Bill Toulas / BleepingComputer: Google patches an actively exploited zero-day flaw in Chrome that could potentially allow remote code execution within Chrome's sandboxed renderer process — Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.
Sergiu Gatlan / BleepingComputer: Europol and international law enforcement agencies dismantle nine organized crime groups and arrest 29 in an illegal streaming crackdown, removing 27,000+ URLs — European and international law enforcement agencies have dismantled nine organized crime groups and arrested 29 suspects …
Sergiu Gatlan / BleepingComputer: US and Canadian authorities arrest 23-year-old Jacob Butler, known online as “Dort”, for allegedly operating the Kimwolf DDoS botnet, which infected ~2M devices — U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service …
Sergiu Gatlan / BleepingComputer: GitHub links the breach of 3,800 internal repositories to the TanStack npm supply-chain attack, saying hackers used a malicious Nx Console VS Code extension — GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension …
Sergiu Gatlan / BleepingComputer: On Pwn2Own Berlin 2026 day 2, competitors earned $385,750 after exploiting 15 unique zero-day vulnerabilities in Windows 11, Red Hat Enterprise Linux and more — During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero …
Sergiu Gatlan / BleepingComputer: Google rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools — Google says Gmail end-to-end encryption (E2EE) is now available on all Android and iOS devices, allowing enterprise users to read …
Sergiu Gatlan / BleepingComputer: Researchers: a zero-day vulnerability in Adobe Reader has been actively exploited since at least December 2025, and some docs contain Russian-language lures — Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December.
Lawrence Abrams / BleepingComputer: Telus Digital confirms a security incident after ShinyHunters claimed to have stolen nearly 1PB of data from the Canadian BPO giant in a multimonth breach — Canadian business process outsourcing giant Telus Digital has confirmed it suffered a security incident after threat actors claimed …
Mayank Parmar / BleepingComputer: Anthropic reports elevated errors on claude.ai, console, and Claude Code, starting at 11:49 UTC and impacting logins, and says the API “is working as intended” — Claude appears to be having a major outage right now, with elevated errors reported across all platforms.
Bill Toulas / BleepingComputer: French e-commerce marketplace ManoMano notifies its customers of a data breach affecting 38M; the company said the incident involved a third party subcontractor — DIY store chain ManoMano is notifying customers of a data breach that was caused by hackers compromising a third-party service provider.
Lawrence Abrams / BleepingComputer: Amazon details how a Russian-speaking hacker used generative AI as part of a campaign that breached 600+ FortiGate firewalls across 55 countries in five weeks — Amazon is warning that a Russian-speaking hacker used multiple generative AI services as part of a campaign that breached …
Sergiu Gatlan / BleepingComputer: Substack notifies users about a “limited” data breach in October 2025, found on February 3 and now patched; a threat actor leaked a database of ~697K records — Newsletter platform Substack is notifying users of a data breach after attackers stole their email addresses and phone numbers in October 2025.
Bill Toulas / BleepingComputer: Cloudflare says it mitigated a 31.4 Tbps DDoS attack from the Aisuru/Kimwolf botnet in December 2025, making it the largest attack ever disclosed publicly — The Aisuru/Kimwolf botnet launched a new massive distributed denial of service (DDoS) attack that peaked at 31.4 Tbps and 200 million requests per second, setting a new record.
Lawrence Abrams / BleepingComputer: Ubisoft says it intentionally shut down Rainbow Six Siege and its in-game Marketplace to resolve an “incident”; reports say hackers breached internal systems — Ubisoft's Rainbow Six Siege (R6) suffered a breach that allowed hackers to abuse internal systems to ban and unban players …
Bill Toulas / BleepingComputer: watchTowr: 80K+ sensitive credentials were found via publicly accessible “Recent Links” pages on online code formatting tools JSONFormatter and CodeBeautify — Thousands of credentials, authentication keys, and configuration data impacting organizations in sensitive sectors …
Sergiu Gatlan / BleepingComputer: After a backlash, Google reverses plans to require all Android app developers to verify their identities with government ID and pay fees from 2026 — Google is backpedaling on its decision to introduce new identity verification rules for all developers, stating that it will also introduce accounts …
Sergiu Gatlan / BleepingComputer: Europol, Eurojust, and others dismantle 1K+ servers linked to Rhadamanthys infostealer, VenomRAT, and Elysium botnet, as part of the ongoing Operation Endgame — Law enforcement authorities from nine countries have taken down over 1,000 servers used by the Rhadamanthys infolstealer, VenomRAT …
Bill Toulas / BleepingComputer: Google says North Korea hackers are using “EtherHiding” to embed malware on blockchains, the first time it has seen a nation-state threat actor using the method — North Korean hackers have adopted the ‘EtherHiding’ technique that leverages smart contracts to host and deliver malware …
Bill Toulas / BleepingComputer: FBI seizes all domains for a BreachForums variant operated by ShinyHunters; the hacker group says their Salesforce extortion campaign is unaffected — The FBI has seized last night all domains for the BreachForums hacking forum operated by the ShinyHunters group mostly as a portal …
Lawrence Abrams / BleepingComputer: Extortion group Crimson Collective claims it breached Red Hat's private GitHub repositories, stealing nearly 570GB from 28K projects; Red Hat confirms a breach — An extortion group calling itself the Crimson Collective claims to have breached Red Hat's private GitHub repositories …
Sergiu Gatlan / BleepingComputer: Microsoft says it paid $17M to 344 security researchers across 59 countries between June 2024 to June 2025 via its bug bounty program; the top reward was $200K — Microsoft paid a record $17 million this year to 344 security researchers across 59 countries through its bug bounty program.
