Skip to main content

BleepingComputer.com

"Cloudflare now blocks all unencrypted traffic to its API end points."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 22 March 2025, 1613 UTC.

Content and Source:   https://www.bleepingcomputer.com/

Please check link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Cloudflare now blocks all unencrypted traffic to its API endpoints

  • Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com.

  • Microsoft
     

Microsoft Trust Signing service abused to code-sign malware

  • Cybercriminals are abusing Microsoft's Trusted Signing platform to code-sign malware executables with short-lived three-day certificates.

  • Push Security
     

2024: A year of identity attacks | Get the new ebook 

  • Identity attacks were rampant in 2024 as attackers doubled down on identity-based TTPs. Prepare to defend your organization in 2025 by looking back at identity-based breaches in 2024.

    Get a free Ebook on the most impactful identity breaches of 2024, and the attacker tooling and techniques that we can expect in 2025.

  • Koofr
     

Save an extra $40 on this Koofr 1TB lifetime cloud storage plan deal

  • Koofr's lifetime cloud storage subscription lets you pay once, then never worry about recurring fees again. Through March 30, you can grab 1TB of cloud storage for $40 less than usual with code KOOFR at checkout. Normally $159.99, this code drops the price to $119.97.

    • BleepingComputer Deals
    •  
    • March 22, 2025
    •  
    • 08:12 AM
    •  
    • Comment Count 0
  • Coinbase
     

Coinbase was primary target of recent GitHub Actions breaches

  • Researchers have determined that Coinbase was the primary target in a recent GitHub Actions cascading supply chain attack that compromised secrets in hundreds of repositories.

  • Oracle
     

Oracle denies breach after hacker claims theft of 6 million data records

  • Oracle denies it was breached after a threat actor claimed to be selling 6 million data records allegedly stolen from the company's Oracle Cloud federated SSO login servers

  • Take this free-standing 15.6-inch portable monitor anywhere
     

Take this free-standing 15.6-inch portable monitor anywhere

  • Second monitors aren't reserved for desktop users anymore. Laptop users can expand their workspace without compromising portability with a Fold Travel Monitor. This 15.6-inch FHD monitor has its own folding base that doubles as a screen protector in transit, and it's on sale for $149.99. 

    • BleepingComputer Deals
    •  
    • March 21, 2025
    •  
    • 02:05 PM
    •  
    • Comment Count 0
  • Google
     

Fake Semrush ads used to steal SEO professionals’ Google accounts

  • A new phishing campaign is targeting SEO professionals with malicious Semrush Google Ads that aim to steal their Google account credentials.

  • Exchange Online
     

Microsoft: Exchange Online bug mistakenly quarantines user emails

  • Microsoft is investigating an Exchange Online bug causing anti-spam systems to mistakenly quarantine some users' emails.

  • Tornado Cash
     

US removes sanctions against Tornado Cash crypto mixer

  • The U.S. Department of Treasury announced today that it has removed sanctions against the Tornado Cash cryptocurrency mixer, which North Korean Lazarus hackers used to launder hundreds of millions stolen in multiple crypto heists.

  • Steam
     

Steam pulls game demo infecting Windows with info-stealing malware

  • Valve has removed a game titled 'Sniper: Phantom's Resolution' from the Steam store following multiple user reports that indicated its demo installer actually infected their systems with information stealing malware.

  • AdGuard Home
     

AdGuard wipes out ads, pop-ups, and trackers for life in this deal

  • This powerful ad blocker works across phones, tablets, and computers, effectively erasing ads from every corner of your online experience. Unlike many apps that require recurring subscriptions, you can get an AdGuard lifetime subscription for nine devices for $15.97 with code FAMPLAN at checkout through March 30 (reg. $39.99).

    • BleepingComputer Deals
    •  
    • March 21, 2025
    •  
    • 07:09 AM
    •  
    • Comment Count 0
  • Veeam
     

Veeam RCE bug lets domain users hack backup servers, patch now

  • Veeam has patched a critical remote code execution vulnerability tracked as CVE-2025-23120 in its Backup & Replication software that impacts domain-joined installations.

  • CISA
     

CISA tags NAKIVO backup flaw as actively exploited in attacks

  • CISA has warned U.S. federal agencies to secure their networks against attacks exploiting a high-severity vulnerability in NAKIVO's Backup & Replication software.

