Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Windows 11 KB5101650 & KB5099414 cumulative updates released

1mo ago · bleeping-computer

Microsoft released the July 2026 Patch Tuesday updates for Windows 11, including KB5101650 and KB5099414, to address 571 vulnerabilities and deliver minor feature improvements. The updates focus on security fixes, Bluetooth enhancements, accessibility features, and File Explorer refinements. No active exploitation of the patched vulnerabilities was reported at the time of release. The updates are mandatory and apply to Windows 11 versions 25H2, 24H2, and 23H2.

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

1mo ago · bleeping-computer

Microsoft's July 2026 Patch Tuesday addresses a record 570 vulnerabilities, including three zero-day flaws actively exploited or publicly disclosed. Two of the zero-days were exploited in the wild: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in Microsoft SharePoint Server, both allowing privilege escalation. The third, CVE-2026-50661, is a publicly disclosed BitLocker security bypass that could allow attackers with physical access to bypass encryption protections.

Microsoft releases Windows 10 KB5099539 extended security update

1mo ago · bleeping-computer

Microsoft released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday updates addressing a record 570 vulnerabilities, including two actively exploited and one publicly disclosed zero-day flaws. The update improves security features such as Secure Boot reporting and enforces TDI transport registration requirements, potentially affecting legacy applications. No active threat campaigns or malicious indicators are described in the article.

Nearly 300 GitHub repos pose as legit software to push malware

1mo ago · bleeping-computer

A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software projects to distribute an infostealer malware, primarily targeting credentials, cryptocurrency wallets, and sensitive data from browsers and messaging apps. The malicious repositories redirect users to spoofed download pages that deliver trojanized payloads, including a malicious libcurl.dll that executes the infostealer in memory. The malware, a variant of BoryptGrab, exfiltrates stolen data to a Russia-based C2 server and is designed for maximum data theft in a single execution without establishing persistence or anti-analysis measures.

1 IoCs
LastPass, Bitwarden users targeted with fake security alerts

1mo ago · bleeping-computer

An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to mimic legitimate corporate communications. The emails direct recipients to fraudulent websites impersonating DocuSign, hosted on malicious domains, where users are prompted to download malicious files. Despite the use of domains resembling official services, LastPass confirms no compromise of its systems and warns users not to provide master passwords via email.

2 IoCs
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

1mo ago · bleeping-computer

Progress Software confirmed a high-severity zero-day path traversal vulnerability in ShareFile Storage Zone Controller versions 5.x and 6.x, leading to the emergency shutdown of affected systems. The flaw allows authenticated administrative users to read arbitrary files, write malicious content, and enumerate the server filesystem. Although a CVE has been reserved, no evidence of customer breaches has been found. Security updates (versions 5.12.5 and 6.0.2) have been released to mitigate the vulnerability.

Microsoft starts testing cleaner Windows Search without ads

1mo ago · bleeping-computer

The article discusses Microsoft's testing of a cleaner and faster version of Windows Search for Windows Insiders in the Experimental channel. The update prioritizes relevant local results over ads and promotional content, improves search reliability, and enhances user control via new privacy settings. There is no mention of malicious activity, threats, or cyber attacks in the article.

SAP warns of critical flaws in NetWeaver and Commerce Cloud

1mo ago · bleeping-computer

SAP has released its July 2026 security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, AppRouter, and Commerce Cloud. The critical vulnerabilities include a memory corruption issue in NetWeaver AS ABAP, an HTTP request smuggling flaw in AppRouter, and a default credentials issue in Commerce Cloud that could allow unauthorized data access. While no active exploitation has been observed yet, CISA has previously cataloged SAP vulnerabilities as exploited, and recent supply chain attacks highlight ongoing risks.

New phishing kits target Microsoft 365 accounts, evade MFA

1mo ago · bleeping-computer

Two new phishing kits, Jalisco and OmegaLord, are targeting Microsoft 365 accounts using techniques that bypass multi-factor authentication (MFA). Jalisco leverages device-code phishing via OAuth 2.0 Device Authorization Grant, tricking users into authorizing attacker-controlled devices. OmegaLord uses a fake PDF reader login page to harvest credentials and phone numbers, aiding in MFA bypass. Both kits enable rapid data exfiltration from SaaS platforms like SharePoint, often within minutes of compromise.

