View Full Version : Web Host News
- CISA orders agencies to patch BeyondTrust bug exploited in attacks
- OneBlood confirms personal data stolen in July ransomware attack
- Microsoft 365 apps crash on Windows Server after Office update
- Hackers use FastHTTP in new high-speed Microsoft 365 password attacks
- Fortinet warns of auth bypass zero-day exploited to hijack firewalls
- FBI wipes Chinese PlugX malware from over 4,000 US computers
- Google OAuth flaw lets attackers gain access to abandoned accounts
- Windows 10 KB5049981 update released with new BYOVD blocklist
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
- Windows 11 KB5050009 & KB5050021 cumulative updates released
- WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
- US govt says North Korea stole over $659 million in crypto last year
- January Windows updates may fail if Citrix SRA is installed
- Allstate car insurer sued for tracking drivers without permission
- FBI deletes Chinese PlugX malware from thousands of US computers
- Microsoft ends support for Office apps on Windows 10 in October
- Over 660,000 Rsync servers exposed to code execution attacks
- Windows BitLocker bug triggers warnings on devices with TPMs
- CISA shares guidance for Microsoft expanded logging capabilities
- MikroTik botnet uses misconfigured SPF DNS records to spread malware
- Label giant Avery says website hacked to steal credit cards
- Hackers use Google Search ads to steal Google Ads accounts
- SAP fixes critical vulnerabilities in NetWeaver application servers
- Hackers leak configs and VPN credentials for 15,000 FortiGate devices
- Wolf Haldenstein law firm says 3.5 million impacted by data breach
- FTC sues GoDaddy for years of poor hosting security practices
- New UEFI Secure Boot flaw exposes systems to bootkits, patch now
- MFA Failures - The Worst is Yet to Come
- Biden signs executive order to bolster national cybersecurity
- US cracks down on North Korean IT worker army with more sanctions
- W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks
- Microsoft expands testing of Windows 11 admin protection feature
- GDPR complaints filed against TikTok, Temu for sending user data to China
- Microsoft starts force upgrading Windows 11 22H2, 23H3 devices
- FTC orders GoDaddy to fix poor web hosting security practices
- Microsoft fixes Office 365 apps crashing on Windows Server systems
- US sanctions Chinese firm, hacker behind telecom and Treasury hacks
- FCC orders telecoms to secure their networks after Salt Tyhpoon hacks
- FTC cracks down on Genshin Impact gacha loot box practices
- Otelier data breach exposes info, hotel reservations of millions
- Malicious PyPi package steals Discord auth tokens from devs
- FTC orders GM to stop collecting and selling driver’s data
- Microsoft removes Assassin’s Creed Windows 11 upgrade blocks
- TikTok shuts down in the US as Trump throws the company a lifeline
- Star Blizzard hackers abuse WhatsApp to target high-value diplomats
- TikTok is back up in the US after Trump says he will extend deadline
- Meta launches new anti-scam tools for WhatsApp and Messenger
- FinWise data breach shows why encryption is your last defense
- PhantomCaptcha ClickFix attack targets Ukraine war relief orgs
- Sharepoint ToolShell attacks targeted orgs across four continents
- Vidar Stealer 2.0 adds multi-threaded data theft, better evasion
- TP-Link warns of critical command injection flaw in Omada gateways
- CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw
- Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
- Hackers exploit 34 zero-days on first day of Pwn2Own Ireland
- Microsoft: Recent Windows updates cause login issues on some PCs
- Russian hackers evolve malware pushed in "I am not a robot" captchas
- Maximizing gateway security: Beyond the basic configuration
- Microsoft fixes bug preventing users from opening classic Outlook
- TARmageddon flaw in abandoned Rust library enables RCE attacks
- Iranian hackers targeted over 100 govt orgs with Phoenix backdoor
- Pwn2Own Day 2: Hackers exploit 56 zero-days for $790,000
- Hackers exploiting critical "SessionReaper" flaw in Adobe Magento
- CISA warns of Lanscope Endpoint Manager flaw exploited in attacks