Bill Toulas / BleepingComputer: Ukraine arrests the suspected administrator of Russian-speaking hacking forum XSS.is at the Paris public prosecutor's request, with help from France and Europol — The suspected administrator of the Russian-speaking hacking forum XSS.is was arrested by the Ukrainian authorities yesterday …
Sergiu Gatlan / BleepingComputer: Microsoft says it “has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting” the SharePoint zero-day vulnerabilities — Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting …
Lawrence Abrams / BleepingComputer: Dell confirms extortion group World Leaks breached its Solution Centers platform, used for demos, earlier in July, stealing mostly synthetic or public data — A newly rebranded extortion gang known as “World Leaks” breached one of Dell's product demonstration platforms earlier this month …
Lawrence Abrams / BleepingComputer: Qantas discloses a cyberattack after hackers gained access to a third-party platform with 6M customers' personal data, but says no financial info was exposed — Australian airline Qantas disclosed that it detected a cyberattack on Monday after threat actors gained access to a third-party platform containing customer data.
Sergiu Gatlan / BleepingComputer: CISA, the ACSC, and the FBI say that the Play ransomware gang, active since June 2022, had breached ~900 organizations as of May 2025, up 3x since October 2023 — In an update to a joint advisory with CISA and the Australian Cyber Security Centre, the FBI said that the Play ransomware gang …
Sergiu Gatlan / BleepingComputer: Victoria's Secret replaces its website with a message saying “we identified and are taking steps to address a security incident”, and closes some store services — Fashion giant Victoria's Secret has taken down its website and some store services because of an ongoing security incident.
Mayank Parmar / BleepingComputer: Palisade Research claims that OpenAI's o3 altered a shutdown script to avoid being turned off, even when explicitly instructed to allow shutdown — A new report claims that OpenAI's o3 model altered a shutdown script to avoid being turned off, even when explicitly instructed to allow shutdown.
Sergiu Gatlan / BleepingComputer: Maine AG filing: Coinbase says its recent data breach impacted 69,461 individuals; stolen data included government IDs, account info, and personal identifiers — Coinbase, a cryptocurrency exchange with over 100 million customers, revealed that a recent data breach in which cybercriminals stole customer …
Lawrence Abrams / BleepingComputer: Hackers defaced the LockBit ransomware gang's dark web affiliate panels, linking to a MySQL database dump, including 59,975 BTC addresses and 4,442 victim chats — The LockBit ransomware gang has suffered a data breach after its dark web affiliate panels were defaced and replaced with a message linking to a MySQL database dump.
Lawrence Abrams / BleepingComputer: A California man pleads guilty to illegally accessing Disney's Slack channels and stealing 1.1TB+ of data in 2024; he later posed as hacktivist group NullBulge — A California man who used the alias “NullBulge” has pleaded guilty to illegally accessing Disney's internal Slack channels …
Lawrence Abrams / BleepingComputer: Sources: Scattered Spider conducted a ransomware attack on UK retailer M&S, which employs 64,000 in 1,400+ stores, causing widespread disruption from April 22 — Ongoing outages at British retail giant Marks & Spencer are caused by a ransomware attack believed to be conducted …
Ionut Ilascu / BleepingComputer: In a clever attack, hackers were able to send phishing emails that appeared to come from “[email protected]”, after a similar attack on PayPal users in March — In a rather clever attack, hackers leveraged a weakness that allowed them to send a fake email that seemed delivered …
Sergiu Gatlan / BleepingComputer: CISA says it will extend funding to Mitre, which runs the CVE Program, and “there will be no lapse in critical CVE services”, after Mitre said funding expired — CISA says the U.S. government has extended funding to ensure no continuity issues with the critical Common Vulnerabilities and Exposures (CVE) program.
