FILTERED

16+ entries
  • BleepingComputer

    CISA orders feds to patch actively exploited Dell flaw within 3 days

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems within three days against a maximum-severity Dell vulnerability that has been under active exploitation since mid-2024. [...]

    Vulnerability
    USA
  • BleepingComputer

    How infostealers turn stolen credentials into real identities

    Infostealer dumps increasingly tie stolen credentials to real identities, linking usernames, cookies, and behavior across personal and enterprise accounts. Specops explains how analyzing 90,000 dumps shows reuse fuels enterprise risk and how continuous AD scanning disrupts that cycle. [...]

  • BleepingComputer

    Texas sues TP-Link over Chinese hacking risks, user deception

    Texas sued networking giant TP-Link Systems, accusing the company of deceptively marketing its routers as secure while allowing Chinese state-backed hackers to exploit firmware vulnerabilities and access users' devices. [...]

    Vulnerability
  • BleepingComputer

    Hackers target Microsoft Entra accounts in device code vishing attacks

    Threat actors are targeting technology, manufacturing, and financial organizations in campaigns that combine device code phishing and voice phishing (vishing) to abuse the OAuth 2.0 Device Authorization flow and compromise Microsoft Entra accounts. [...]

    Phishing
  • BleepingComputer

    Critical infra Honeywell CCTVs vulnerable to auth bypass flaw

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking. [...]

    Vulnerability
    USA
  • BleepingComputer

    Telegram channels expose rapid weaponization of SmarterMail flaws

    Underground Telegram channels shared SmarterMail exploit PoCs and stolen admin credentials within days of disclosure. Flare explains how monitoring these communities reveals rapid weaponization of CVE-2026-24423 and CVE-2026-23760 tied to ransomware activity. [...]

    Ransomware
    Vulnerability
  • BleepingComputer

    Microsoft says bug causes Copilot to summarize confidential emails

    Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely on to protect sensitive information. [...]

— END OF FEED —