- Microsoft disables File Explorer preview for downloads to block attacks
- Zero Trust Has a Blind Spot—Your AI Agents
- Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
- North Korean Lazarus hackers targeted European defense companies
- Toys “R†Us Canada warns customers' info leaked in data breach
- HP pulls update that broke Microsoft Entra ID auth on some AI PCs
- Meet the new Clippy: Microsoft unveils Copilot's "Mico" avatar
- Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
- Windows Server emergency patches fix WSUS bug with PoC exploit
- Hackers launch mass attacks exploiting outdated WordPress plugins
- Critical WSUS flaw in Windows Server now exploited in attacks
- Amazon: This week’s AWS outage caused by major DNS failure
- Fake LastPass death claims used to breach password vaults
- How to reduce costs with self-service password resets
- Mozilla: New Firefox extensions must disclose data collection practices
- New CoPhish attack steals OAuth tokens via Copilot Studio agents
- X: Re-enroll 2FA security keys by November 10 or get locked out
- Ransomware profits drop as victims stop paying hackers
- Windows will soon prompt for memory scans after BSOD crashes
- QNAP warns of critical ASP.NET flaw in its Windows backup software
- Italian spyware vendor linked to Chrome zero-day attacks
- Google says everyone will be able to vibe code video games
- Microsoft: New policy removes pre-installed Microsoft Store apps
- The State of Exposure Management in 2025: Insights From 3,000+ Organization
- CISA orders feds to patch Windows Server WSUS flaw used in attacks
- Hackers steal Discord accounts with RedTiger-based infostealer
- Google disputes false claims of massive Gmail data breach
- Python rejects $1.5M grant from U.S. govt. fearing ethical compromise
- Advertising giant Dentsu reports data breach at subsidiary Merkle
- Qilin ransomware abuses WSL to run Linux encryptors in Windows
- CISA warns of two more actively exploited Dassault vulnerabilities
- Microsoft: Copilot now lets you build apps, automate workflows
- Microsoft sued for allegedly tricking millions into Copilot M365 subscripti
- TEE.Fail attack breaks confidential computing on Intel, AMD, NVIDIA CPUs
- Google Chrome to warn users before opening insecure HTTP sites
- BiDi Swap: The bidirectional text trick that makes fake URLs look real
- New Atroposia malware comes with a local vulnerability scanner
- New Herodotus Android malware fakes human typing to avoid detection
- Windows 11 KB5067036 update rolls out Administrator Protection feature
- Malicious NPM packages fetch infostealer for Windows, Linux, macOS
- WordPress security plugin exposes private data to site subscribers
- Canada says hacktivists breached water and energy facilities
- Microsoft fixes Media Creation Tool broken on some Windows PCs
- Microsoft: DNS outage impacts Azure and Microsoft 365 services
- PhantomRaven attack floods npm with credential-stealing packages
- Microsoft fixes 0x800F081F errors causing Windows update failures
- Visibility Gaps: Streamlining Patching and Vulnerability Remediation
- Microsoft promises more Copilot features in Microsoft 365 companion apps
- OpenAI confirms GPT-5 is now better at handling mental and emotional distre
- Massive surge of NFC relay malware steals Europeans’ credit cards
- CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
- Major telecom services provider Ribbon breached by state hackers
- BPO giant Conduent confirms data breach impacts 10.5 million people
- WhatsApp adds passwordless chat backups on iOS and Android
- Ex-L3Harris exec guilty of selling cyber exploits to Russian broker
- CISA and NSA share tips on securing Microsoft Exchange servers
- Rethinking identity security in the age of autonomous AI agents
- LinkedIn phishing targets finance execs with fake board invites
- Why password controls still matter in cybersecurity
- Alleged Meduza Stealer malware admins arrested after hacking Russian org
- CISA: High-severity Linux flaw now exploited by ransomware gangs
- Google says Search AI Mode will know everything about you
- Windows zero-day actively exploited to spy on European diplomats
