Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: bleeping-computer Clear filter
Scattered Spider members behind TfL hack get five years in prison

4w ago · bleeping-computer

Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, were sentenced to five years and six months in prison for their involvement in the August 2024 breach of Transport for London (TfL). The attack disrupted critical internal systems, forced 27,000 employees to reset passwords, and led to the theft of customer data. The group is also linked to over 120 network intrusions globally, including attacks on U.S. healthcare providers and critical infrastructure, resulting in over $115 million in extortions.

1 Actors
23andMe to pay $18 million in new genetics data breach settlement

4w ago · bleeping-computer

23andMe suffered a significant data breach in 2023 due to credential-stuffing attacks that went undetected for five months, resulting in the theft of genetic and personal data from 6.9 million customers. The breach was attributed to inadequate security controls, including lack of password blocklisting, multifactor authentication, and intrusion detection. The company faced multiple lawsuits, regulatory fines, and ultimately a bankruptcy filing, culminating in a $18 million settlement with a coalition of 43 attorneys general to resolve claims over its failure to protect user data.

AI Agents Broke the Security Playbook. Here's What Replaces It.

4w ago · bleeping-computer

AI agents are transforming enterprise environments by operating autonomously, accessing systems, and evolving faster than traditional security tools can track. This shift invalidates the old security model based on static, knowable environments, as agents can inherit human credentials and bypass conventional monitoring. The article argues that security teams must move beyond fixed workflows and vendor dashboards, instead building on a live identity foundation to maintain control over dynamic agent behaviors and access patterns.

New Spirals ransomware encrypts victim network in under 24 hours

4w ago · bleeping-computer

A new ransomware actor named Spirals successfully breached an IT services firm in South Asia, achieving full network encryption within 24 hours of initial access. The attackers exploited a publicly exposed IIS server, deployed an ASP.NET web shell, and used tools like PsExec, revsocks, and Chisel for lateral movement and persistence. The Spirals ransomware, written in Rust, uses AES-128 encryption protected by ECDH P-256 and employs intermittent encryption to speed up the process, threatening victims with data exposure unless a ransom is paid.

2 IoCs
Dutch police bust investment fraud ring stealing over €100 million

1mo ago · bleeping-computer

Dutch police dismantled an international investment fraud ring responsible for stealing over €100 million monthly, with tens of thousands of victims worldwide. The criminal organization operated through 20 call centers across multiple countries, using social engineering to lure victims into fake investment platforms. Victims were manipulated into sending cryptocurrency, while the group used technical obfuscation to hide their identities and infrastructure. The main suspect, an Israeli-Polish national with prior hacking charges, was arrested in Poland and extradited to the Netherlands.

Zoom warns of critical account takeover vulnerability

1mo ago · bleeping-computer

Zoom has disclosed a critical vulnerability, CVE-2026-53412, in its Windows desktop client and SDK that could allow unauthenticated attackers to perform account takeover via network access. The flaw is described as an improper input validation issue and affects multiple versions of Zoom Workplace, VDI Client, and Meeting SDK for Windows. Zoom recommends updating to the latest patched versions to mitigate the risk, as no active exploitation has been observed at the time of disclosure.

Google Gemini CLI abused as a hacking agent, malware botnet operator

1mo ago · bleeping-computer

A Russian-speaking threat actor named 'bandcampro' abused Google's open-source Gemini CLI AI tool to operate a small-scale botnet and conduct hacking activities. The actor used the AI as an automated hacking agent to migrate command-and-control (C2) infrastructure, manage botnet operations via natural language, and attempt password guessing and data analysis. The botnet targeted systems in a dental clinic, accessing the OpenDental database, with operations sustained through simple but effective techniques including PowerShell agents and scheduled tasks. The malware lacked advanced evasion capabilities but was managed efficiently through AI-driven automation.