1 Actors
Microsoft Entra ID gets passkeys default authentication starting September

1mo ago · bleeping-computer

Microsoft is transitioning to passkeys as the default authentication method for Entra ID starting September 2026, retiring SMS and voice authentication by February 2027. This shift aims to reduce reliance on phishable methods and improve security against credential theft and identity attacks. Threat actors, including the ShinyHunters group, have been targeting Entra ID SSO accounts using stolen credentials, with AI-enhanced phishing campaigns achieving high click-through rates. Organizations are urged to adopt phishing-resistant authentication methods to prevent sign-in disruptions and strengthen account protection.

1 Actors
You Don't Have to Run an Exploit to Know If You're Vulnerable

1mo ago · bleeping-computer

The article discusses the shrinking window between vulnerability disclosure and exploitation, driven by the increasing volume of CVEs and the rapid weaponization of flaws using AI. It highlights the case of 'Nightmare-Eclipse,' a set of Windows zero-day exploits developed by a disgruntled security researcher, which enables local privilege escalation, credential theft, and evasion of Windows Defender. The article advocates for breach and attack simulation (BAS) techniques that validate exploitability without executing real exploits, allowing defenders to prioritize patching based on actual risk.

1 IoCs
US sanctions VPN, malware providers for enabling ransomware attacks

1mo ago · bleeping-computer

The U.S. Treasury Department sanctioned two individuals and one entity for supporting ransomware operations by providing infrastructure and tools to conceal malicious activity. First VPN Service (1VPNS), a no-logs VPN provider used by ransomware groups, and its administrator Dmytro Rashevskyi were designated for enabling attackers to hide their identities. Additionally, Belarusian national Yegeniy Vladimirovich Silayev was sanctioned for selling crypters that help malware evade detection. These actions are part of a broader international effort to dismantle enablers of cybercrime, following the takedown of 1VPNS in Operation Saffron with European law enforcement.

1 IoCs
New CrashStealer malware poses as Apple crash reporting tool

1mo ago · bleeping-computer

A new macOS information-stealing malware named CrashStealer impersonates Apple's crash reporting tool to evade detection and steal sensitive data. It uses a signed and notarized installer to bypass macOS Gatekeeper, tricks users with a fake password prompt to access Keychain data, and targets browser credentials, crypto wallets, and password managers. The malware encrypts stolen data with AES-256-GCM before exfiltration, indicating a sophisticated and stealthy operation.

4 IoCs
Hackers backdoor Jscrambler npm package with infostealer malware

1mo ago · bleeping-computer

Hackers compromised the npm publishing credentials of Jscrambler and published malicious versions of its npm package (8.14, 8.16, 8.17, 8.20), which were downloaded nearly 1,500 times. The backdoored package executed an infostealer during the 'preinstall' hook, targeting source code, credentials, cloud secrets, cryptocurrency wallets, and browser data. The malware used ChaCha20-Poly1305 encryption for obfuscation, and Jscrambler has since deprecated the affected versions and enhanced its publishing pipeline security.

2 IoCs
Japan's largest taxi operator shuts systems after cyberattack

1mo ago · bleeping-computer

Japan's largest taxi operator, Nihon Kotsu, suffered a cyberattack involving unauthorized access and suspected malware infection, leading to the shutdown of critical systems including taxi dispatch, web booking, and reservation management. The company has disconnected affected systems to prevent further damage and is working with external cybersecurity experts to investigate potential data leaks. No ransomware group has claimed responsibility, and customers are warned against opening suspicious communications.

