BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
BEC Scammers Go After Employee Paychecks

A change has been noticed in the evolution of business email compromise (BEC) scams, with fraudsters tricking human resource departments into changing an employee's direct deposit information to divert paychecks into an account they control. [...]

https://www.bleepingcomputer.com/news/security/bec-scammers-go-after-employee-paychecks/
New York Privacy Bill Forces Businesses to Disclose Consumer Data Use

A bill known as the "Right to know act of 2019" was proposed by New York State Senator Brad Madison Hoylman on January 9 to amend the general business law so that consumers have the right to request personal information that has been collected by a company and is being disclosed to third-parties. [...]

https://www.bleepingcomputer.com/news/legal/new-york-privacy-bill-forces-businesses-to-disclose-consumer-data-use/
Microsoft Says Outlook Mobile Now Ready For Pentagon Use

Outlook for iOS and Android can now be used by Department of Defense and Office 365 US Government Community Cloud High customers after their architecture was updated to use native Microsoft sync technology with direct connections to the already compliant Exchange Online backend services [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-outlook-mobile-now-ready-for-pentagon-use/
Zero-Day Vulnerabilities Leave Smart Buildings Open to Cyber Attacks

A team of researchers discovered six zero-day vulnerabilities in protocols and individual components used in smart buildings. The flaws could be used to steal sensitive information, access or delete critical files, or perform malicious actions. [...]

https://www.bleepingcomputer.com/news/security/zero-day-vulnerabilities-leave-smart-buildings-open-to-cyber-attacks/
Djvu Ransomware Spreading New .TRO Variant Through Cracks & Adware Bundles

In December 2018, a new ransomware called Djvu, which could be a variant of STOP,  was released that has been heavily promoted through crack downloads & adware bundles. Originally, this ransomware would append a variation of the .djvu string as an extension to encrypted files, but a recent variant has switched to the .tro extension. [...]

https://www.bleepingcomputer.com/news/security/djvu-ransomware-spreading-new-tro-variant-through-cracks-and-adware-bundles/
Firefox 66 Lets You Configure Keyboard Shortcuts for Extensions

Firefox lets developers create keyboard shortcuts for their extension's functions, which are hard coded or possibly configurable depending on the extension. In Firefox 66, Mozila is making extension keyboard shortcuts configurable by a user directly from the about:addons page.  [...]

https://www.bleepingcomputer.com/news/software/firefox-66-lets-you-configure-keyboard-shortcuts-for-extensions/
Bug in Fortnite Authentication Left Accounts Open to Take Over

Weaknesses in Epic Games' authentication process for the highly popular Fortnite left gamers' accounts exposed to take over risks. An attacker could have stolen login tokens by just tricking the victim into clicking a link. [...]

https://www.bleepingcomputer.com/news/security/bug-in-fortnite-authentication-left-accounts-open-to-take-over/
NVIDIA Tesla T4 GPUs in Beta on the Google Cloud Platform

The Google Cloud Platform is the first cloud vendor to provide its customers with access to NVIDIA's professional Tesla T4 GPU, via a beta program with instances available for customers from Brazil, India, Netherlands, Singapore, Tokyo, and the United States. [...]

https://www.bleepingcomputer.com/news/hardware/nvidia-tesla-t4-gpus-in-beta-on-the-google-cloud-platform/
MageCart Skimmer Hits Hundreds of Sites In Ad Supply Chain Attack

Most attackers who utilize malicious scripts known as MageCart to steal payment information usually try to keep a low profile to stay undetected on the sites they compromise. New research shows how one MageCart criminal group recently compromised an advertising script to inject MageCart into hundreds of sites at the same time. [...]

https://www.bleepingcomputer.com/news/security/magecart-skimmer-hits-hundreds-of-sites-in-ad-supply-chain-attack/
LoJax Command and Control Domains Still Active

Security researchers have uncovered new details about the infrastructure used by LoJax UEFI rootkit used in attacks from APT28. The analysis revealed two command and control (C2) servers were still active in early 2019. [...]

https://www.bleepingcomputer.com/news/security/lojax-command-and-control-domains-still-active/
EU Copyright Directive to Turn Google into Ghost Town

Google's search results will look like a deserted town according to the search giant, with no article titles, no images, and no news summaries if the SERP templates following the EU Copyright Directive provisions will go live [...]

https://www.bleepingcomputer.com/news/google/eu-copyright-directive-to-turn-google-into-ghost-town/