1 IoCs
We built a vulnerability vending machine: AI tokens in, zero-days out

1mo ago · bleeping-computer

Intruder's AI-powered vulnerability research pipeline, combining code scanning with large language models, discovered a high-impact blind SQL injection vulnerability (CVE-2026-3985) in the Creative Mail WordPress plugin. The vulnerability allows unauthenticated attackers to extract sensitive database information, including admin password hashes and secret tokens, when WooCommerce is also installed. The exploit chain requires multiple requests and was automatically discovered and validated using AI, demonstrating the growing capability of AI in both offensive and defensive security research.

​ ​AsyncAPI npm packages infected with credential-stealing malware

1mo ago · bleeping-computer

Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack that delivered a credential-stealing remote access trojan. The attacker compromised GitHub repositories via a misconfigured CI/CD pipeline, leveraging legitimate workflows to publish trojanized packages with valid SLSA attestations. The malware, which resembles the Miasma backdoor, steals credentials, tokens, browser data, and other sensitive information, and communicates via HTTP, Nostr, Ethereum smart contracts, and libp2p. The exposure window lasted about four hours on July 14, 2026, and although the packages have been removed, existing installations may still be compromised.

1 IoCs 1 Malware
CISA warns admins to patch actively exploited SharePoint flaws

1mo ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned administrators that three vulnerabilities in on-premises SharePoint Server instances are being actively exploited. These flaws allow attackers to bypass authentication, achieve remote code execution, and conduct post-exploitation activities such as stealing IIS machine keys and deploying malware. CISA urges immediate patching, enhanced monitoring, and network hardening to mitigate risks.

US charges alleged operators of Russian bulletproof hosting service

1mo ago · bleeping-computer

U.S. authorities have charged three Russian nationals for operating bulletproof hosting services, Media Land and ML.Cloud, which provided infrastructure to ransomware groups such as Lockbit, Blacksuit, and Play. These services enabled cybercriminals to conduct malware delivery, command-and-control operations, DDoS attacks, and phishing campaigns while evading takedowns. The services caused over $62 million in damages globally and targeted critical infrastructure, including banks, schools, hospitals, and government entities across 21 U.S. states.

1 Malware
Microsoft: Some Dell PCs shut down after recent Windows updates

1mo ago · bleeping-computer

Microsoft has identified a compatibility issue between a recent Windows preview update (KB5095093) and Dell devices equipped with the Intel Innovation Platform Framework Processor Participant driver. The conflict causes unexpected shutdowns, performance degradation, increased heat, and battery drain. Microsoft is blocking the KB5101650 update on affected systems while working with Dell and Intel to resolve the issue.

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

1mo ago · bleeping-computer

SonicWall has warned of active zero-day exploitation of two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in its SMA1000 appliances. CVE-2026-15409 is a critical SSRF flaw allowing unauthenticated remote attackers to force unintended requests, while CVE-2026-15410 is a post-authentication code injection vulnerability enabling arbitrary command execution. Both vulnerabilities are being actively exploited, with an overall CVSS score of 10.0, and affect multiple SMA1000 models. Immediate patching is advised, as no mitigations exist beyond updating to the latest hotfix releases.

3 IoCs
Spanish Police take down €140 million cyber fraud ring, arrest four

1mo ago · bleeping-computer

Spanish Police dismantled a cybercrime and money-laundering organization responsible for €140 million in losses through investment fraud and business email compromise (BEC) attacks. The group used over 800 bank accounts and 120 business accounts to launder funds, employing social engineering tactics like CEO fraud and false-invoice fraud. Four suspects were arrested across Spain, Portugal, and Panama, with law enforcement support from Interpol and Europol. The operation disrupted an extensive network involving 67 external accomplices and led to the seizure of digital devices and frozen assets.

Windows 11 KB5101650 & KB5099414 cumulative updates released

1mo ago · bleeping-computer

Microsoft released the July 2026 Patch Tuesday updates for Windows 11, including KB5101650 and KB5099414, to address 571 vulnerabilities and deliver minor feature improvements. The updates focus on security fixes, Bluetooth enhancements, accessibility features, and File Explorer refinements. No active exploitation of the patched vulnerabilities was reported at the time of release. The updates are mandatory and apply to Windows 11 versions 25H2, 24H2, and 23H2.

Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days

1mo ago · bleeping-computer

Microsoft's July 2026 Patch Tuesday addresses a record 570 vulnerabilities, including three zero-day flaws actively exploited or publicly disclosed. Two of the zero-days were exploited in the wild: CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in Microsoft SharePoint Server, both allowing privilege escalation. The third, CVE-2026-50661, is a publicly disclosed BitLocker security bypass that could allow attackers with physical access to bypass encryption protections.

Microsoft releases Windows 10 KB5099539 extended security update

1mo ago · bleeping-computer

Microsoft released the Windows 10 KB5099539 extended security update, which includes the July 2026 Patch Tuesday updates addressing a record 570 vulnerabilities, including two actively exploited and one publicly disclosed zero-day flaws. The update improves security features such as Secure Boot reporting and enforces TDI transport registration requirements, potentially affecting legacy applications. No active threat campaigns or malicious indicators are described in the article.

Nearly 300 GitHub repos pose as legit software to push malware

1mo ago · bleeping-computer

A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software projects to distribute an infostealer malware, primarily targeting credentials, cryptocurrency wallets, and sensitive data from browsers and messaging apps. The malicious repositories redirect users to spoofed download pages that deliver trojanized payloads, including a malicious libcurl.dll that executes the infostealer in memory. The malware, a variant of BoryptGrab, exfiltrates stolen data to a Russia-based C2 server and is designed for maximum data theft in a single execution without establishing persistence or anti-analysis measures.

1 IoCs
LastPass, Bitwarden users targeted with fake security alerts

1mo ago · bleeping-computer

An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to mimic legitimate corporate communications. The emails direct recipients to fraudulent websites impersonating DocuSign, hosted on malicious domains, where users are prompted to download malicious files. Despite the use of domains resembling official services, LastPass confirms no compromise of its systems and warns users not to provide master passwords via email.

2 IoCs
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

1mo ago · bleeping-computer

Progress Software confirmed a high-severity zero-day path traversal vulnerability in ShareFile Storage Zone Controller versions 5.x and 6.x, leading to the emergency shutdown of affected systems. The flaw allows authenticated administrative users to read arbitrary files, write malicious content, and enumerate the server filesystem. Although a CVE has been reserved, no evidence of customer breaches has been found. Security updates (versions 5.12.5 and 6.0.2) have been released to mitigate the vulnerability.

Microsoft starts testing cleaner Windows Search without ads

1mo ago · bleeping-computer

The article discusses Microsoft's testing of a cleaner and faster version of Windows Search for Windows Insiders in the Experimental channel. The update prioritizes relevant local results over ads and promotional content, improves search reliability, and enhances user control via new privacy settings. There is no mention of malicious activity, threats, or cyber attacks in the article.

SAP warns of critical flaws in NetWeaver and Commerce Cloud

1mo ago · bleeping-computer

SAP has released its July 2026 security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, AppRouter, and Commerce Cloud. The critical vulnerabilities include a memory corruption issue in NetWeaver AS ABAP, an HTTP request smuggling flaw in AppRouter, and a default credentials issue in Commerce Cloud that could allow unauthorized data access. While no active exploitation has been observed yet, CISA has previously cataloged SAP vulnerabilities as exploited, and recent supply chain attacks highlight ongoing risks.

New phishing kits target Microsoft 365 accounts, evade MFA

1mo ago · bleeping-computer

Two new phishing kits, Jalisco and OmegaLord, are targeting Microsoft 365 accounts using techniques that bypass multi-factor authentication (MFA). Jalisco leverages device-code phishing via OAuth 2.0 Device Authorization Grant, tricking users into authorizing attacker-controlled devices. OmegaLord uses a fake PDF reader login page to harvest credentials and phone numbers, aiding in MFA bypass. Both kits enable rapid data exfiltration from SaaS platforms like SharePoint, often within minutes of compromise.

