Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
The Future of Age Verification: Your Face Never Leaves Your Device

1mo ago · bleeping-computer

The article discusses the growing implementation of age verification laws worldwide and highlights concerns around biometric data privacy. Incode Technologies introduces On-Device Age Estimation, a privacy-preserving solution where facial analysis occurs locally on the user's device, ensuring faces are never transmitted or stored. The company also emphasizes its $100 million commitment to privacy-enhancing technologies and anti-fraud collaboration without centralized data pooling. This approach aims to meet compliance requirements while mitigating risks of data breaches and increasing consumer trust.

Abbott Laboratories probes two cyber incidents amid extortion claims

1mo ago · bleeping-computer

Abbott Laboratories is investigating two unrelated cyber incidents. The first involves the ShinyHunters extortion gang, which claims to have accessed legacy Exact Sciences systems via a vishing attack compromising Microsoft Entra SSO credentials, exfiltrating sensitive customer and internal data. The second incident involves a threat actor named ShadowByt3$, who claims unauthorized access to Abbott's LabCentral portal using compromised customer credentials, allegedly stealing technical and regulatory documents. Abbott states that no critical operations were impacted and disputes claims that sensitive data was exposed in the LabCentral incident.

1 IoCs 1 Actors
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

1mo ago · bleeping-computer

A vulnerability named HollowByte allows unauthenticated attackers to cause a denial-of-service condition on OpenSSL servers by sending an 11-byte malicious payload during the TLS handshake. The flaw stems from improper memory allocation based on unvalidated message length headers, leading to memory bloat and heap fragmentation. Although the issue has been silently patched in OpenSSL versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, affected systems remain at risk until updated, particularly given the widespread use of OpenSSL in web servers, runtimes, and databases.

Inside the Search for "Clean" Residential Proxies for Carding

1mo ago · bleeping-computer

Cybercriminals involved in carding are increasingly relying on 'clean' residential proxies to bypass fraud detection systems, but these proxies alone are no longer sufficient. They are now part of a broader identity-simulation strategy that includes matching geographic data, device fingerprints, and browser profiles to stolen identity information. As financial services improve detection, carders face challenges with proxy reputation degradation and provider restrictions, leading to a growing demand for finance-compatible proxy services.

2 IoCs
Ernst & Young discloses data breach after support system hack

1mo ago · bleeping-computer

Ernst & Young disclosed a data breach resulting from the compromise of a third-party support ticket system used by its IT personnel. The breach occurred between March 28 and April 12, during which an unauthorized party accessed and downloaded documents containing personal and financial data related to tax filings. The company detected anomalous activity on April 23, launched an investigation with external cybersecurity experts, and has since secured its systems. No threat actor has claimed responsibility, and there is no evidence of data misuse to date.

New Windows LegacyHive zero-day gives hackers admin privileges

1mo ago · bleeping-computer

A security researcher known as Nightmare Eclipse has released a Windows zero-day exploit named LegacyHive, which enables privilege escalation on fully patched systems by exploiting a flaw in the Windows User Profile Service. The proof-of-concept requires additional user credentials to limit weaponization, but successful exploitation allows non-admin users to manipulate registry hives and achieve automatic code execution upon administrator login. Microsoft has not yet assigned a CVE to this vulnerability, and the company has issued warnings against malicious use of such disclosures.

1 IoCs
CISA urges immediate action on actively exploited Fortinet flaws

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to urgently patch two actively exploited critical vulnerabilities in Fortinet's FortiSandbox platform, identified as CVE-2026-39808 and CVE-2026-25089. These flaws allow unauthenticated remote code execution via command injection with no user interaction required. Exploitation in the wild has been confirmed by threat intelligence firm Defused, prompting CISA to add the vulnerabilities to its known exploited catalog. Agencies must remediate by July 19, 2026, per Binding Operational Directive 26-04.

