News

Bleeping Computer
bleepingcomputer. com > news > security > payouts-king-ransomware-uses-qemu-vms-to-bypass-endpoint-security

Payouts King ransomware uses QEMU VMs to bypass endpoint security

7+ hour, 57+ min ago  (886+ words) New Microsoft Defender "Red Sun" zero-day Po C grants SYSTEM privileges Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now…...

Bleeping Computer
bleepingcomputer. com > news > security > grinex-exchange-blames-western-intelligence-for-137m-crypto-hack

Grinex exchange blames "Western intelligence" for $13. 7 M crypto hack

11+ hour, 59+ min ago  (613+ words) New Microsoft Defender "Red Sun" zero-day Po C grants SYSTEM privileges Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now…...

Bleeping Computer
bleepingcomputer. com > offer > deals > add-azure-architect-and-administrator-skills-to-your-resume-for-40

Add Azure Architect & Administrator skills to your resume for $40

1+ day, 8+ hour ago  (505+ words) New Microsoft Defender "Red Sun" zero-day Po C grants SYSTEM privileges Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now…...

Bleeping Computer
bleepingcomputer. com > news > security > recently-leaked-windows-zero-days-now-exploited-in-attacks

Recently leaked Windows zero-days now exploited in attacks

20+ hour, 53+ min ago  (642+ words) Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Payouts King ransomware uses QEMU VMs…...

Bleeping Computer
bleepingcomputer. com > news > microsoft > new-microsoft-defender-redsun-zero-day-poc-grants-system-privileges

New Microsoft Defender "Red Sun" zero-day Po C grants SYSTEM privileges

1+ day, 6+ hour ago  (862+ words) Data breach at edtech giant Mc Graw Hill affects 13. 5 million accounts New ATHR vishing platform uses AI voice agents for automated attacks Critical Nginx UI auth bypass flaw now actively exploited in the wild Payouts King ransomware uses QEMU VMs…...

@Bleepin Computer
bleepingcomputer. com > news > security > critical-nginx-ui-auth-bypass-flaw-now-actively-exploited-in-the-wild > amp

Critical Nginx UI auth bypass flaw now actively exploited in the wild

2+ day, 4+ hour ago  (416+ words) A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. The flaw, tracked as CVE-2026-33032, is caused by nginx-ui leaving the "/mcp_message" endpoint unprotected, allowing remote…...

Bleeping Computer
bleepingcomputer. com > news > security > new-agingfly-malware-used-in-attacks-on-ukraine-govt-hospitals

New Aging Fly malware used in attacks on Ukraine govt, hospitals

2+ day, 5+ hour ago  (744+ words) Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw Stolen Rockstar Games analytics data leaked by extortion gang New Booking. com data breach forces reservation PIN resets Critical Nginx UI auth bypass flaw now actively exploited in the wild…...

Bleeping Computer
bleepingcomputer. com > news > security > wordpress-plugin-suite-hacked-to-push-malware-to-thousands-of-sites

Word Press plugin suite hacked to push malware to thousands of sites

2+ day, 6+ hour ago  (579+ words) Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw Stolen Rockstar Games analytics data leaked by extortion gang New Booking. com data breach forces reservation PIN resets New Aging Fly malware used in attacks on Ukraine govt, hospitals Word…...

Bleeping Computer
bleepingcomputer. com > news > security > signed-software-abused-to-deploy-antivirus-killing-scripts

Signed software abused to deploy antivirus-killing scripts

2+ day, 9+ hour ago  (909+ words) Stolen Rockstar Games analytics data leaked by extortion gang New Booking. com data breach forces reservation PIN resets Access GPT, Gemini, and Claude in one $30 app to get tasks done faster Microsoft pays $2. 3 M for cloud and AI flaws at…...

Bleeping Computer
bleepingcomputer. com > news > security > over-100-chrome-extensions-in-web-store-target-users-accounts-and-data

Over 100 Chrome Web Store extensions steal user accounts, data

3+ day, 6+ hour ago  (569+ words) Stolen Rockstar Games analytics data leaked by extortion gang New Booking. com data breach forces reservation PIN resets CISA flags Windows Task Host vulnerability as exploited in attacks Microsoft: April updates trigger Bit Locker key prompts on some servers Get…...