1 Actors
Microsoft Entra ID gets passkeys default authentication starting September

1mo ago · bleeping-computer

Microsoft is transitioning to passkeys as the default authentication method for Entra ID starting September 2026, retiring SMS and voice authentication by February 2027. This shift aims to reduce reliance on phishable methods and improve security against credential theft and identity attacks. Threat actors, including the ShinyHunters group, have been targeting Entra ID SSO accounts using stolen credentials, with AI-enhanced phishing campaigns achieving high click-through rates. Organizations are urged to adopt phishing-resistant authentication methods to prevent sign-in disruptions and strengthen account protection.

1 Actors
You Don't Have to Run an Exploit to Know If You're Vulnerable

1mo ago · bleeping-computer

The article discusses the shrinking window between vulnerability disclosure and exploitation, driven by the increasing volume of CVEs and the rapid weaponization of flaws using AI. It highlights the case of 'Nightmare-Eclipse,' a set of Windows zero-day exploits developed by a disgruntled security researcher, which enables local privilege escalation, credential theft, and evasion of Windows Defender. The article advocates for breach and attack simulation (BAS) techniques that validate exploitability without executing real exploits, allowing defenders to prioritize patching based on actual risk.

1 IoCs
US sanctions VPN, malware providers for enabling ransomware attacks

1mo ago · bleeping-computer

The U.S. Treasury Department sanctioned two individuals and one entity for supporting ransomware operations by providing infrastructure and tools to conceal malicious activity. First VPN Service (1VPNS), a no-logs VPN provider used by ransomware groups, and its administrator Dmytro Rashevskyi were designated for enabling attackers to hide their identities. Additionally, Belarusian national Yegeniy Vladimirovich Silayev was sanctioned for selling crypters that help malware evade detection. These actions are part of a broader international effort to dismantle enablers of cybercrime, following the takedown of 1VPNS in Operation Saffron with European law enforcement.

1 IoCs
New CrashStealer malware poses as Apple crash reporting tool

1mo ago · bleeping-computer

A new macOS information-stealing malware named CrashStealer impersonates Apple's crash reporting tool to evade detection and steal sensitive data. It uses a signed and notarized installer to bypass macOS Gatekeeper, tricks users with a fake password prompt to access Keychain data, and targets browser credentials, crypto wallets, and password managers. The malware encrypts stolen data with AES-256-GCM before exfiltration, indicating a sophisticated and stealthy operation.

4 IoCs
Hackers backdoor Jscrambler npm package with infostealer malware

1mo ago · bleeping-computer

Hackers compromised the npm publishing credentials of Jscrambler and published malicious versions of its npm package (8.14, 8.16, 8.17, 8.20), which were downloaded nearly 1,500 times. The backdoored package executed an infostealer during the 'preinstall' hook, targeting source code, credentials, cloud secrets, cryptocurrency wallets, and browser data. The malware used ChaCha20-Poly1305 encryption for obfuscation, and Jscrambler has since deprecated the affected versions and enhanced its publishing pipeline security.

2 IoCs
Japan's largest taxi operator shuts systems after cyberattack

1mo ago · bleeping-computer

Japan's largest taxi operator, Nihon Kotsu, suffered a cyberattack involving unauthorized access and suspected malware infection, leading to the shutdown of critical systems including taxi dispatch, web booking, and reservation management. The company has disconnected affected systems to prevent further damage and is working with external cybersecurity experts to investigate potential data leaks. No ransomware group has claimed responsibility, and customers are warned against opening suspicious communications.

CISA warns of actively exploited RCE flaws in Joomla extensions

1mo ago · bleeping-computer

CISA has issued a warning about actively exploited remote code execution (RCE) vulnerabilities in two Joomla extensions, iCagenda and Balbooa Forms. The vulnerabilities, CVE-2026-48939 and CVE-2026-56291, allow attackers to upload arbitrary files, including malicious PHP scripts, leading to full website compromise. These flaws were exploited in automated attacks before patches were released, with exploitation occurring just days prior to vendor fixes.

← Previous Next →