Bill Toulas

Articles by Bill Toulas

Lazarus hackers exploited Windows zero-day to target defense firms - BleepingComputer

Technology August 14, 2026

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. Microsoft addressed the flοΏ½...

Critical SharePoint RCE flaw exploited to steal machine keys - BleepingComputer

Technology July 24, 2026

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. An attacker obtaiοΏ½...

Critical wp2shell WordPress flaws exploited to install webshells - BleepingComputer

Technology July 23, 2026

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affecteοΏ½...

Flipper Zero firmware development continues with community help - BleepingComputer

Technology July 6, 2026

Flipper Devices says development of the Flipper Zero firmware will continue, albeit with a smaller internal team and greater reliance on community contributions. The announcement comes as the gadgetοΏ½...

New BioShocking attack manipulates AI browser into data theft - BleepingComputer

Technology July 3, 2026

A new prompt injection attack dubbed β€œBioShocking” could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardra...

CISA tells govt agencies to patch critical exploited flaws in 3 days - BleepingComputer

Business June 13, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced a new Binding Operational Directive, 26-04, that prioritizes security updates for Federal Civilian Executive Branch (FCEB) aοΏ½...

Critical cPanel and WHM bug exploited as a zero-day, PoC now available - BleepingComputer

Technology May 1, 2026

The critical CVE-2026-41940 authentication bypass vulnerability in cPanel, WHM, and WP Squared is being actively exploited in the wild and has been leveraged in attempts since late February. It is uοΏ½...

New Linux β€˜Copy Fail’ flaw gives hackers root on major distros

Crypto May 1, 2026

An exploit has been published for a local privilege escalation vulnerability dubbed β€œCopy Fail” that impacts Linux kernels released since 2017, allowing an unprivileged local attacker to gain root...

Threat actor uses Microsoft Teams to deploy new β€œSnow” malware - BleepingComputer

Technology April 26, 2026

A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named β€œSnow,” which includes a browser extension, a tunneler, and a backdoor. Their goal is to stea...

New β€˜Pack2TheRoot’ flaw gives hackers root Linux access - BleepingComputer

Technology April 26, 2026

A new vulnerability dubbedΒ Pack2TheRoot could be exploited in theΒ PackageKit daemon to allowΒ local Linux users to install or remove system packages and gain root permissions. The flaw is identifie...