BleepingComputer.com

"ShinyHunters claims 1.5 billion Salesforce records stolen in drift hacks."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 18 September 2025, 0236 UTC.

Content and Source:  "BleepingComputer.com."

URL--https://www.bleepingcomputer.com/

Please check URL or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

  • The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

  • Security Cybersecurity
     

Get a foundation in cybersecurity with this $25 course deal

  • Getting into cybersecurity is easier when you learn the tools, workflows, and standards that real teams use every day. The 2025 Cyber Security Career Foundations Course Bundle pulls those pieces together so you can build a practical base and figure out where you want to specialize. It's also on sale for only $24.99 (reg. $120).

    • BleepingComputer Deals
    •  
    • September 17, 2025
    •  
    • 02:06 PM
    •  
    • Comment Count 0
  • Push Security
     

New Webinar: Analyzing Real-world ClickFix Attacks 

  • ClickFix, FileFix, fake CAPTCHA — whatever you call it, attacks where users interact with malicious scripts in their web browser are a fast-growing source of security breaches.

    Register for the webinar on October 23rd to learn how ClickFix-style attacks are bypassing detection controls, and what security teams can do about it.

  • Insight Partners
     

VC giant Insight Partners warns thousands after ransomware breach

  • New York-based venture capital and private equity firm Insight Partners is notifying thousands of individuals whose personal information was stolen in a ransomware attack.

  • SonicWall
     

SonicWall warns customers to reset credentials after breach

  • SonicWall warned customers today to reset credentials after their firewall configuration backup files were exposed in a security breach that impacted MySonicWall accounts.

  • Microsoft Office
     

Microsoft: Office 2016 and Office 2019 reach end of support next month

  • ​​​​​Microsoft reminded customers again this week that Office 2016 and Office 2019 will reach the end of extended support in less than 30 days, on October 14, 2025.

  • From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques
     

From ClickFix to MetaStealer: Dissecting Evolving Threat Actor Techniques

  • ClickFix isn't just back—it's mutating. New variants use fake CAPTCHAs, File Explorer tricks & MSI lures to drop MetaStealer. Stay ahead with Huntress' Tradecraft Tuesday threat briefings.

  • Racccoon
     

Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service

  • Microsoft and Cloudflare have disrupted a massive Phishing-as-a-Service (PhaaS) operation, known as RaccoonO365, that helped cybercriminals steal thousands of Microsoft 365 credentials.

  • This Mondly lifetime deal adds 41 languages to your toolkit
     

This Mondly lifetime deal adds 41 languages to your toolkit

  • Language skills are increasingly valuable in a global economy, but keeping up with subscription-based learning apps can be expensive and inconsistent. Mondly by Pearson addresses that with a lifetime Premium Plan available now for $89.99 (MSRP $299.99).

    • BleepingComputer Deals
    •  
    • September 17, 2025
    •  
    • 07:10 AM
    •  
    • Comment Count 0
  • Hacker cybersecurity
     

BreachForums hacking forum admin resentenced to three years in prison

  • Conor Brian Fitzpatrick, the 22-year-old behind the notorious BreachForums hacking forum, was resentenced today to three years in prison after a federal appeals court overturned his prior sentence of time served and 20 years of supervised release.

  • Cybersecurity framework
     

Get 8 courses to kickstart or advance your security career for $30

  • Breaking into cybersecurity—or advancing within it—means mastering security and risk management, one of the toughest but most critical domains. The CISSP Security & Risk Management Training Bundle can help you build that foundation, and for a limited time, it's only $29.97 (MSRP: $424) through Oct. 5.

    • BleepingComputer Deals
    •  
    • September 16, 2025
    •  
    • 02:06 PM
    •  
    • Comment Count 0
  • Microsoft Copilot
     

Microsoft rolls out Copilot Chat to Microsoft 365 Office apps

  • ​Microsoft is rolling out Copilot Chat to Word, Excel, PowerPoint, Outlook, and OneNote for paying Microsoft 365 business customers.

  • Android
     

Google nukes 224 Android malware apps behind massive ad fraud campaign

  • A massive Android ad fraud operation dubbed "SlopAds" was disrupted after 224 malicious applications on Google Play were used to generate 2.3 billion ad requests per day.

  • NPM
     

Self-propagating supply chain attack hits 187 npm packages

  • Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the compromise of the @ctrl/tinycolor npm package, and has now expanded to CrowdStrike's npm namespace.

  • WMIC
     

Microsoft: WMIC will be removed after Windows 11 25H2 upgrade

  • Microsoft has announced that the Windows Management Instrumentation Command-line (WMIC) tool will be removed after upgrading to Windows 11 25H2 and later.

  • Team-Wide VMware Certification: Your Secret Weapon for Security
     

Team-Wide VMware Certification: Your Secret Weapon for Security

  • One VMware-certified pro is a win. An entire certified team? That's a security multiplier. VMUG Advantage makes team-wide certification practical—building collaboration, resilience, and retention.

    • VMUG
    •  
    • September 16, 2025
    •  
    • 10:01 AM
    •  
    • Comment Count 0
  • Jaguar
     

Jaguar Land Rover extends shutdown after cyberattack by another week

  • Jaguar Land Rover (JLR) announced today that it will extend the production shutdown for another week, following a devastating cyberattack that impacted its systems at the end of August.

  • Apple
     

Apple backports zero-day patches to older iPhones and iPads

  • ​Apple has released security updates to backport patches released last month to older iPhones and iPads, addressing a zero-day bug that was exploited in "extremely sophisticated" attacks.

  • Hacker
     

New FileFix attack uses steganography to drop StealC malware

  • A newly discovered FileFix social engineering attack impersonates Meta account suspension warnings to trick users into unknowingly installing the StealC infostealer malware.

  • Lifetime access to an all-in-one AI platform is just $100 in this deal
     

Lifetime access to an all-in-one AI platform is just $100 in this deal

  • Most AI tools are scattered across different platforms with separate subscriptions, with the costs quickly adding up. 1min.AI Advanced Business Plan Lifetime Subscription gives you access to many AI platform for a one-time payment of $99.99 (MSRP: $540),

    • BleepingComputer Deals
    •  
    • September 16, 2025
    •  
    • 07:07 AM
    •  
    • Comment Count 0
  • Hacking security Cybersecurity
     

Webinar: Your browser is the breach — securing the modern web edge

  • The web browser has quietly become one of the most critical components of enterprise infrastructure—and one of the most dangerous. Join BleepingComputer, SC Media, and Push Security on September 29 at 12:00 PM ET for a live webinar on how attackers are targeting the browser to hijack sessions, steal data, and bypass security.

View More

 

Comments

Popular posts from this blog

Cyber War News Today.

Cyber War News Today.

SecurityWeek Briefing