that is scanning for exposed Docker Engine APIs and utilizing them to deploy containers that download and execute a coin miner. These containers then use scripts to spread to other systems. [...]

https://www.bleepingcomputer.com/news/security/exposed-docker-apis-continue-to-be-used-for-cryptojacking/
Microsoft Sandboxes Windows Defender

As the infosec community talked about potential cyber attacks leveraging vulnerabilities in antivirus products, Microsoft took notes and started to work on a solution. The company announced that its Windows Defender can run in a sandbox. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-sandboxes-windows-defender/
Windows 10 Bug Allowed UWP Apps Full Access to File System

A bug in Windows 10 allowed UWP apps (Universal Windows Platform) to have access to the entire file system in Windows without permission from the user. This could have allowed a malicious app to access any data stored on the computer without the knowledge or consent of the user. [...]

https://www.bleepingcomputer.com/news/security/windows-10-bug-allowed-uwp-apps-full-access-to-file-system/