US charges two over laundering $43 million from investment fraud

1mo ago · bleeping-computer

U.S. authorities charged Zhuoying Chen and Haojie Zhang for allegedly managing a money laundering network that processed at least $43 million from cyber-enabled investment fraud scams. The funds originated from 'pig butchering' or romance baiting schemes, where victims were lured into fraudulent investment opportunities via social media and messaging platforms. The defendants used 140 bank accounts under 45 shell companies to transfer stolen funds to China. This case highlights the growing scale of investment fraud, which accounted for 49% of scam incidents in the FBI's 2025 Internet Crime Report.

Windows Server 2022 reach end of mainstream support in 90 days

1mo ago · bleeping-computer

Microsoft has announced that Windows Server 2022 will reach the end of mainstream support on October 13, 2026, transitioning to extended support with continued security updates until 2031. Organizations are advised to upgrade to Windows Server 2025, the latest Long-Term Servicing Channel release, to remain protected and supported. The article highlights Microsoft's lifecycle policy and recent extensions to hotpatching and extended security updates for certain editions.

New ClickLock macOS malware traps users into revealing login password

1mo ago · bleeping-computer

A new macOS malware named ClickLock targets users through social engineering to steal login credentials, cryptocurrency assets, browser data, and password manager information. The malware forces victims into entering their system password by displaying fake authentication dialogs and terminating critical system processes. It establishes persistence via LaunchAgents, exfiltrates data through Telegram, and deploys a persistent backdoor using GSocket for remote access. The malware leverages compromised legitimate domains and evades detection by self-deleting modules and clean reputations of host infrastructure.

2 IoCs
Claude Chrome extension flaw lets malicious extensions trigger AI actions

1mo ago · bleeping-computer

A vulnerability in Anthropic's Claude for Chrome extension allows malicious browser extensions to trigger predefined AI workflows by simulating untrusted click events. The flaw arises because the extension fails to validate the Event.isTrusted property, enabling unauthorized execution of actions in connected services like Gmail, Google Docs, Calendar, and Salesforce. Although the issue requires a malicious extension already installed by the user, it can abuse Claude's authenticated access to sensitive platforms without additional user consent.

Coca-Cola says Fairlife ransomware attack halts US dairy production

1mo ago · bleeping-computer

The Coca-Cola Company disclosed that its Fairlife dairy subsidiary suffered a ransomware attack, leading to the temporary suspension of production across U.S. facilities. The attack impacted production-related systems, though product safety remains unaffected. Investigation is ongoing, with outside cybersecurity experts and law enforcement involved. No ransomware group has claimed responsibility, and details on data exfiltration or extortion remain undisclosed.

New OkoBot framework deploys 20 payloads to steal data, crypto

1mo ago · bleeping-computer

A new malicious framework named OkoBot has been active since January 2026, delivering over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and malicious GitHub repositories hosting trojanized software. The infection chain begins with the TookPS PowerShell script, which installs an SSH bot to deploy further modules. Victims are primarily in Brazil, with secondary targets in Vietnam, Canada, Mexico, and Turkey, and evidence suggests the threat actor may be Russian-speaking due to geoblocking and code comments.

7 IoCs
Russian hackers trojanize WebEx, Zoom apps to push Starland malware

1mo ago · bleeping-computer

A Russian financially motivated threat actor, UAT-11795, has been conducting attacks since at least June 2025 by distributing trojanized installers of legitimate software such as WebEx, Zoom, and MobaXterm to deploy the Starland RAT. The malware establishes persistence, performs reconnaissance, steals credentials and cryptocurrency, and can deploy additional payloads like CastleStealer and Remcos RAT. The campaign targets users in the U.S., Germany, Romania, and Venezuela, using sophisticated techniques including registry manipulation, sandbox detection, and encrypted C2 communications via a PowerShell framework called WLDR.

1 IoCs
CISA orders feds to patch actively exploited Oracle flaw by Saturday

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated federal agencies to patch a critical vulnerability, CVE-2026-46817, in Oracle E-Business Suite (EBS) by July 18, 2026, due to active exploitation in the wild. The flaw resides in the File Transmission component of Oracle Payments and allows unauthenticated attackers to take over systems via HTTP. Threat intelligence firm Defused confirmed exploitation after observing attacks on honeypots, despite the absence of public proof-of-concept code. CISA emphasizes prompt patching to prevent compromise of federal systems.