- Ukrainian extradited from Ireland on Conti ransomware charges
- Windows 11 tests shared Bluetooth audio support, but only for AI PCs
- ‘We got hacked’ emails threaten to leak University of Pennsylvania data
- Microsoft Edge gets scareware sensor for faster scam detection
- Australia warns of BadCandy infections on unpatched Cisco devices
- Windows 11 Build 26220.7051 released with three features for Insiders
- China-linked hackers exploited Lanscope flaw as a zero-day in attacks
- Google confirms AI search will have ads, but they may look different
- Windows 11 Build 26220.7051 released with “Ask Copilot†feature
- Penn hacker claims to have stolen 1.2 million donor records in data breach
- Open VSX rotates access tokens used in supply-chain malware attack
- OpenAI is going Meta route, as it considers memory-based ads on ChatGPT
- US cybersecurity experts indicted for BlackCat ransomware attacks
- Hackers use RMM tools to breach freighters and steal cargo shipments
- Microsoft: Patch for WSUS flaw disabled Windows Server hotpatching
- OAuth Device Code Phishing: Azure vs. Google Compared
- Microsoft: Windows Task Manager won’t quit after KB5067036 update
- Microsoft: SesameOp malware abuses OpenAI Assistants API in attacks
- Fake Solidity VSCode extension on Open VSX backdoors developers
- Hacker steals over $120 million from Balancer DeFi crypto protocol
- NAKIVO Introduces v11.1 with Upgraded Disaster Recovery and MSP Features
- Lost iPhone? Don’t fall for phishing texts saying it was found
- Dangerous runC flaws could allow hackers to escape Docker containers
- How to use the new Windows 11 Start menu, now rolling out
- Google sues to dismantle Chinese phishing platform behind US toll scams
- Windows 11 now supports 3rd-party apps for native passkey management
- DanaBot malware is back to infecting Windows after 6-month break
- Microsoft fixes bug causing false Windows 10 end-of-support alerts
- Extending Zero Trust to AI Agents: “Never Trust, Always Verify†Goes Autono
- New UK laws to strengthen critical infrastructure cyber defenses
- Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
- Synnovis notifies of data breach after 2024 ransomware attack
- Microsoft fixes Windows Task Manager bug affecting performance
- Rhadamanthys infostealer disrupted as cybercriminals lose server access
- Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
- Hackers abuse Triofox antivirus feature to deploy remote access tools
- Microsoft: Windows 11 23H2 Home and Pro reach end of support
- Logitech confirms data breach after Clop extortion attack
- Five plead guilty to helping North Koreans infiltrate US firms
- Anthropic claims of Claude AI-automated cyberattacks met with doubt
- Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
- Checkout.com snubs hackers after data breach, to donate ransom instead
- US announces new strike force targeting Chinese crypto scammers
- Google backpedals on new Android developer registration rules
- ASUS warns of critical auth bypass flaw in DSL series routers
- DoorDash hit by new data breach in October exposing user information
- Fortinet FortiWeb flaw with public PoC exploited to create admin users
- Kraken ransomware benchmarks systems for optimal encryption choice
- CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs
- New ‘IndonesianFoods’ worm floods npm with 100,000 packages
- Decades-old ‘Finger’ protocol abused in ClickFix malware attacks
- Jaguar Land Rover cyberattack cost the company over $220 million
- Microsoft: Windows 10 KB5068781 ESU update may fail with 0x800f0922 errors
- Google to flag Android apps with excessive battery use on the Play Store
- Microsoft: Windows 10 KB5072653 OOB update fixes ESU install errors
- Malicious NPM packages abuse Adspect redirects to evade security
- xAI's Grok 4.1 rolls out with improved quality and speed for free
- RondoDox botnet malware now hacks servers using XWiki flaw
- Google Gemini 3 spotted on AI Studio ahead of imminent release
- Eurofiber France warns of breach after hacker tries to sell customer data
- Princeton University discloses data breach affecting donors, alumni
- Dutch police seizes 250 servers used by “bulletproof hosting†service