CISA warns of actively exploited RCE flaws in Joomla extensions

1mo ago · bleeping-computer

CISA has issued a warning about actively exploited remote code execution (RCE) vulnerabilities in two Joomla extensions, iCagenda and Balbooa Forms. The vulnerabilities, CVE-2026-48939 and CVE-2026-56291, allow attackers to upload arbitrary files, including malicious PHP scripts, leading to full website compromise. These flaws were exploited in automated attacks before patches were released, with exploitation occurring just days prior to vendor fixes.

UK charges suspects linked to Russian Coms call spoofing platform

1mo ago · bleeping-computer

UK authorities have charged five individuals in connection with Russian Coms, a caller ID spoofing platform used by criminals to conduct over 1.8 million scam calls since 2020. The platform enabled scammers to spoof numbers of financial institutions, telecoms, and law enforcement agencies to steal personal data and funds from victims. It was marketed on Telegram, Snapchat, and Instagram, offering encrypted calls, voice-changing, and no-logs services, leading to an estimated £9,400 average loss per victim across more than 107 countries.

Breach at the Beach: Play the Ultimate Entra ID CTF

1mo ago · bleeping-computer

Varonis Threat Labs created 'Breach at the Beach,' a hands-on Capture the Flag (CTF) training exercise focused on detecting real-world attacks in Microsoft Entra ID environments. The CTF simulates modern identity-based threats, particularly those involving non-human identities and AI-powered workflows, to educate defenders on data exfiltration techniques. It emphasizes detection of legitimate feature abuse rather than misconfigurations and is designed to be resilient to AI-based solving, promoting deep learning through practical experience.

1 IoCs
Lidl discloses online shop breach after service provider hack

1mo ago · bleeping-computer

Lidl disclosed a data breach affecting customers in Germany, Belgium, and the Netherlands following a cyberattack on a third-party service provider. The attackers accessed a file containing personal information such as names, phone numbers, email addresses, dates of birth, and customer numbers. While the online shop system was not compromised, Lidl cannot rule out exposure of passwords, payment details, and addresses, urging customers to remain vigilant against phishing and identity fraud.

US and allies warn of Russian critical infrastructure attacks

1mo ago · bleeping-computer

Cybersecurity agencies from the US and allied nations have issued a joint advisory warning of Russian state-sponsored hackers, attributed to FSB Center 16, targeting critical infrastructure by exploiting misconfigured routers and known vulnerabilities. The threat actor scans for devices using default SNMP credentials and exploits CVE-2018-0171 in Cisco Smart Install to gain control of network devices. Sectors at risk include energy, healthcare, defense, and government services. The advisory emphasizes mitigation steps such as disabling vulnerable features, upgrading to SNMPv3, and blocking unauthorized protocols at firewalls.

2 Actors
EU sanctions Russian GRU military hackers over cyberattacks

1mo ago · bleeping-computer

The European Union and the United Kingdom have jointly imposed sanctions on Russian individuals and entities linked to state-sponsored cyberattacks. The targeted groups include GRU officers, FSB-affiliated hackers such as the Turla group, and cybercriminals involved in operations like the Lumma Stealer malware. These actors are accused of conducting cyberespionage, targeting critical infrastructure across Europe, and supporting disinformation campaigns. The sanctions follow a series of attacks on energy grids and government institutions, including failed attempts to disrupt Poland's power infrastructure.

2 Actors 2 Malware
OpenAI temporarily relaxes GPT-5.6 Sol usage limits

1mo ago · bleeping-computer

OpenAI temporarily relaxed usage limits for its GPT-5.6 Sol model due to high demand, removing the five-hour usage restriction for Plus, Pro, and Business plans and resetting usage counters. The change allows users to perform more coding and agentic tasks without hitting previous limits. OpenAI also improved model efficiency, likely by reducing token consumption, to extend available usage.

Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time

1mo ago · bleeping-computer

Anthropic has extended access to its Claude Fable 5 model for paid subscribers until July 19, 2026, allowing continued use within weekly subscription limits. The extension applies to Pro, Max, Team, and premium Enterprise plans, with no changes required to activate the benefit. Fable 5 consumes usage limits faster than other models, and once the 50% weekly allowance is exhausted, users must either switch models or use paid credits. This is not a security-related threat event but a product update.