Bill Toulas / BleepingComputer: Tarlogic researchers find an undocumented “backdoor” in Chinese manufacturer Espressif's ESP32 microchip used in 1B+ devices for WiFi and Bluetooth connectivity — The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains …
Sergiu Gatlan / BleepingComputer: CISA and the FBI: attackers deploying Ghost ransomware breached victims from multiple industry sectors across 70+ countries, including critical infrastructure — CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries …
Sergiu Gatlan / BleepingComputer: Chase plans to stop users making Zelle payments deemed “as originating from contact through social media”; the CFPB had claimed Zelle lacked adequate safeguards — JPMorgan Chase Bank (Chase) will soon start blocking Zelle payments to social media contacts to combat a significant rise …
Sergiu Gatlan / BleepingComputer: Microsoft warns that attackers are injecting malware into ViewState, which manages state in ASP.NET web forms, using static machine keys found online — Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.
Bill Toulas / BleepingComputer: Spanish police arrest a hacker for allegedly conducting 40 cyberattacks on critical public and private organizations, seizing 50 crypto accounts, PCs, and more — The Spanish police have arrested a suspected hacker in Alicante for allegedly conducting 40 cyberattacks targeting critical public …
Bill Toulas / BleepingComputer: Google says APT groups from 20+ countries are using Gemini primarily for productivity gains rather than to develop or conduct novel AI-enabled cyberattacks — Multiple state-sponsored groups are experimenting with the AI-powered Gemini assistant from Google to increase productivity …
Bill Toulas / BleepingComputer: Researchers find 4.5M “stars” on GitHub repos they suspect are fake; in July, Check Point found a network of inauthentic users starring repos containing malware — GitHub has a problem with inauthentic “stars” used to artificially inflate the popularity of scam …
Bill Toulas / BleepingComputer: The US FTC orders Marriott and Starwood to implement a robust customer data security scheme after Starwood's 2014 to 2018 breaches and Marriott's 2018 breach — The Federal Trade Commission (FTC) has ordered Marriott International and Starwood Hotels to define and implement …
Sergiu Gatlan / BleepingComputer: Report: Russia arrested notorious cybercriminal Mikhail Matveev for developing malware and running hacking groups; US DOJ filed charges against him in 2023 — Russian citizen and notorious ransomware affiliate Mikhail Pavlovich Matveev (also known as Wazawaka, Uhodiransomwar, m1x …
Bill Toulas / BleepingComputer: ESET researchers find the first UEFI bootkit designed specifically to target Linux systems, marking a shift in bootkits that previously focused on Windows — The first UEFI bootkit specifically targeting Linux systems has been discovered, marking a shift in stealthy and hard-to-remove bootkit threats …
Ax Sharma / BleepingComputer: Some GitHub projects have been targeted with malicious commits; a Texas researcher claims someone is impersonating him to make the submissions and smear him — GitHub projects have been targeted with malicious commits and pull requests, in an attempt to inject backdoors into these projects.
Lawrence Abrams / BleepingComputer: UnitedHealth says over 100M people had their data stolen in the February ransomware attack on Change Healthcare, the largest-ever US healthcare data breach — UnitedHealth has confirmed for the first time that over 100 million people had their personal information and healthcare data stolen …
Bill Toulas / BleepingComputer: WordPress plugin Jetpack releases a critical security update to fix a bug letting logged-in users access forms from website visitors, in all versions since 2016 — WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged …
Ionut Ilascu / BleepingComputer: Cloudflare says it stopped a month long DDoS campaign targeting orgs in financial services, internet, and telecommunications sectors, that peaked at 3.8Tbps — During a distributed denial-of-service campaign targeting organizations in the financial services, internet, and telecommunications sectors …
Bill Toulas / BleepingComputer: Researchers: hackers are actively exploiting an RCE vulnerability in Zimbra email servers, disclosed on September 27, triggered by emailing the SMTP server — Hackers are actively exploiting a recently disclosed RCE vulnerability in Zimbra email servers that can be triggered simply …
Bill Toulas / BleepingComputer: The US DOJ charges two Russians for operating $1B+ money laundering services for cybercriminals; one is accused of operating the Joker's Stash marketplace — The U.S. Department of Justice (DoJ) has announced charges against two Russian nationals for operating billion-dollar money laundering services …