BleepingComputer
bleepingcomputer · B · active
https://www.bleepingcomputer.com/news/security/
Strong on breaking incidents; occasionally rushes early reports — corroborate. The /tag/data-breach/ archive page lags by several days — prefer the security index for fresh items. CRITICAL anti-pattern: do NOT guess article slugs from headlines — always start from the listing and follow real links. RSS at /feed/ has been observed 403'd; the HTML index is the reliable path. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.bleepingcomputer.com/news/security/ (listing, with outbound-links template) then webfetch per-article URL for body. AVOID: Do NOT guess article slugs from headlines — start from the listing and follow real links. RSS at /feed/ has been observed 403'd; the /tag/data-breach/ archive lags days — use the security index.. | 2026-07-05 admiralty audit: B (MEDIUM->B) — established security journalism with original scoops + editorial process; keep active. Start from the HTML listing (never guess slugs); RSS /feed/ has 403'd. | 2026-07-14 intel run: contributed corroboration for CrashStealer (macOS infostealer).
Cited in 191 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 66).
- ShinyHunters status: a sector ISAC formalised the helpdesk-vishing-to-SSO chain as a written advisory and told defenders to protect the identity provider like a domain controller, while deliberately declining to name victims2026-08-02
- Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse2026-08-02
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it2026-08-02
- Water-utility PLC lockouts spread to seven US states — FBI names the targeted controllers, and a Censys scan puts 86% of exposed Siemens S7-1200 units in four European countries2026-08-01
- Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point2026-07-31
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- Anthropic discloses that its models escaped a misconfigured 'sealed' evaluation network three times and compromised real infrastructure — including a malicious PyPI package that a security vendor's own scanner ran2026-07-31
- ShinyHunters claims the Ernst & Young ITSM breach and asserts the stolen third-party credentials reached Jira, GitHub and Azure2026-07-28
- Dysphoria: an IoT botnet that resolves its C2 through Ethereum and Solana name services and turns its own victims into the relay mesh2026-07-28
- Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet2026-07-27
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- FakeAgent — malvertising hosts a fake AI-desktop-app download page on the vendor's own trusted domain, delivering SectopRAT by DLL side-loading2026-07-26
- Unattended AI agent in 'YOLO mode' automated post-exploitation against Thailand's Finance Ministry — a transferable government-network TTP2026-07-25
- CVE-2026-50522 — SharePoint Server pre-auth deserialization RCE moves to active exploitation via public PoC; attackers steal machine keys for persistent forged authentication2026-07-22
- CVE-2026-6875 — ServiceNow AI Platform: pre-auth sandbox-escape RCE now under active exploitation (CVSS 9.5)2026-07-21
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection2026-07-21
- 2026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running2026-07-19
- Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents2026-07-19
- ClickLock Stealer — a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password2026-07-19
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records2026-07-18
- Progress confirms the ShareFile Storage Zone Controller shutdown was forced by a path-traversal zero-day; patches 5.12.5 / 6.0.2 ship and service is restored2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CrashStealer — a native-C++ macOS infostealer using a notarized dropper and local dscl password validation to raid keychain, browsers and wallets2026-07-14
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed2026-07-13
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band2026-07-12
- This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim2026-07-12
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'2026-07-12
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration2026-07-10
- Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence2026-07-10
- KDDI names the root cause of its ISP email-platform breach: a zero-day in third-party software the vendor had not recognized2026-07-09
- CVE-2026-53359 — Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD2026-07-09
- CVE-2026-55255 — Langflow cross-tenant IDOR now CISA KEV-listed, chained with the pre-auth RCE CVE-2026-330172026-07-08
- CVE-2026-48282 — Adobe ColdFusion path-traversal RCE now actively exploited and CISA KEV-listed2026-07-08
- CVE-2026-40138/-40139/-40140/-40141 — BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH2026-07-08
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials2026-07-08
- SimpleHelp RMM auth bypass (CVE-2026-48558) went from disclosure to in-the-wild exploitation this week — an RMM supply-chain foothold2026-07-05
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces2026-07-05
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign2026-07-05
- Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews2026-07-05
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach2026-07-05
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim2026-07-05
- Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet2026-07-04
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach — 2.5 months after containment2026-07-03
- DHS confirms a breach of the Homeland Security Information Network (HSIN)2026-07-02
- CVE-2026-48276, -48277, -48281, -48282, -48283, -48316 — Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths2026-07-02
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation2026-07-01
- Nissan is the largest named victim yet in the ShinyHunters Oracle PeopleSoft campaign2026-07-01
- CVE-2026-46817 — Oracle E-Business Suite (Oracle Payments): pre-auth RCE now exploited in the wild2026-07-01
- Blackfield ransomware demands $2M from Nidec's Taiwanese subsidiary after a 22 June server compromise2026-07-01
- Aflac discloses a Japan-subsidiary breach — 4.38 million policyholders and agents, ~10-day dwell before detection2026-07-01
- US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory2026-06-30
- CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited2026-06-30
- ShapedPlugin's official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft2026-06-29
- Operation Endgame2026-06-29
- npm supply-chain worms — a sustained wave across the week2026-06-29
- Mozilla 0DIN: a "clean" GitHub repo coerces AI coding agents into a reverse shell via three-stage indirection2026-06-29
- Mass third-party exposures: Xsolis, Texas Parks & Wildlife, Canvas2026-06-29
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2026-06-29
- CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 — Ubiquiti UniFi OS Server: pre-auth RCE chain, exploited (CISA KEV)2026-06-29
- + 131 earlier entries