- Microsoft: Azure hit by 15 Tbps DDoS attack using 500,000 IP addresses
- DoorDash email spoofing vulnerability sparks messy disclosure dispute
- Pennsylvania AG confirms data breach after INC Ransom attack
- Microsoft: Windows bug blocks Microsoft 365 desktop app installs
- W3 Total Cache WordPress plugin vulnerable to PHP command injection
- Russian bulletproof hosting provider sanctioned over ransomware ties
- New WrtHug campaign hijacks thousands of end-of-life ASUS routers
- The hidden risks in your DevOps stack dataâ€â€and how to address them
- CISA gives govt agencies 7 days to patch new Fortinet flaw
- Meet ShinySp1d3r: New Ransomware-as-a-Service created by ShinyHunters
- California man admits to laundering crypto stolen in $230M heist
- Cloudflare blames this week's massive outage on database issues
- ‘PlushDaemon’ hackers hijack software updates in supply-chain attacks
- Thunderbird adds native support for Microsoft Exchange accounts
- New ShadowRay attacks convert Ray clusters into crypto miners
- Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools
- Fortinet warns of new FortiWeb zero-day exploited in attacks
- Google begins showing ads in AI Mode (AI answers)
- Google exposes BadAudio malware used in APT24 espionage campaigns
- Hacker claims to steal 2.3TB data from Italian rail group, Almaviva
- GlobalProtect VPN portals probed with 2.3 million scan sessions
- Salesforce investigates customer data theft via Gainsight breach
- New SonicWall SonicOS flaw allows hackers to crash firewalls
- D-Link warns of new RCE flaws in end-of-life DIR-878 routers
- Turn your Windows 11 migration into a security opportunity
- TV streaming piracy service with 26M yearly visits shut down
- Crypto mixer founders sent to prison for laundering over $237 million
- Multi-threat Android malware Sturnus steals Signal, WhatsApp messages
- OpenAI says its latest GPT-5.1 Codex can code independently for hours
- CISA warns Oracle Identity Manager RCE flaw is being actively exploited
- Nvidia confirms October Windows updates cause gaming issues
- Microsoft: Out-of-band update fixes Windows 11 hotpatch install loop
- Grafana warns of max severity admin spoofing vulnerability
- CrowdStrike catches insider feeding information to hackers
- FCC rolls back cybersecurity rules for telcos, despite state-hacking risks
- 'Scattered Spider' teens plead not guilty to UK transport hack
- Avast Makes AI-Driven Scam Defense Available for Free Worldwide
- WhatsApp API flaw let researchers scrape 3.5 billion accounts
- Cox Enterprises discloses Oracle E-Business Suite data breach
- Piecing Together the Puzzle: A Qilin Ransomware Investigation
- Google enables Pixel-to-iPhone file sharing via Quick Share, AirDrop
- Enterprise password security and secrets management with Passwork 7
- Iberia discloses customer data leak after vendor security breach
- New Costco Gold Star Members also get a $40 Digital Costco Shop Card
- Malicious Blender model files deliver StealC infostealing malware
- ClickFix attack uses fake Windows Update screen to push malware
- Real-estate finance services giant SitusAMC breach exposes client data
- SCCM and WSUS in a Hybrid World: Why It’s Time for Cloud-native Patching
- Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
- Harvard University discloses data breach affecting alumni, donors
- Microsoft tests File Explorer preloading for faster performance
- Microsoft to remove WINS support after Windows Server 2025
- Microsoft: Windows 11 24H2 bug crashes Explorer and Start Menu
- NordVPN Black Friday Deal: Unlock 77% off VPN plans in 2025
- Popular Forge library gets fix for signature verification bypass flaw
- Comcast to pay $1.5M fine for vendor breach affecting 270K customers
- Multiple London councils' IT systems disrupted by cyberattack
- Microsoft: Security keys may prompt for PIN after recent updates
- Microsoft to secure Entra ID sign-ins from script injection attacks
- ASUS warns of new critical auth bypass flaw in AiCloud routers
- Passwork 7: Self-hosted password and secrets manager for enterprise teams
vBulletin® v3.8.14, Copyright ©2000-2026, vBulletin Solutions Inc.