  • VSCode
     

VSCode extensions found downloading early-stage ransomware

  • Two malicious VSCode Marketplace extensions were found deploying in-development ransomware from a remote server, exposing critical gaps in Microsoft's review process.

  • Cisco
     

Critical Cisco Smart Licensing Utility flaws now exploited in attacks

  • Attackers have started targeting Cisco Smart Licensing Utility (CSLU) instances unpatched against a vulnerability exposing a built-in backdoor admin account.

  • CompTIA
     

Last chance: Get 17 CompTIA training courses for under $50

  • The Complete 2025 CompTIA Certification Training Super Bundle by IDUNOVA includes 17 prep courses across many disciplines, helping you prepare for virtually any IT career. Get lifetime access to every course for $49.99—breaking down to less than $3 each (reg. $493). This offer expires on March 31.

    • BleepingComputer Deals
    •  
    • March 20, 2025
    •  
    • 02:02 PM
    •  
    • Comment Count 0
  • Hacker data theft
     

RansomHub ransomware uses new Betruger ‘multi-function’ backdoor

  • Security researchers have linked a new backdoor dubbed Betruger, deployed in several recent ransomware attacks, to an affiliate of the RansomHub operation.

  • UK
     

UK urges critical orgs to adopt quantum cryptography by 2035

  • The UK's National Cyber Security Centre (NCSC) has published specific timelines on migrating to post-quantum cryptography (PQC), dictating that critical organizations should complete migration by 2035.

  • WordPress
     

WordPress security plugin WP Ghost vulnerable to remote code execution bug

  • Popular WordPress security plugin WP Ghost is vulnerable to a critical severity flaw that could allow unauthenticated attackers to remotely execute code and hijack servers.

  • GitHub
     

GitHub Action supply chain attack exposed secrets in 218 repos

  • The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it, with it estimated that only 218 repositories exposed secrets due to the supply chain attack.

View More

Comments

Popular posts from this blog

Cyber War News Today.

"International Defence Cooperation:  A key to regional stability." Views expressed in this cybersecurity, cyber espionage, and cyber crime update are those of the reporters and correspondents.  Accessed on 15 December 2024, 0134 UTC. Content and Source:   https://cyberwar.einnews.com/news/cyber-war-news?n=2&code=FA9GNesSTpp2rjO1&utm_source=NewsletterNews&utm_medium=email&utm_campaign=Cyber+War+News&utm_content=navig Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). Cyber War News Monitoring Get by    Email    •     RSS Published on  Dec 13, 2024 The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 13.3% WILMINGTON, DE, UNITED STATES, December 13, 2024 /⁨EINPresswire.com⁩/ -- According to the report, The Cyber Warfare Market Size Reach USD 127.1 Billion by 2032 Exhibiting CAGR at 1...

The Cyberwire Daily Briefing

"Fortinet confirms breach of customer data." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 15 September 2024, 1339 UTC. Content and Source:   https://thecyberwire.com/newsletters/daily-briefing/13/176 Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net). V13 | Issue 176 | 9.13.24 Daily Briefing for 09.13.24 Announcement Cloud Security in the Age of Generative AI. Artificial Intelligence is revolutionizing business, but it also introduces new risks. Join us on Wednesday, September 18th at 2pm EDT for a compelling live webinar on "Good vs. Evil: Cloud Security in the Age of Generative AI" with N2K CyberWire’s Dave Bittner and Sysdig’s Loris Degioanni.  Learn more and register now . Summary By the CyberWire staff At a glance. Fortinet confirms breach of customer data. Iran's Scarred Manticore deplo...

SecurityWeek Briefing

"New RAMBO attack allows air-gapped data theft." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 10 September 2024, 0035 UTC. Content and Source:  https://www.securityweek.com Please check link or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net).   Monday, September 9 , 2024 Are you worried about unmanaged devices and apps? LATEST CYBERSECURITY HEADLINES New RAMBO Attack Allows Air-Gapped Data Theft Predator Spyware Resurfaces With Fresh Infrastructure Google Pushes Rust in Legacy Firmware to Tackle Memory Safety Flaws 300,000 Impacted by Data Breach at Car Rental Firm Avis One Million US Kaspersky Customers Transferred to Pango’s UltraAV Two Indicted in US for Running Dark Web Marketplaces Offering Stolen Information Critical SonicWall Vulnerability Possibly Exploited in Ransomware Attacks CISA Breaks Silence on Controvers...