RedHook Android malware now uses Wireless ADB for shell access

1mo ago · bleeping-computer

The RedHook Android malware has evolved to leverage Wireless ADB for shell-level access without requiring device rooting. By tricking users into enabling Accessibility permissions, the malware enables Developer Options and Wireless Debugging, then pairs with the device's ADB service via loopback to gain elevated privileges. It uses the legitimate Shizuku framework to execute privileged commands, enabling screen streaming, keystroke logging, app manipulation, and persistence through multiple mechanisms, all while evading detection by mimicking legitimate system behavior.

1 IoCs
Australia warns of global campaign targeting vulnerable CMS platforms

1mo ago · bleeping-computer

The Australian Cyber Security Centre (ACSC) has issued a warning about a global campaign targeting vulnerabilities in content management systems (CMS) and plugins, affecting numerous small- to medium-sized businesses in Australia. Threat actors are actively scanning for exposed CMS platforms and deploying webshells to gain persistent access, enabling credential theft, service disruption, and lateral movement. The campaign exploits known vulnerabilities across multiple CMS platforms including WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE, with potential AI assistance to accelerate exploitation.

5 CVEs
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

1mo ago · bleeping-computer

The 'Ghostcommit' attack exploits a review gap in AI code review systems by hiding malicious prompt injection instructions within a PNG image referenced in a pull request. The image contains text instructing the AI agent to read and exfiltrate environment variables (.env) by encoding them as integers in a seemingly benign module constant. Since reviewers and automated tools typically do not inspect image content, the malicious payload bypasses detection and is later executed by AI coding agents, leading to secret exfiltration.

3 IoCs
New U-Boot flaws could enable stealthy firmware attacks

1mo ago · bleeping-computer

Six vulnerabilities in the U-Boot bootloader have been discovered, potentially allowing attackers to execute arbitrary code or crash devices during the boot process. These flaws affect the FIT signature verification functionality and could enable stealthy, persistent firmware-level attacks on embedded systems. Exploitation may not require physical access, especially on systems supporting remote firmware updates like BMCs. The vulnerabilities impact over 50 U-Boot releases and downstream vendor implementations, with older devices potentially remaining unpatched.

Money launderer accused of stealing seized crypto while in prison

1mo ago · bleeping-computer

Rossen G. Iossifov, a Bulgarian national serving prison time for operating a cryptocurrency exchange used to launder funds from online fraud, is accused of orchestrating the theft of $290,000 in government-seized cryptocurrency while incarcerated. He allegedly conspired with others to move the funds through multiple exchanges and mixing services to evade law enforcement. Iossifov previously operated RG Coins, a Bulgaria-based exchange that facilitated money laundering for a fraud ring targeting American victims via fake online listings.

Hackers exploit critical auth bypass in Gitea Docker image

1mo ago · bleeping-computer

Hackers are actively exploiting a critical authentication bypass vulnerability, CVE-2026-20896, in the official Gitea Docker image. The flaw allows unauthenticated attackers to impersonate any user, including administrators, by spoofing the X-WEBAUTH-USER header when reverse proxy settings are misconfigured. The vulnerability affects Gitea Docker images up to version 1.26.2 in default configurations, and exploitation has already been observed in the wild. Singapore’s Cybersecurity Agency (CSA) has issued a warning, urging users to upgrade to patched versions 1.26.3 or 1.26.4.

1 CVEs
Progress urges ShareFile admins to shut down servers over “credible” threat

1mo ago · bleeping-computer

Progress Software has issued an urgent warning to ShareFile customers using on-premises Storage Zone Controllers, advising them to immediately shut down their servers due to a 'credible external security threat.' The threat targets Internet-accessible Storage Zone Controllers used in hybrid deployments, which manage file transfers between ShareFile's cloud and customer-owned storage. While no unauthorized access has been confirmed, Progress has temporarily disabled access as a precaution and is investigating with cybersecurity experts. The situation bears similarities to past attacks on enterprise file transfer platforms like the 2023 MOVEit breach.

← Previous Next →