News

Bleeping Computer
bleepingcomputer. com > news > security > avada-builder-wordpress-plugin-flaws-allow-site-credential-theft

Avada Builder Word Press plugin flaws allow site credential theft

5+ hour, 34+ min ago  (560+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Funnel Builder Word Press plugin bug exploited to steal credit cards Microsoft Exchange, Windows 11 hacked…...

Bleeping Computer
bleepingcomputer. com > news > security > funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards

Funnel Builder Word Press plugin bug exploited to steal credit cards

2+ hour, 1+ min ago  (453+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Funnel Builder Word Press plugin bug exploited to steal credit cards Microsoft Exchange, Windows 11 hacked…...

Bleeping Computer
bleepingcomputer. com > news > security > pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days

Microsoft Exchange, Windows 11 hacked on second day of Pwn2 Own

3+ hour, 41+ min ago  (615+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Microsoft Exchange, Windows 11 hacked on second day of Pwn2 Own Popular node-ipc npm package compromised to…...

Bleeping Computer
bleepingcomputer. com > news > security > popular-node-ipc-npm-package-compromised-to-steal-credentials

Popular node-ipc npm package compromised to steal credentials

4+ hour, 21+ min ago  (522+ words) Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Popular node-ipc npm package compromised to steal credentials Avada Builder Word Press plugin flaws allow site credential theft Microsoft backpedals: Edge to stop loading passwords into…...

@Bleepin Computer
bleepingcomputer. com > news > security > inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution > amp

Inside the REMUS Infostealer: Session Theft, Maa S, and Rapid Evolution

7+ hour, 25+ min ago  (547+ words) In recent months, a new infostealer malware known as REMUS has emerged across the cybercrime landscape, drawing attention from security researchers and malware analysts. Several technical analyses published in recent months focused on the malware's capabilities, infrastructure, and similarities to…...

Bleeping Computer
bleepingcomputer. com > news > microsoft > microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup

Microsoft backpedals: Edge to stop loading passwords into memory

6+ hour, 24+ min ago  (557+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Microsoft backpedals: Edge to stop loading passwords into memory Inside the REMUS Infostealer: Session Theft,…...

Bleeping Computer
bleepingcomputer. com > news > microsoft > microsoft-to-automatically-roll-back-faulty-windows-drivers

Microsoft to automatically roll back faulty Windows drivers

8+ hour, 52+ min ago  (270+ words) Microsoft is introducing a new capability that will allow it to remotely roll back problematic Windows drivers delivered through Windows Update....

Bleeping Computer
bleepingcomputer. com > news > microsoft > microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks

Microsoft warns of Exchange zero-day flaw exploited in attacks

11+ hour, 51+ min ago  (588+ words) Shai Hulud attack ships signed malicious Tan Stack, Mistral npm packages Windows 11 KB5089549 & KB5087420 cumulative updates released Instructure reaches 'agreement' with Shiny Hunters to stop data leak Microsoft warns of Exchange zero-day flaw exploited in attacks Team PCP hackers advertise Mistral AI…...

@Bleepin Computer
bleepingcomputer. com > news > security > hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin > amp

Hackers exploit auth bypass flaw in Burst Statistics Word Press plugin

1+ day, 24+ min ago  (475+ words) Hackers are leveraging a critical authentication bypass vulnerability in the Word Press plugin Burst Statistics to obtain admin-level access to websites. Burst Statistics is a privacy-focused analytics plugin active on 200, 000 Word Press sites and marketed as a lightweight alternative to…...

@Bleepin Computer
bleepingcomputer. com > news > security > windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026 > amp

Windows 11 and Microsoft Edge hacked at Pwn2 Own Berlin 2026

1+ day, 2+ hour ago  (336+ words) On the first day of Pwn2 Own Berlin 2026, security researchers collected $523, 000in cash awards after exploiting24 unique zero-days. Today's highlight was Orange Tsai's attempt, who was awarded$175, 000 in rewards afterchaining4 logic bugs to achieve a sandbox escape on Microsoft Edge. Windows 11 was also hacked…...