Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.
Notices by BleepingComputer (bleepingcomputer@infosec.exchange)
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 27-Feb-2026 06:44:45 JST
BleepingComputer
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Monday, 16-Feb-2026 19:58:01 JST
BleepingComputer
Google has released emergency updates to fix a high-severity Chrome vulnerability exploited in zero-day attacks, marking the first such security flaw patched since the start of the year.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 14-Feb-2026 13:00:35 JST
BleepingComputer
Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 05-Feb-2026 09:47:58 JST
BleepingComputer
A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker's backend infrastructure.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 30-Jan-2026 07:59:50 JST
BleepingComputer
A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 29-Jan-2026 07:37:27 JST
BleepingComputer
CISA has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered U.S. federal agencies to secure their servers within three weeks.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 27-Jan-2026 21:29:39 JST
BleepingComputer
Hackers have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform's systems.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 22-Jan-2026 05:01:10 JST
BleepingComputer
Fortinet admins are seeing attackers exploiting a patch bypass for a previously fixed FortiGate authentication bypass (CVE-2025-59718) to hack patched firewalls.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 06-Jan-2026 21:40:50 JST
BleepingComputer
Microsoft has pushed back against claims that multiple prompt injection and sandbox-related issues raised by a security engineer in its Copilot AI assistant constitute security vulnerabilities. The development highlights a growing divide between how vendors and researchers define risk in generative AI systems.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 20-Dec-2025 05:59:30 JST
BleepingComputer
Microsoft Teams is experiencing issues, with thousands reporting problems sending messages, including delays.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 20-Dec-2025 02:23:57 JST
BleepingComputer
Multiple threat actors are compromising Microsoft 365 accounts in phishing attacks that leverage the OAuth device code authorization mechanism.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 16-Dec-2025 07:49:24 JST
BleepingComputer
A new malware-as-a-service (MaaS) information stealer named SantaStealer is being advertised on Telegram and hacker forums as operating in memory to avoid file-based detection.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 11-Dec-2025 22:21:04 JST
BleepingComputer
An unpatched zero-day vulnerability (CVE-2025-8110) in Gogs, a popular self-hosted Git service, has enabled attackers to gain remote code execution on Internet-facing instances and compromise hundreds of servers.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 05-Dec-2025 02:27:38 JST
BleepingComputer
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote code execution without authentication in React and Next.js applications.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 28-Nov-2025 03:41:19 JST
BleepingComputer
GreyNoise Labs has launched a free tool called GreyNoise IP Check that lets users check if their IP address has been observed in malicious scanning operations, like botnet and residential proxy networks.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Wednesday, 26-Nov-2025 18:18:32 JST
BleepingComputer
Thousands of credentials, authentication keys, and configuration data impacting organizations in sensitive sectors have been sitting in publicly accessible JSON snippets submitted to the JSONFormatter and CodeBeautify online tools that format and structure code.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Monday, 24-Nov-2025 00:34:28 JST
BleepingComputer
Google has added interoperability support between Android Quick Share and Apple AirDrop, to let users share files between Pixel devices and iPhones.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 18-Nov-2025 21:26:08 JST
BleepingComputer
Cloudflare is investigating an outage affecting its global network services, with users encountering "internal server error" messages when attempting to access affected websites and online platforms.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 15-Nov-2025 05:31:18 JST
BleepingComputer
Fortinet has silently patched a critical zero-day vulnerability in its FortiWeb web application firewall, which is now being widely exploited.
-
Embed this notice
BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Wednesday, 12-Nov-2025 09:25:28 JST
BleepingComputer
The Rhadamanthys infostealer operation has been disrupted, with numerous "customers" of the malware-as-a-service reporting that they no longer have access to their servers.