Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

Microsoft warns of new Defender zero-days exploited in attacks

Erfasst 21.05.2026 09:50 | BleepingComputer
On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. [...]
Quelle ansehen

GitHub links repo breach to TanStack npm supply-chain attack

Erfasst 21.05.2026 09:05 | BleepingComputer
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack n...
Quelle ansehen

Ukraine identifies infostealer operator tied to 28,000 stolen accounts

Erfasst 20.05.2026 23:49 | BleepingComputer
The Ukrainian cyberpolice, working in conjunction with U.S. law enforcement, has identified an 18-year-old man from Odesa suspected of running an infostealer malware operation t...
Quelle ansehen

Hackers bypass SonicWall VPN MFA due to incomplete patching

Erfasst 20.05.2026 23:34 | BleepingComputer
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks. [...]
Quelle ansehen

Grafana breach caused by missed token rotation after TanStack attack

Erfasst 20.05.2026 17:48 | BleepingComputer
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. [...]
Quelle ansehen

Identity Alone Isn't Enough: Why Device Security Has to Share the Load

Erfasst 20.05.2026 16:18 | BleepingComputer
Identity checks alone can't stop attackers using stolen session tokens and compromised devices. Specops Software outlines why Zero Trust strategies increasingly depend on contin...
Quelle ansehen

Drupal critical update to fix bug with high exploitation risk

Erfasst 20.05.2026 15:03 | BleepingComputer
Drupal has announced a "core security release" scheduled for later today, warning that threat actors might develop exploits within hours of the update disclosure. [...]
Quelle ansehen

Exploit released for new PinTheft Arch Linux root escalation flaw

Erfasst 20.05.2026 13:03 | BleepingComputer
PinTheft, a recently patched Linux privilege escalation vulnerability, now has a publicly available proof-of-concept (PoC) exploit that allows local attackers to gain root privi...
Quelle ansehen

GitHub confirms breach of 3,800 repos via malicious VSCode extension

Erfasst 20.05.2026 10:17 | BleepingComputer
GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. [...]
Quelle ansehen

Microsoft shares mitigation for YellowKey Windows zero-day

Erfasst 20.05.2026 09:32 | BleepingComputer
Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. [...]
Quelle ansehen

GitHub investigates internal repositories breach claimed by TeamPCP

Erfasst 20.05.2026 07:17 | BleepingComputer
GitHub is investigating a breach of its internal repositories after the TeamPCP hacker group claimed to have accessed approximately 4,000 repositories containing private code. [...
Quelle ansehen

Max-severity flaw in ChromaDB for AI apps allows server hijacking

Erfasst 20.05.2026 00:31 | BleepingComputer
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. [...]
Quelle ansehen

Cybercrime service disrupted for abusing Microsoft platform to sign malware

Erfasst 20.05.2026 00:01 | BleepingComputer
Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company's Artifact Signing service to generate fraudulent code-signing certifica...
Quelle ansehen

Discord rolls out end-to-end encryption on voice, video calls

Erfasst 19.05.2026 22:46 | BleepingComputer
Discord announced that all voice and video calls through the communication platform are now protected by default with end-to-end encryption (E2EE). [...]
Quelle ansehen

FBI: Americans lost over $388 million to scams using crypto ATMs in 2025

Erfasst 19.05.2026 22:01 | BleepingComputer
The FBI says Americans have lost over $388 million last year to scams using cryptocurrency kiosks, also known as crypto ATMs or Bitcoin ATMs. [...]
Quelle ansehen

Microsoft Self-Service Password Reset abused in Azure data theft attacks

Erfasst 19.05.2026 21:46 | BleepingComputer
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features. [...]
Quelle ansehen

Microsoft plans to improve Windows 11 driver quality in 2026

Erfasst 19.05.2026 18:30 | BleepingComputer
Microsoft plans to raise the quality bar of Windows 11 drivers, as drivers "sit at the heart of every Windows experience" and connect the OS to the "silicon, components, and per...
Quelle ansehen

Microsoft blames undismissible Teams location prompts on macOS update

Erfasst 19.05.2026 18:15 | BleepingComputer
Microsoft has confirmed user reports that the Teams team collaboration app is displaying non-dismissible location prompts on some macOS systems. [...]
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.