Software

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. BleepingComputer learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people’s posts about […]

Steam forum ClickFix attacks infect gamers with XMRig cryptominers Read More »

GitHub, PyPI add time-based defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. Specifically, Dependabot comes with a default three-day cooldown setting, while PyPI will reject new files uploaded to releases older than 14 days. The measure comes after the two

GitHub, PyPI add time-based defenses against supply chain attacks Read More »

Europol flags 4,340 URLs for removal in ‘The Com’ crackdown

Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to “The Com,” a loosely organized network of nihilistic violent extremist groups. Investigators from nine countries (i.e., Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden) took part in what Europol called “Referral Action Days” between June and

Europol flags 4,340 URLs for removal in ‘The Com’ crackdown Read More »

Clop ransomware targets Windchill, FlexPLM in data theft attacks

The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company ReliaQuest reported

Clop ransomware targets Windchill, FlexPLM in data theft attacks Read More »

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing

Hackers are increasingly using AI to launch attacks on a massive scale, with email emerging as a primary target. AI can quickly aggregate personal information — such as information about co-workers, active projects, and recent travel itineraries — allowing bad actors to instantly craft convincing messages that look authentic. Last year, former Google security executives

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing Read More »

US government says Iran-linked hackers are disrupting American water and energy providers

The U.S. government is warning that Iranian state-backed hackers are actively breaking in and disrupting industrial control systems at American water and energy providers. This new alert comes months after federal agencies warned of an escalation in hacking from Iranian actors amid the ongoing war. In an advisory updated Wednesday, the FBI, the NSA, the

US government says Iran-linked hackers are disrupting American water and energy providers Read More »

How AI guardrails are impeding the work of offensive cybersecurity researchers

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers. In June, the U.S. government slapped export control restrictions on Anthropic’s much-hyped AI

How AI guardrails are impeding the work of offensive cybersecurity researchers Read More »

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

I spent years on the offensive side of security performing red and purple team assessments, bypassing controls that GRC teams, and often times even auditors, were convinced were working. Spoiler: it was rarely as difficult as it should have been. Not because those teams were careless, but because they were measured against a system that

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires Read More »

Microsoft 365 outage affects Teams, SharePoint and other services

Update 7/23/26 9:55 PM ET: Article updated that the outage has been resolved. Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. At 11:11 AM ET on July 23, Downdetector recorded 2,403 reports, sharply above its normal baseline of 29. SharePoint accounted for 78% of

Microsoft 365 outage affects Teams, SharePoint and other services Read More »