BleepingComputer
bleepingcomputer · B · active
https://www.bleepingcomputer.com/news/security/
Strong on breaking incidents; occasionally rushes early reports — corroborate. The /tag/data-breach/ archive page lags by several days — prefer the security index for fresh items. CRITICAL anti-pattern: do NOT guess article slugs from headlines — always start from the listing and follow real links. RSS at /feed/ has been observed 403'd; the HTML index is the reliable path. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.bleepingcomputer.com/news/security/ (listing, with outbound-links template) then webfetch per-article URL for body. AVOID: Do NOT guess article slugs from headlines — start from the listing and follow real links. RSS at /feed/ has been observed 403'd; the /tag/data-breach/ archive lags days — use the security index.. | 2026-07-05 admiralty audit: B (MEDIUM->B) — established security journalism with original scoops + editorial process; keep active. Start from the HTML listing (never guess slugs); RSS /feed/ has 403'd. | 2026-07-14 intel run: contributed corroboration for CrashStealer (macOS infostealer).
Cited in 171 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 55).
- Progress confirms the ShareFile Storage Zone Controller shutdown was forced by a path-traversal zero-day; patches 5.12.5 / 6.0.2 ship and service is restored2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CrashStealer — a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets2026-07-14
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed2026-07-13
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band2026-07-12
- This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim2026-07-12
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'2026-07-12
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration2026-07-10
- Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence2026-07-10
- KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized2026-07-09
- CVE-2026-53359 — Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD2026-07-09
- CVE-2026-55255 — Langflow cross-tenant IDOR now CISA KEV-listed, chained with the pre-auth RCE CVE-2026-330172026-07-08
- CVE-2026-48282 — Adobe ColdFusion path-traversal RCE now actively exploited and CISA KEV-listed2026-07-08
- CVE-2026-40138/-40139/-40140/-40141 — BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH2026-07-08
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials2026-07-08
- SimpleHelp RMM auth bypass (CVE-2026-48558) went from disclosure to in-the-wild exploitation this week — an RMM supply-chain foothold2026-07-05
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces2026-07-05
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign2026-07-05
- Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews2026-07-05
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach2026-07-05
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim2026-07-05
- Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet2026-07-04
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment2026-07-03
- DHS confirms a breach of the Homeland Security Information Network (HSIN)2026-07-02
- CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths2026-07-02
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation2026-07-01
- Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign2026-07-01
- CVE-2026-46817 — Oracle E-Business Suite (Oracle Payments): pre-auth RCE now exploited in the wild2026-07-01
- Blackfield ransomware demands $2M from Nidec's Taiwanese subsidiary after a 22 June server compromise2026-07-01
- Aflac discloses a Japan-subsidiary breach — 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory2026-06-30
- CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited2026-06-30
- ShapedPlugin's official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft2026-06-29
- Operation Endgame2026-06-29
- npm supply-chain worms — a sustained wave across the week2026-06-29
- Mozilla 0DIN: a "clean" GitHub repo coerces AI coding agents into a reverse shell via three-stage indirection2026-06-29
- Mass third-party exposures: Xsolis, Texas Parks & Wildlife, Canvas2026-06-29
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2026-06-29
- CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 — Ubiquiti UniFi OS Server: pre-auth RCE chain, exploited (CISA KEV)2026-06-29
- CVE-2026-20230 — Cisco Unified CM WebDialer: pre-auth SSRF to arbitrary root file write, reconnaissance-stage scanning observed2026-06-29
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone2026-06-25
- Edgecution: abusing the Chrome/Edge Native Messaging API as a browser-sandbox-to-host bridge2026-06-25
- Ubiquiti UniFi OS triple-flaw chain to unauthenticated root (CVE-2026-34908 / -34909 / -34910)2026-06-24
- macOS ClickFix evolves: hdiutil attach -nobrowse mounts the malicious DMG invisibly before dropping AMOS2026-06-24
- CVE-2026-20230 — Cisco Unified CM: WebDialer SSRF to arbitrary file write to root, reconnaissance-stage exploitation observed2026-06-24
- ShapedPlugin build pipeline compromised — three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell2026-06-23
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE2026-06-23
- Threat actor: DPRK Sapphire Sleet escalates npm supply-chain attacks with the Mastra compromise2026-06-22
- The third-party breach as the week's dominant entry vector2026-06-22
- Technology & SaaS supply chain — the week's busiest victim class2026-06-22
- Public administration — named European institutions and government data in the firing line2026-06-22
- FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory2026-06-22
- Energy, water & OT — perimeter and process failures, with an OT-adjacent halt2026-06-22
- AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS2026-06-22
- Texas Parks & Wildlife: 3.08M licence holders exposed via an unnamed third-party vendor — with a public-vs-AG-filing SSN contradiction2026-06-21
- Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom note2026-06-21
- Mastra npm scope compromise attributed to North Korea, with the access vector our deep dive could not name2026-06-21
- Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed2026-06-21
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems2026-06-20
- + 111 earlier entries