Windows 11 24H2 Home and Pro reach end of support in 90 days

1mo ago · bleeping-computer

Microsoft has announced that Windows 11 24H2 Home and Pro editions will reach end of support on October 13, 2026, after which they will no longer receive security or non-security updates. This increases the risk of unpatched vulnerabilities being exploited on unupdated systems. Users are advised to upgrade to Windows 11 25H2 to remain protected against emerging threats.

Scattered Spider members behind TfL hack get five years in prison

1mo ago · bleeping-computer

Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to five years and six months in prison for their involvement in the August 2024 breach of Transport for London (TfL). The attack disrupted critical internal systems, forced 27,000 employees to reset passwords, and led to the theft of customer data. The group is also linked to over 120 network intrusions globally, including attacks on U.S. healthcare providers and critical infrastructure, resulting in over $115 million in extortions.

1 Actors
23andMe to pay $18 million in new genetics data breach settlement

1mo ago · bleeping-computer

23andMe suffered a significant data breach in 2023 due to credential-stuffing attacks that went undetected for five months, resulting in the theft of genetic and personal data from 6.9 million customers. The breach was attributed to inadequate security controls, including lack of password blocklisting, multifactor authentication, and intrusion detection. The company faced multiple lawsuits, regulatory fines, and ultimately a bankruptcy filing, culminating in a $18 million settlement with a coalition of 43 attorneys general to resolve claims over its failure to protect user data.

AI Agents Broke the Security Playbook. Here's What Replaces It.

1mo ago · bleeping-computer

AI agents are transforming enterprise environments by operating autonomously, accessing systems, and evolving faster than traditional security tools can track. This shift invalidates the old security model based on static, knowable environments, as agents can inherit human credentials and bypass conventional monitoring. The article argues that security teams must move beyond fixed workflows and vendor dashboards, instead building on a live identity foundation to maintain control over dynamic agent behaviors and access patterns.

New Spirals ransomware encrypts victim network in under 24 hours

1mo ago · bleeping-computer

A new ransomware actor named Spirals successfully breached an IT services firm in South Asia, achieving full network encryption within 24 hours of initial access. The attackers exploited a publicly exposed IIS server, deployed an ASP.NET web shell, and used tools like PsExec, revsocks, and Chisel for lateral movement and persistence. The Spirals ransomware, written in Rust, uses AES-128 encryption protected by ECDH P-256 and employs intermittent encryption to speed up the process, threatening victims with data exposure unless a ransom is paid.

2 IoCs
Dutch police bust investment fraud ring stealing over €100 million

1mo ago · bleeping-computer

Dutch police dismantled an international investment fraud ring responsible for stealing over €100 million monthly, with tens of thousands of victims worldwide. The criminal organization operated through 20 call centers across multiple countries, using social engineering to lure victims into fake investment platforms. Victims were manipulated into sending cryptocurrency, while the group used technical obfuscation to hide their identities and infrastructure. The main suspect, an Israeli-Polish national with prior hacking charges, was arrested in Poland and extradited to the Netherlands.

Zoom warns of critical account takeover vulnerability

1mo ago · bleeping-computer

Zoom has disclosed a critical vulnerability, CVE-2026-53412, in its Windows desktop client and SDK that could allow unauthenticated attackers to perform account takeover via network access. The flaw is described as an improper input validation issue and affects multiple versions of Zoom Workplace, VDI Client, and Meeting SDK for Windows. Zoom recommends updating to the latest patched versions to mitigate the risk, as no active exploitation has been observed at the time of disclosure.

Google Gemini CLI abused as a hacking agent, malware botnet operator

1mo ago · bleeping-computer

A Russian-speaking threat actor named 'bandcampro' abused Google's open-source Gemini CLI AI tool to operate a small-scale botnet and conduct hacking activities. The actor used the AI as an automated hacking agent to migrate command-and-control (C2) infrastructure, manage botnet operations via natural language, and attempt password guessing and data analysis. The botnet targeted systems in a dental clinic, accessing the OpenDental database, with operations sustained through simple but effective techniques including PowerShell agents and scheduled tasks. The malware lacked advanced evasion capabilities but was managed efficiently through AI-driven automation.

