GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by BleepingComputer (bleepingcomputer@infosec.exchange)

  1. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 18-Jul-2026 02:57:45 JST BleepingComputer BleepingComputer

    A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.

    https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/

    In conversation about 2 months ago from infosec.exchange permalink
  2. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Tuesday, 30-Jun-2026 05:53:38 JST BleepingComputer BleepingComputer

    Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.

    https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/

    In conversation about 2 months ago from infosec.exchange permalink
  3. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 26-Jun-2026 01:23:54 JST BleepingComputer BleepingComputer

    A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable.

    https://www.bleepingcomputer.com/news/security/new-macos-malware-embeds-fake-errors-to-confuse-ai-analysis-tools/

    In conversation about 3 months ago from infosec.exchange permalink
  4. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Wednesday, 17-Jun-2026 05:35:23 JST BleepingComputer BleepingComputer

    Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages.

    https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/

    In conversation about 3 months ago from infosec.exchange permalink
  5. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 11-Jun-2026 06:27:11 JST BleepingComputer BleepingComputer

    Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers.

    https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/

    In conversation about 3 months ago from infosec.exchange permalink
  6. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Wednesday, 10-Jun-2026 08:13:23 JST BleepingComputer BleepingComputer

    https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
      Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
      from @BleepinComputer
  7. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Monday, 18-May-2026 07:50:10 JST BleepingComputer BleepingComputer

    A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems. 

    https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
      New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
      from @BleepinComputer
      A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems. 
  8. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Monday, 04-May-2026 06:37:21 JST BleepingComputer BleepingComputer

    Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some cases, removing certificates from Windows.

    https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/

    In conversation about 4 months ago from infosec.exchange permalink
  9. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 24-Apr-2026 04:22:01 JST BleepingComputer BleepingComputer

    The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects.

    https://www.bleepingcomputer.com/news/security/bitwarden-cli-npm-package-compromised-to-steal-developer-credentials/

    In conversation about 5 months ago from infosec.exchange permalink
  10. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 23-Apr-2026 08:04:50 JST BleepingComputer BleepingComputer

    A new supply chain attack targeting the Node Package Manager (npm) ecosystem is stealing developer credentials and attempting to spread through packages published from compromised accounts.

    https://www.bleepingcomputer.com/news/security/new-npm-supply-chain-attack-self-spreads-to-steal-auth-tokens/

    In conversation about 5 months ago from infosec.exchange permalink
  11. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 16-Apr-2026 05:51:11 JST BleepingComputer BleepingComputer

    More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them.

    https://www.bleepingcomputer.com/news/security/wordpress-plugin-suite-hacked-to-push-malware-to-thousands-of-sites/

    In conversation about 5 months ago from infosec.exchange permalink
  12. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 09-Apr-2026 06:29:23 JST BleepingComputer BleepingComputer

    A new campaign delivering the Atomic Stealer malware to macOS users abuses the Script Editor in a variation of the ClickFix attack that tricked users into executing commands in Terminal.

    https://www.bleepingcomputer.com/news/security/new-macos-stealer-campaign-uses-script-editor-in-clickfix-attack/

    In conversation about 5 months ago from infosec.exchange permalink
  13. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Wednesday, 01-Apr-2026 08:05:13 JST BleepingComputer BleepingComputer

    Cisco has suffered a cyberattack after threat actors used stolen credentials from the recent Trivy supply chain attack to breach its internal development environment and steal source code belonging to the company and its customers.

    https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/

    In conversation about 5 months ago from infosec.exchange permalink
  14. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 13-Mar-2026 06:34:52 JST BleepingComputer BleepingComputer

    Still, out of an abundance of caution, Loblaw says it has automatically logged out all customers from their accounts. Account holders who need to access the company's digital services will have to log in again.

    https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/

    In conversation about 6 months ago from infosec.exchange permalink
  15. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 27-Feb-2026 06:44:45 JST BleepingComputer BleepingComputer

    Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data.

    https://www.bleepingcomputer.com/news/security/previously-harmless-google-api-keys-now-expose-gemini-ai-data/

    In conversation about 6 months ago from infosec.exchange permalink
  16. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Monday, 16-Feb-2026 19:58:01 JST BleepingComputer BleepingComputer

    Google has released emergency updates to fix a high-severity Chrome vulnerability exploited in zero-day attacks, marking the first such security flaw patched since the start of the year.

    https://www.bleepingcomputer.com/news/security/google-patches-first-chrome-zero-day-exploited-in-attacks-this-year/

    In conversation about 7 months ago from infosec.exchange permalink
  17. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Saturday, 14-Feb-2026 13:00:35 JST BleepingComputer BleepingComputer

    Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries.

    https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/

    In conversation about 7 months ago from infosec.exchange permalink
  18. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 05-Feb-2026 09:47:58 JST BleepingComputer BleepingComputer

    A threat actor is compromising NGINX servers in a campaign that hijacks user traffic and reroutes it through the attacker's backend infrastructure.

    https://www.bleepingcomputer.com/news/security/hackers-compromise-nginx-servers-to-redirect-user-traffic/

    In conversation about 7 months ago from infosec.exchange permalink
  19. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Friday, 30-Jan-2026 07:59:50 JST BleepingComputer BleepingComputer

    A new Android malware campaign is using the Hugging Face platform as a repository for thousands of variations of an APK payload that collects credentials for popular financial and payment services.

    https://www.bleepingcomputer.com/news/security/hugging-face-abused-to-spread-thousands-of-android-malware-variants/

    In conversation about 7 months ago from infosec.exchange permalink
  20. Embed this notice
    BleepingComputer (bleepingcomputer@infosec.exchange)'s status on Thursday, 29-Jan-2026 07:37:27 JST BleepingComputer BleepingComputer

    CISA has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered U.S. federal agencies to secure their servers within three weeks.

    https://www.bleepingcomputer.com/news/security/cisa-says-critical-vmware-rce-flaw-now-actively-exploited/

    In conversation about 7 months ago from infosec.exchange permalink
  • Before

User actions

    BleepingComputer

    BleepingComputer

    Breaking technology news, security guides, and tutorials that help you get the most from your computer. Feel free to send us story tips at press@bleepingcomputer.com.Sometimes a bot, sometimes not.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          56787
          Member since
          7 Dec 2022
          Notices
          167
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.