BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Cisco Network Assurance Engine Bug Allows Login with Old Passwords

Cisco has issue a security advisory for Cisco Network Assurance Engine (NAE) Release 3.0(1) for a bug that causes password changes done via NAE to not be synchronized to the CLI of the associated device. This would allow a user to be able to gain access to a device via its CLI using the previous password. [...]

https://www.bleepingcomputer.com/news/security/cisco-network-assurance-engine-bug-allows-login-with-old-passwords/
OpenOffice Zero-Day Code Execution Flaw Gets Free Micropatch

A micropatch is now available for a zero-day OpenOffice code execution vulnerability which can be triggered via automated macro execution following a mouseover event when viewing a maliciously crafted ODT document. [...]

https://www.bleepingcomputer.com/news/security/openoffice-zero-day-code-execution-flaw-gets-free-micropatch/
Shlayer Malware Disables macOS Gatekeeper to Run Unsigned Payloads

A new variant of the multi-stage Shlayer malware known to target macOS users has been observed in the wild, now being capable to escalate privileges using a two-year-old technique and to disable the Gatekeeper protection mechanism to run unsigned second stage payloads. [...]

https://www.bleepingcomputer.com/news/security/shlayer-malware-disables-macos-gatekeeper-to-run-unsigned-payloads/
Ransomware Attacks Target MSPs to Mass-Infect Customers

Ransomware distributors have started to target managed service providers (MSPs) in order to mass-infect all of their clients in a single attack. Recent reports indicate that multiple MSPs have been hacked recently, which has led to hundreds, if not thousands, of clients being infected with the GandCrab Ransomware. [...]

https://www.bleepingcomputer.com/news/security/ransomware-attacks-target-msps-to-mass-infect-customers/
Microsoft Releases First Windows 10 20H1 Build 18836 To Skip Ahead Users

Microsoft has released the Windows 10 Insider Preview Build 18836, which is the first insider build in the 20H1 development branch. This build is available to Insiders in the Skip Ahead ring and is just a general bug fix without any new features. [...]

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-first-windows-10-20h1-build-18836-to-skip-ahead-users/
Coffee Meets Bagel Dating App Discloses Data Breach on Valentine's Day

As a Valentine's Day gift to all its users, online dating app Coffee Meets Bagel disclosed a data breach that contained user's email addresses and names. This data breach was discovered as part of a compilation of leaked credentials that was being sold on criminal marketplaces. [...]

https://www.bleepingcomputer.com/news/security/coffee-meets-bagel-dating-app-discloses-data-breach-on-valentines-day/
Collection of 127 Million Stolen Accounts Up for Sale on the Dark Web

A batch of 127 million records stolen in data breaches affecting eight companies was put up for sale on the Dream Market marketplace by a seller who goes by the name of "gnosticplayers" and asking the equivalent of $14,500 in bitcoin for the entire collection. [...]

https://www.bleepingcomputer.com/news/security/collection-of-127-million-stolen-accounts-up-for-sale-on-the-dark-web/
Cryptojacking Coinhive Miners Land on the Microsoft Store For the First Time

A batch of eight potentially unwanted applications (PUAs) were found on the Microsoft Store dropping malicious Monero (XMR) Coinhive cryptomining scripts, delivered with the help of Google's legitimate Google Tag Manager (GTM) library. [...]

https://www.bleepingcomputer.com/news/security/cryptojacking-coinhive-miners-land-on-the-microsoft-store-for-the-first-time/
18,000 Android Apps Track Users by Violating Advertising ID Policies

18K Android apps with tens or hundreds of millions of installs have been found to violate Google's Advertising ID policy guidance by collecting persistent device identifiers such as serial numbers, IMEI, WiFi MAC addresses, SIM card serial numbers, and sending them to mobile advertising related domains alongside ad IDs. [...]

https://www.bleepingcomputer.com/news/security/18-000-android-apps-track-users-by-violating-advertising-id-policies/
Google Fixing Chrome API to Prevent Incognito Mode Detection

When browsing the web with Google Chrome, some sites are using a method to determine if a visitor is in a regular browsing session or in incognito mode. As this can be considered a breach in privacy, Google will be changing how a particular API works so that web sites can no longer utilize this technique. [...]

https://www.bleepingcomputer.com/news/google/google-fixing-chrome-api-to-prevent-incognito-mode-detection/
Apple Requiring 2-Factor Authentication on Developer Account Holders

Users who are part of the Apple Developer program have started receiving emails that state they need to add 2-factor authentication to their accounts by February 27th, 2019. Otherwise, they will be locked out of their Developer accounts and be unable to access their Certificates, Identifiers, and Profiles. [...]

https://www.bleepingcomputer.com/news/apple/apple-requiring-2-factor-authentication-on-developer-account-holders/
The Week in Ransomware - February 15th 2019 - Attack on MSPs

It has been a really dead week with ransomware, which we are always happy to see. Not much new variants released, other than the standard ones such as Matrix and Dharma. The biggest news this week has been GandCrab affiliates targeting vulnerabilities in MSP software that allows them to infect all the clients they manage. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-february-15th-2019-attack-on-msps/
Google to Let you Link Directly to a Word or Phrase in Chrome

Chrome is adding a new feature to Chrome that lets you link directly to a word or phrase without the need of special markup on the web page. This will make it much easier to share a section of a page that is relevant to the person you are sending it to, rather than having them read the entire page. [...]

https://www.bleepingcomputer.com/news/google/google-to-let-you-link-directly-to-a-word-or-phrase-in-chrome/