B
BleepingComputer
Bleepingcomputer
RSSen

BleepingComputer - All Stories

Information
Followers
Following
AI Overview
13 posts analyzed·Updated 3/11/2026

Key Highlights

  • Russian-speaking threat actor targets HR departments with new EDR killer malware called BlackSanta. 1 post

  • Microsoft's March 2026 Patch Tuesday fixes 79 flaws including 2 zero-days, with extended security updates for Windows 10 and cumulative updates for Windows 11. 3 posts

  • New Android malware BeatBanker poses as Starlink app to hijack devices, while KadNap botnet targets ASUS routers for proxy networks. 2 posts

Main Topics (4)

Latest posts

website-logo

Meta adds new WhatsApp, Facebook, and Messenger anti-scam tools

BleepingComputer

Meta is introducing new anti-scam protections across its platforms, deploying systems and user-facing warnings to protect users against scammers. [...]

website-logo

New ‘BlackSanta’ EDR killer spotted targeting HR departments

BleepingComputer

For more than a year, a Russian-speaking threat actor targeted human resource (HR) departments with malware that delivers a new EDR killer named BlackSanta. [...]

website-logo

New BeatBanker Android malware poses as Starlink app to hijack devices

BleepingComputer

A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. [...]

website-logo

New 'Zombie ZIP' technique lets malware slip past security tools

BleepingComputer

A new technique dubbed "Zombie ZIP" helps conceal payloads in compressed files specially created to avoid detection from security solutions such as antivirus and endpoint detection and response (EDR) products. [...]

website-logo

Microsoft releases Windows 10 KB5078885 extended security update

BleepingComputer

Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting down. [...]

website-logo

Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws

BleepingComputer

Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities. [...]

website-logo

Windows 11 KB5079473 & KB5078883 cumulative updates released

BleepingComputer

Microsoft has released Windows 11 KB5079473 and KB5078883 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]

website-logo

HPE warns of critical AOS-CX flaw allowing admin password resets

BleepingComputer

Hewlett Packard Enterprise (HPE) has patched multiple security vulnerabilities in the Aruba Networking AOS-CX operating system, including several authentication and code execution issues. [...]

website-logo

Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys

BleepingComputer

Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, adding phishing-resistant passwordless authentication via Windows Hello. [...]

website-logo

New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network

BleepingComputer

A newly discovered botnet malware called KadNap is targeting ASUS routers and other edge networking devices to turn them into proxies for malicious traffic. [...]

website-logo

The New Turing Test: How Threats Use Geometry to Prove 'Humanness'

BleepingComputer

Malware is evolving to evade sandboxes by pretending to be a real human behind the keyboard. The Picus Red Report 2026 shows 80% of top attacker techniques now focus on evasion and persistence, including geometry-based cursor tests and CPU timing checks. [...]

website-logo

CISA: Recently patched Ivanti EPM flaw now actively exploited

BleepingComputer

CISA flagged a high-severity Ivanti Endpoint Manager (EPM) vulnerability as actively exploited in attacks and ordered U.S. federal agencies to patch systems within three weeks. [...]

website-logo

Microsoft to enable Windows hotpatch security updates by default

BleepingComputer

Microsoft will turn on hotpatch security updates by default for all eligible Windows devices managed through Microsoft Intune and the Microsoft Graph API, beginning with the May 2026 Windows security update. [...]

website-logo

APT28 hackers deploy customized variant of Covenant open-source tool

BleepingComputer

The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. [...]

website-logo

Microsoft Teams phishing targets employees with A0Backdoor malware

BleepingComputer

Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor. [...]

Google: Cloud attacks exploit flaws more than weak credentials

BleepingComputer

Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just days. [...]

website-logo

Dutch govt warns of Signal, WhatsApp account hijacking attacks

BleepingComputer

Russian state-sponsored hackers have been linked to an ongoing Signal and WhatsApp phishing campaign targeting government officials, military personnel, and journalists to gain access to sensitive messages. [...]

website-logo

Ericsson US discloses data breach after service provider hack

BleepingComputer

Ericsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to over 15,000 employees and customers after hacking one of its service providers. [...]

website-logo

Microsoft Teams will tag third-party bots trying to join meetings

BleepingComputer

Microsoft says Teams will soon automatically tag third-party bots in lobbies, allowing organizers to control whether they can join meetings. [...]

website-logo

ShinyHunters claims ongoing Salesforce Aura data theft attacks

BleepingComputer

Salesforce is warning customers that hackers are targeting websites with misconfigured Experience Cloud platforms that give guest users access to more data than intended. However, the ShinyHunters extortion gang claims to be actively exploiting a new bug to steal data from instances. [...]

website-logo

FBI warns of phishing attacks impersonating US city, county officials

BleepingComputer

The Federal Bureau of Investigation (FBI) warns that criminals are impersonating U.S. officials in phishing attacks targeting businesses and individuals who request city and county planning and zoning permits. [...]

website-logo

Why Password Audits Miss the Accounts Attackers Actually Want

BleepingComputer

Password audits often focus on complexity rules but miss the accounts attackers actually target. Specops Software explains how breached passwords, orphaned users, and service accounts can leave organizations exposed. [...]

website-logo

Microsoft still working to fix Windows Explorer white flashes

BleepingComputer

Microsoft has confirmed that it's still working to fully address a known issue that causes bright white flashes when opening the File Explorer on some Windows 11 systems. [...]

website-logo

EU court adviser says banks must immediately refund phishing victims

BleepingComputer

Athanasios Rantos, the Advocate General of the Court of Justice of the EU (CJEU), has issued a formal opinion suggesting that banks must immediately refund account holders affected by unauthorized transactions, even when it's their fault. [...]

website-logo

Hackers abuse .arpa DNS and ipv6 to evade phishing defenses

BleepingComputer

Threat actors are abusing the special-use ".arpa" domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation checks and email security gateways. [...]