BleepingComputer.com
"Fake Open AI repository on Hugging Face pushes infostealer malware."
Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents. Accessed on 09 May 2026, 1716 UTC.
Content and Source: "BleepingComputer.com."
URL--https://www.bleepingcomputer.com/
Please check URL or scroll down to read your selections. Thanks for joining us today.
Russ Roberts (https://www.hawaiicybersecurityjournal.net).
-
Fake OpenAI repository on Hugging Face pushes infostealer malware
A malicious Hugging Face repository that reached the platform's trending list impersonated OpenAI's "Privacy Filter" project to deliver information-stealing malware to Windows users.
- May 09, 2026
- 10:26 AM
0
-
This Babbel deal shows how human-created language learning works better
There's no shortage of AI tools that can translate a sentence for you. But actually speaking a language? The Babbel platform takes a different approach to help you learn to speak your new language in as little as three weeks. The lifetime subscription to Babbel is just $159 (MSRP $646.20) using StackSocial's code LEARN at checkout.
- May 09, 2026
- 08:09 AM
0
-
Shadow AI Is Everywhere. Here's How to Find and Secure It.

With MCP servers, AI agents, SaaS apps with AI-enabled features taking hold, shadow AI now extends far beyond purpose-built AI tools. Your discovery approach should too. This guide walks through commonly overlooked sources of shadow AI risks, DIY discovery methods using tools you already have, and the pros and cons of more advanced approaches.
-
NVIDIA confirms GeForce NOW data breach affecting Armenian users
NVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach.
- May 08, 2026
- 12:18 PM
0
-
Why More Analysts Won’t Solve Your SOC’s Alert Problem
Attackers move faster than overwhelmed SOC teams can realistically investigate alerts. Prophet Security breaks down how AI can help analysts investigate alerts faster and focus on real threats.
- May 08, 2026
- 10:02 AM
0
-
Trellix source code breach claimed by RansomHouse hackers
The attack on the Trellix source code repository disclosed last week has been claimed by the RansomHouse threat group, which leaked a small set of images as proof of the intrusion.
- May 08, 2026
- 09:23 AM
0
-
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
CISA has given U.S. federal agencies four days to secure their networks against a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) exploited in zero-day attacks.
- May 08, 2026
- 08:16 AM
0
-
Get 5 years of AdGuard VPN access across 70+ global servers for $40
A 5-year subscription to AdGuard VPN is currently $39.97 (MSRP $359.40), which breaks down to less than a dollar a month for private browsing across 10 of your mobile and desktop devices.
- May 08, 2026
- 07:07 AM
0
-
Zara data breach exposed personal information of 197,000 people
Hackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned.
- May 08, 2026
- 06:42 AM
0
-
Former govt contractor convicted for wiping dozens of federal databases
A 34-year-old Virginia man was found guilty of conspiring to destroy dozens of government databases after getting fired from his job as a federal contractor.
- May 08, 2026
- 04:45 AM
0
-
New Linux 'Dirty Frag' zero-day gives root on all major distros
A new Linux zero-day exploit, named Dirty Frag, allows local attackers to gain root privileges on most major Linux distributions with a single command.
- May 08, 2026
- 03:45 AM
3
-
Canvas login portals hacked in mass ShinyHunters extortion campaign
The ShinyHunters extortion gang has breached education technology giant Instructure again, this time exploiting another vulnerability to deface Canvas login portals for hundreds of colleges and universities.
- May 07, 2026
- 06:36 PM
2
-
New TCLBanker malware self-spreads over WhatsApp and Outlook
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems.
- May 07, 2026
- 06:06 PM
3
-
New PCPJack worm steals credentials, cleans TeamPCP infections
A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP's access to the systems.
- May 07, 2026
- 02:35 PM
0
-
Don’t miss this Lenovo Chromebook while it’s on sale for just $60
The refurbished Lenovo 100e Chromebook Gen 2 (2019) is easy, reliable, and affordable. At just $59.99 (MSRP $199.99), it's built for simple, everyday tasks without overcomplicating things.
- May 07, 2026
- 02:11 PM
0
-
Australia warns of ClickFix attacks pushing Vidar Stealer malware
The Australian Cyber Security Center (ACSC) is warning organizations of an ongoing malware campaign using the ClickFix social engineering technique to distribute the Vidar Stealer info-stealing malware.
- May 07, 2026
- 02:00 PM
0
-
Ivanti warns of new EPMM flaw exploited in zero-day attacks
Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks.
- May 07, 2026
- 11:20 AM
0
-
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
Your security controls aren't failing, they're missing where most of today's work actually happens. Keep Aware shows how browser activity like copy/paste and AI prompts bypass traditional protections.
- May 07, 2026
- 10:01 AM
0
-
Americans sentenced for running 'laptop farms' for North Korea
Two U.S. nationals were sentenced to 18 months in prison each for operating so-called laptop farms that helped North Korean IT workers fraudulently obtain remote employment at nearly 70 American companies.
- May 07, 2026
- 09:45 AM
0
-
Crypto gang member gets 6.5 years for role in $230 million heist
A 20-year-old California man was sentenced to 78 months in prison for serving as a home invader and money launderer in a criminal ring that stole over $250 million in cryptocurrency.
- May 07, 2026
- 08:11 AM
0
-
Webinar: Why modern attacks require both security and recovery
Modern attacks don't stop at initial compromise. This webinar explores why security and recovery must work together to reduce downtime and improve resilience.
- May 07, 2026
- 08:00 AM
0

Comments
Post a Comment
Please leave a comment about our recent post.