BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Collection of 127 Million Stolen Accounts Up for Sale on the Dark Web

A batch of 127 million records stolen in data breaches affecting eight companies was put up for sale on the Dream Market marketplace by a seller who goes by the name of "gnosticplayers" and asking the equivalent of $14,500 in bitcoin for the entire collection. [...]

https://www.bleepingcomputer.com/news/security/collection-of-127-million-stolen-accounts-up-for-sale-on-the-dark-web/
Cryptojacking Coinhive Miners Land on the Microsoft Store For the First Time

A batch of eight potentially unwanted applications (PUAs) were found on the Microsoft Store dropping malicious Monero (XMR) Coinhive cryptomining scripts, delivered with the help of Google's legitimate Google Tag Manager (GTM) library. [...]

https://www.bleepingcomputer.com/news/security/cryptojacking-coinhive-miners-land-on-the-microsoft-store-for-the-first-time/
18,000 Android Apps Track Users by Violating Advertising ID Policies

18K Android apps with tens or hundreds of millions of installs have been found to violate Google's Advertising ID policy guidance by collecting persistent device identifiers such as serial numbers, IMEI, WiFi MAC addresses, SIM card serial numbers, and sending them to mobile advertising related domains alongside ad IDs. [...]

https://www.bleepingcomputer.com/news/security/18-000-android-apps-track-users-by-violating-advertising-id-policies/
Google Fixing Chrome API to Prevent Incognito Mode Detection

When browsing the web with Google Chrome, some sites are using a method to determine if a visitor is in a regular browsing session or in incognito mode. As this can be considered a breach in privacy, Google will be changing how a particular API works so that web sites can no longer utilize this technique. [...]

https://www.bleepingcomputer.com/news/google/google-fixing-chrome-api-to-prevent-incognito-mode-detection/
Apple Requiring 2-Factor Authentication on Developer Account Holders

Users who are part of the Apple Developer program have started receiving emails that state they need to add 2-factor authentication to their accounts by February 27th, 2019. Otherwise, they will be locked out of their Developer accounts and be unable to access their Certificates, Identifiers, and Profiles. [...]

https://www.bleepingcomputer.com/news/apple/apple-requiring-2-factor-authentication-on-developer-account-holders/
The Week in Ransomware - February 15th 2019 - Attack on MSPs

It has been a really dead week with ransomware, which we are always happy to see. Not much new variants released, other than the standard ones such as Matrix and Dharma. The biggest news this week has been GandCrab affiliates targeting vulnerabilities in MSP software that allows them to infect all the clients they manage. [...]

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-february-15th-2019-attack-on-msps/
Google to Let you Link Directly to a Word or Phrase in Chrome

Chrome is adding a new feature to Chrome that lets you link directly to a word or phrase without the need of special markup on the web page. This will make it much easier to share a section of a page that is relevant to the person you are sending it to, rather than having them read the entire page. [...]

https://www.bleepingcomputer.com/news/google/google-to-let-you-link-directly-to-a-word-or-phrase-in-chrome/
2.7 Million Health-Related Calls, Sensitive Info Exposed for Six Years

A server used to store real-time recordings of phone calls made to the 1177 Swedish Healthcare Guide service for health care information was found completely exposed to the Internet, with no user or password to protect it. [...]

https://www.bleepingcomputer.com/news/security/27-million-health-related-calls-sensitive-info-exposed-for-six-years/
State Actor Behind Parliament Breach Says Australian Prime Minister

The computer network of Australia's Federal Parliament has been breached in a cyber attack which targeted the country's major political parties and carried out by a "sophisticated state actor" according to Prime Minister Scott Morrison. [...]

https://www.bleepingcomputer.com/news/security/state-actor-behind-parliament-breach-says-australian-prime-minister/
GandCrab Decrypter Available for v5.1, New Variant Already Out

A free file decryption tool is available for users whose computers got infected with the latest confirmed versions of GandCrab. It can unlock data encrypted by versions 4 through 5.1 of the malware, and some earlier releases of the threat. [...]

https://www.bleepingcomputer.com/news/security/gandcrab-decrypter-available-for-v51-new-variant-already-out/
North Korean APT Lazarus Targets Russian Entities with KEYMARBLE Backdoor

Bluenoroff, a subdivision of the North Korean sponsored APT group Lazarus, recently switched its sights to Russian entities as unveiled by a newly discovered campaign which uses malicious Office documents specifically crafted to target Russian organizations. [...]

https://www.bleepingcomputer.com/news/security/north-korean-apt-lazarus-targets-russian-entities-with-keymarble-backdoor/
Ukraine Announces Joint Exercises with EU to Fend Off Russian Cyber Threats

Ukraine will organize a number of joint exercises in the near future with the European Union (EU) to develop appropriate response models to possible Russian cyber threats designed to interfere in Ukrainian presidential elections that will be held on March 31 [...]

https://www.bleepingcomputer.com/news/security/ukraine-announces-joint-exercises-with-eu-to-fend-off-russian-cyber-threats/