BleepingComputer
10.3K subscribers
41 photos
24.5K links
Latest news and stories from BleepingComputer.com

From a bleeping computer to a working computer.
Download Telegram
Windows 10 Build 18343 Released to Insiders with Windows Sandbox Improvements

Windows 10 19H1 Build 18343 is now rolling out to the Windows Insiders in the Fast Ring with improvements for Windows Sandbox and general bug fixes. Windows 10 Build 18343 comes from the 19H1 development and changes in this release will be shipped to the public with Windows 10 April 2019 Update. [...]

https://www.bleepingcomputer.com/news/microsoft/windows-10-build-18343-released-to-insiders-with-windows-sandbox-improvements/
Tax Returns Exposed in TurboTax Credential Stuffing Attacks

Financial software company Intuit discovered that tax return info was accessed by an unauthorized party after an undisclosed number of TurboTax tax preparation software accounts were breached in a credential stuffing attack. [...]

https://www.bleepingcomputer.com/news/security/tax-returns-exposed-in-turbotax-credential-stuffing-attacks/
NY Governor Cuomo Calls For Investigation on Facebook Health Data Collection

New York Governor Andrew M. Cuomo stated that a number of state agencies including the Department of State and the Department of Financial Services will investigate Facebook health data acquisition practices exposed by The Wall Street Journal. [...]

https://www.bleepingcomputer.com/news/technology/ny-governor-cuomo-calls-for-investigation-on-facebook-health-data-collection/
B0r0nt0K Ransomware Wants $75,000 Ransom, Infects Linux Servers

A new ransomware called B0r0nt0K is encrypting victim's web sites and demanding a 20 bitcoin, or approximately $75,000, ransom. This ransomware is known to infect Linux servers, but may also be able to encrypt users running Windows. [...]

https://www.bleepingcomputer.com/news/security/b0r0nt0k-ransomware-wants-75-000-ransom-infects-linux-servers/
NVIDIA Patches Security Issues in GPU Display Driver for Windows, Linux

NVIDIA released a security update for the NVIDIA GPU Display Driver software designed to patch eight security issues that could lead to code execution, escalation of privileges, denial of service, or information disclosure on both Windows and Linux machines. [...]

https://www.bleepingcomputer.com/news/security/nvidia-patches-security-issues-in-gpu-display-driver-for-windows-linux/
Smart Homes at Risk Due to Unpatched Vulnerabilities, Weak Credentials

40.8% of smart homes have at least one device vulnerable to remote attacks, a third of them being vulnerable because of outdated software with unpatched security issues, while more than two-thirds are exposed by weak credentials. [...]

https://www.bleepingcomputer.com/news/security/smart-homes-at-risk-due-to-unpatched-vulnerabilities-weak-credentials/
Apex Legends Fans Targeted with Malware and Scam Campaigns

Apex Legends fans who want to play the game on mobile devices are being actively targeted by scam and malware campaigns which promise to deliver a playable version of the game ready to install on iOS and Android devices. [...]

https://www.bleepingcomputer.com/news/security/apex-legends-fans-targeted-with-malware-and-scam-campaigns/
Hackers Backdoor Cloud Servers to Attack Future Customers

A new vulnerability dubbed Cloudborne can allow attackers to implant backdoor implants in the firmware or BMC of bare metal servers that survive client reassignment in bare metal and general cloud services, leading to a variety of attack scenarios. [...]

https://www.bleepingcomputer.com/news/security/hackers-backdoor-cloud-servers-to-attack-future-customers/
Malvertising Attack Sneaks JavaScript Payload in Polyglot Images

A new malvertising attack observed in the wild relies on a less used technique to hide the malicious payload. The authors turned to polyglot images to add the JavaScript code that redirects to a page offering a fake reward. [...]

https://www.bleepingcomputer.com/news/security/malvertising-attack-sneaks-javascript-payload-in-polyglot-images/
Adobe Sends Emails About Retirement of Shockwave on April 9th

Adobe has started sending out emails to enterprise clients about the imminent retirement of Adobe Shockwave. These emails state that Adobe Shockwave player for Windows will no longer be available for download starting on April 9th 2019. [...]

https://www.bleepingcomputer.com/news/software/adobe-sends-emails-about-retirement-of-shockwave-on-april-9th/
Thunderclap Vulnerabilities Allow Attacks Using Thunderbolt Peripherals

Modern computers that come with a Thunderbolt interface and run Windows, macOS, Linux, or FreeBSD are vulnerable to a range of Direct Memory Access (DMA) attacks performed by potential attackers with physical access to the device using malicious peripherals. [...]

https://www.bleepingcomputer.com/news/security/thunderclap-vulnerabilities-allow-attacks-using-thunderbolt-peripherals/
28 Billion Credential Stuffing Attempts During Second Half of 2018

During the second half of 2018, between May and December 2018, roughly 28 billion credential stuffing attempts have been detected, with retail websites being the main target of credential abuse with 10 billion attempts. [...]

https://www.bleepingcomputer.com/news/security/28-billion-credential-stuffing-attempts-during-second-half-of-2018/