1 IoCs
We built a vulnerability vending machine: AI tokens in, zero-days out

1mo ago · bleeping-computer

Intruder's AI-powered vulnerability research pipeline, combining code scanning with large language models, discovered a high-impact blind SQL injection vulnerability (CVE-2026-3985) in the Creative Mail WordPress plugin. The vulnerability allows unauthenticated attackers to extract sensitive database information, including admin password hashes and secret tokens, when WooCommerce is also installed. The exploit chain requires multiple requests and was automatically discovered and validated using AI, demonstrating the growing capability of AI in both offensive and defensive security research.

​ ​AsyncAPI npm packages infected with credential-stealing malware

1mo ago · bleeping-computer

Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack that delivered a credential-stealing remote access trojan. The attacker compromised GitHub repositories via a misconfigured CI/CD pipeline, leveraging legitimate workflows to publish trojanized packages with valid SLSA attestations. The malware, which resembles the Miasma backdoor, steals credentials, tokens, browser data, and other sensitive information, and communicates via HTTP, Nostr, Ethereum smart contracts, and libp2p. The exposure window lasted about four hours on July 14, 2026, and although the packages have been removed, existing installations may still be compromised.

1 IoCs 1 Malware
CISA warns admins to patch actively exploited SharePoint flaws

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned administrators that three vulnerabilities in on-premises SharePoint Server instances are being actively exploited. These flaws allow attackers to bypass authentication, achieve remote code execution, and conduct post-exploitation activities such as stealing IIS machine keys and deploying malware. CISA urges immediate patching, enhanced monitoring, and network hardening to mitigate risks.

US charges alleged operators of Russian bulletproof hosting service

1mo ago · bleeping-computer

U.S. authorities have charged three Russian nationals for operating bulletproof hosting services, Media Land and ML.Cloud, which provided infrastructure to ransomware groups such as Lockbit, Blacksuit, and Play. These services enabled cybercriminals to conduct malware delivery, command-and-control operations, DDoS attacks, and phishing campaigns while evading takedowns. The services caused over $62 million in damages globally and targeted critical infrastructure, including banks, schools, hospitals, and government entities across 21 U.S. states.

1 Malware
Microsoft: Some Dell PCs shut down after recent Windows updates

1mo ago · bleeping-computer

Microsoft has identified a compatibility issue between a recent Windows preview update (KB5095093) and Dell devices equipped with the Intel Innovation Platform Framework Processor Participant driver. The conflict causes unexpected shutdowns, performance degradation, increased heat, and battery drain. Microsoft is blocking the KB5101650 update on affected systems while working with Dell and Intel to resolve the issue.

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

1mo ago · bleeping-computer

SonicWall has warned of active zero-day exploitation of two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in its SMA1000 appliances. CVE-2026-15409 is a critical SSRF flaw allowing unauthenticated remote attackers to force unintended requests, while CVE-2026-15410 is a post-authentication code injection vulnerability enabling arbitrary command execution. Both vulnerabilities are being actively exploited, with an overall CVSS score of 10.0, and affect multiple SMA1000 models. Immediate patching is advised, as no mitigations exist beyond updating to the latest hotfix releases.

3 IoCs
Spanish Police take down €140 million cyber fraud ring, arrest four

1mo ago · bleeping-computer

Spanish Police dismantled a cybercrime and money-laundering organization responsible for €140 million in losses through investment fraud and business email compromise (BEC) attacks. The group used over 800 bank accounts and 120 business accounts to launder funds, employing social engineering tactics like CEO fraud and false-invoice fraud. Four suspects were arrested across Spain, Portugal, and Panama, with law enforcement support from Interpol and Europol. The operation disrupted an extensive network involving 67 external accomplices and led to the seizure of digital devices and frozen assets.

← Previous Next →