Google Threat Intelligence Group (GTIG) announces a new naming schema for tracking threat actors. cloud.google.com/blog/topics/...
Sergiu Gatlan
@serghei.bsky.social
Cybersecurity/tech reporter @BleepingComputer / serghei.ro
Chick-fil-A has confirmed that over 13,000 customers had their accounts compromised in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. www.bleepingcomputer.com/news/securit...
Chick-fil-A data breach affects more than 13,000 customers
Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.
bleepingcomputer.com
Periodic reminder that if you are being asked by a captcha to type any kind of combinations of keys & especially if they look like shortcut key stroke combinations it is an attack called ClickFix. Basically the prompt is to fool you into downloading & installing malicious software. Stay vigilant!
This is new and completely wierd. To proof that I am not an AI, cloudflare now wants me to enter something in the terminal, of unknown origin. Sorry, no way.
NEW: After a purported crackdown on scam compounds last year, researchers now say at least 25 new scamming sites have opened or expanded in Myanmar. Satellite images show trees being razed and land cleared, with large compounds appearing months later
Satellite Images Reveal How Suspected Scam Compounds Appear Out of Nowhere
Analysis of satellite images of Myanmar shows dozens of alleged scam compounds have appeared in recent months, despite a purported crackdown on the criminal organizations.
wired.com
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Clop ransomware targets Windchill, FlexPLM in data theft attacks
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
bleepingcomputer.com
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
bleepingcomputer.com
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
bleepingcomputer.com
It's unusual for former FSB employees to be arrested outside of Russia (and extradited) these days. But what's also unusual about Denis Obrezko -- charged with the "Laundry Bear" hack of computers in the U.S. and Europe-- is how careless he appeared to have been online. www.rferl.org/a/russia-hac...
An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.
What’s unusual about the arrest of Denis Obrezko is how relatively rare it is for Russian hackers to be detained abroad these days. What’s also unusual: Obrezko used to work for Russia’s FSB. And it a...
rferl.org
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
Maine disables data breach notification portal after fake disclosures
Maine has taken its public data breach reporting portal offline after fraudulent breach disclosures were published on the state's website, prompting a review of procedures to prevent abuse in the future.
bleepingcomputer.com
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
Pharma giant Novo Nordisk discloses breach of clinical trials data
Danish pharmaceutical giant Novo Nordisk, the world's largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
bleepingcomputer.com
In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims.
Maine breach portal abused to publish fake data breach disclosures
In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies to deny the claims.
bleepingcomputer.com
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.
bleepingcomputer.com
New out of Boston: A suspected Russian hacker who was arrested last year in Thailand at the FBI's behest is now in U.S. custody and has been charged with facilitating a campaign of cyberattacks carried out by a Russia-aligned group called Void Blizzard. www.reuters.com/legal/govern...
US charges suspected Russian hacker with facilitating cyber campaign
A suspected Russian hacker is now in U.S. custody following his arrest in Thailand last year and has been charged with facilitating a campaign of cyberattacks carried out by a Russia-aligned group t...
reuters.com
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.
bleepingcomputer.com
🚨 NEW 🚨 The Justice Department gagged Apple from talking about surveillance on a senior Republican staffer that's been going on for at least the last three years. Apple fought the non-disclosure orders and won. It's now informed the target. www.forbes.com/sites/the-wi...
The FBI Gagged Apple About Surveilling A Republican Aide. Apple Took It To Court And Won.
The DOJ served Apple with repeated gag orders related to extensive surveillance of a senior Republican Congressional staffer in a Qatari-influence investigation.
forbes.com
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
ServiceNow discloses security incident exposing customer data
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
bleepingcomputer.com
The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.
UN food agency discloses breach affecting 600,000 Gaza households
The United Nations' World Food Programme (WFP), the world's largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.
bleepingcomputer.com
Microsoft's digital crimes unit said it would pursue security researchers who "irresponsibly" disclose 0day. But it's simple: Redmond can't dictate what researchers do with bugs. If you can't entice hackers to disclose bugs via your preferred channels, that's a you problem! (aka skill issue)
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.
VS Code zero-day lets hackers steal GitHub tokens in one click
A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.
bleepingcomputer.com
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks.
bleepingcomputer.com
Are Microsoft arguing that releasing proof of concept is a crime if you don't get their approval first? Because this seems to lump a security researcher not going along with their preferred disclosure process in with "criminal activity".
Microsoft has published a blog addressing all the zero-days disclosed by Nightmare Eclipse: www.microsoft.com/en-us/msrc/b... This comes after both GitHub and GitLab took down the researcher's accounts, and after the researcher was also doxxed on Twitter yesterday
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
Charter confirms data breach after ShinyHunters extortion threat
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
bleepingcomputer.com
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
bleepingcomputer.com
Huawei has not explained why no CVE has been issued for the vulnerability that caused Luxembourg’s nationwide telecoms outage. Ten months later, it remains unclear whether the vuln was ever fully patched, how many operators may have been exposed or whether similar systems remain vulnerable today.
Scoop: An attack exploiting a previously unknown vulnerability in Huawei enterprise router software caused a nationwide telecoms outage in Luxembourg last year, according to multiple sources briefed on the matter, disrupting mobile, landline and emergency communications for more than three hours.
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension.
bleepingcomputer.com
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
OpenAI confirms security breach in TanStack supply chain attack
OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.
bleepingcomputer.com
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.
US govt seeks Instructure testimony on massive Canvas cyberattack
The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.
bleepingcomputer.com
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion. www.bleepingcomputer.com/news/securit...
Trellix source code breach claimed by RansomHouse hackers
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.
bleepingcomputer.com