BleepingComputer.com
"Hackers launch mass attack exploiting outdated Wordpress plugins."
Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents. Accessed on 25 October 2025, 1533 UTC.
Content and Source: "BleepingComputer.com."
URL--https://www.bleepingcomputer.com/
Please check URL or scroll down to read your selections. Thanks for joining us today.
Russ Roberts (https://www.hawaiicybersecurityjournal.net).
Latest Articles
-
This Pok Pok app deal makes screen time educational for kids
Parents want screen time to feel meaningful, not mindless. That's the idea behind Pok Pok, a Montessori-inspired digital playroom that helps kids aged two to eight learn through exploration instead of overstimulation. Right now, it's also only $47.99 for life (reg. $250).
- October 25, 2025
- 08:12 AM
0
-
Hackers launch mass attacks exploiting outdated WordPress plugins
A widespread exploitation campaign is targeting WordPress websites with GutenKit and Hunk Companion plugins vulnerable to critical-severity, old security issues that can be used to achieve remote code execution (RCE).
- October 24, 2025
- 03:28 PM
0
-
New Webinar: Endpoint Security Evolution — Detection and Response in the Web Browser

Today's workforce spends more time in the browser than ever, with work shifting to SaaS and cloud services. Yet most security controls haven't kept up, leaving identities unmonitored and attackers free to exploit them.
Register now to join a discussion on why the browser is the new endpoint, and how browser-native visibility is redefining what effective defense looks like.
-
Critical WSUS flaw in Windows Server now exploited in attacks
Attackers are now exploiting a critical-severity Windows Server Update Service (WSUS) vulnerability, which already has publicly available proof-of-concept exploit code.
- October 24, 2025
- 12:28 PM
1
-
Amazon: This week’s AWS outage caused by major DNS failure
Amazon says a major DNS failure was behind a massive AWS (Amazon Web Services) outage that took down many websites and online services on Monday.
- October 24, 2025
- 11:33 AM
0
-
Fake LastPass death claims used to breach password vaults
LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process.
- October 24, 2025
- 10:47 AM
1
-
How to reduce costs with self-service password resets
Password resets account for nearly 40% of IT help desk calls, costing orgs time and money. Specops Software's uReset lets users securely reset passwords with flexible MFA options like Duo, Okta, and Yubikey while enforcing identity verification to stop misuse.
- October 24, 2025
- 10:06 AM
0
-
Mozilla: New Firefox extensions must disclose data collection practices
Starting next month, Mozilla will require Firefox extension developers to disclose whether their add-ons collect or share user data with third parties.
- October 24, 2025
- 09:17 AM
1
-
The refurbished Chromebook that’s built for everyday life is just $80
Sometimes you just need a laptop that works — no frills, no overcomplication, no headaches. The refurbished Lenovo 300E 11.6″ Touchscreen Chromebook (2018) is exactly that kind of machine. Currently priced at just $79.99 (MSRP: $284.99), it's the dependable, budget-friendly device you can take anywhere.
- October 24, 2025
- 07:12 AM
0
-
Windows Server emergency patches fix WSUS bug with PoC exploit
Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code.
- October 24, 2025
- 03:27 AM
1
-
Hackers earn $1,024,750 for 73 zero-days at Pwn2Own Ireland
The Pwn2Own Ireland 2025 hacking competition has ended with security researchers collecting $1,024,750 in cash awards after exploiting 73 zero-day vulnerabilities.
- October 24, 2025
- 02:36 AM
0
-
Toys “R” Us Canada warns customers' info leaked in data breach
Toys "R" Us Canada has sent notices of a data breach to customers informing them of a security incident where threat actors leaked customer records they had previously stolen from its systems.
- October 23, 2025
- 06:25 PM
0
-
HP pulls update that broke Microsoft Entra ID auth on some AI PCs
HP has pulled an HP OneAgent software update for Windows 11 that mistakenly deleted Microsoft certificates required for some organizations to log in to Microsoft Entra ID, effectively disconnecting them from their company's cloud environments.
- October 23, 2025
- 05:50 PM
1
-
Get started in AI with 50 courses + lifetime access for just $20 in this deal
For a limited time, the 2025 Ultimate GenAI Masterclass Bundle is available for just $19.97 (MSRP $249), giving you lifetime access to 50 expert-led courses that teach you how to master the most advanced AI tools out there.
- October 23, 2025
- 02:07 PM
0
-
Meet the new Clippy: Microsoft unveils Copilot's "Mico" avatar
Today, Microsoft introduced Mico, a new and more personal avatar for the AI-powered Copilot digital assistant, which the company describes as human-centered.
- October 23, 2025
- 01:28 PM
11
-
CISA warns of Lanscope Endpoint Manager flaw exploited in attacks
The Cybersecurity & Infrastructure Security Agency (CISA) is warning that hackers are exploiting a critical vulnerability in the Motex Landscope Endpoint Manager.
- October 23, 2025
- 12:24 PM
0
-
Microsoft disables File Explorer preview for downloads to block attacks
Microsoft says that the File Explorer (formerly Windows Explorer) now automatically blocks previews for files downloaded from the Internet to block credential theft attacks via malicious documents.
- October 23, 2025
- 11:57 AM
4
-
Zero Trust Has a Blind Spot—Your AI Agents
AI agents now act, decide, and access systems on their own — creating new blind spots Zero Trust can't see. Token Security helps organizations govern AI identities so every agent's access, intent, and action are verified and accountable.
- October 23, 2025
- 10:15 AM
0
-
Spoofed AI sidebars can trick Atlas, Comet users into dangerous actions
OpenAI's Atlas and Perplexity's Comet browsers are vulnerable to AI sidebar spoofing attacks that mislead users into following fake AI-generated instructions.
- October 23, 2025
- 10:09 AM
0
-
North Korean Lazarus hackers targeted European defense companies
North Korean Lazarus hackers compromised three European companies in the defense sector through a coordinated Operation DreamJob campaign leveraging fake recruitment lures.
- October 23, 2025
- 08:38 AM
0
-
The new Mondly language learning app is only $90 for life
Mondly turns the language learning process into a routine that's easy to stick to, so you can make learning a quick, fun, and easy part of your day. Right now, a lifetime subscription to Mondly is on sale for only $89.99 (reg. $299.99), but that price won't last much longer.
- October 23, 2025
- 07:09 AM
0

Comments
Post a Comment
Please leave a comment about our recent post.