Bill Toulas

Articles by Bill Toulas

Initial access hackers switch to Tsundere Bot for ransomware attacks

Crypto January 30, 2026

A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks. Proofpo...

Hackers hijack exposed LLM endpoints in Bizarre Bazaar operation

Crypto January 29, 2026

A malicious campaign is actively targeting exposed LLM (Large Language Model) service endpoints to commercialize unauthorized access to AI infrastructure. Over a period of 40 days, researchers at P...

WinRAR path traversal flaw still exploited by numerous hackers - BleepingComputer

Technology January 29, 2026

Multiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for initial access and to deliver various malicious pa...

Cloudflare misconfiguration behind recent BGP route leak - BleepingComputer

Technology January 28, 2026

Cloudflare has shared more details about a recent 25-minute Border Gateway Protocol (BGP) route leak affecting IPv6 traffic, which caused measurable congestion, packet loss, and approximately 12 Gbp...

Konni hackers target blockchain engineers with AI-built malware

Crypto January 25, 2026

The North Korean hacker group Konni (Opal Sleet, TA406) is using AI-generated PowerShell malware to target developers and engineers in the blockchain sector. Believed to be associated with APT37 and�...

CISA confirms active exploitation of four enterprise software bugs - BleepingComputer

Technology January 25, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. warned of active exploitation of four vulnerabilities impacting enterprise software from Versa and Zimbra, the Vite frontend to...

New Android malware uses AI to click on hidden browser ads - BleepingComputer

Technology January 24, 2026

A new family of Android click-fraud trojans leverages TensorFlow machine learning models to automatically detect and interact with specific advertisement elements. The mechanism relies on visual ana...

Hackers exploit security testing apps to breach Fortune 500 firms

Crypto January 22, 2026

Threat actors are exploiting misconfigured web applications used for security training and internal penetration testing, such as DVWA, OWASP Juice Shop, Hackazon, and bWAPP, to gain access to cloud ...

Fake ad blocker extension crashes the browser for ClickFix attacks - BleepingComputer

Technology January 21, 2026

A malvertising campaign is using a fake ad-blocking Chrome and Edge extension named NexShield that intentionally crashes the browser in preparation for ClickFix attacks. The attacks were spotted ea...

Reprompt attack let hackers hijack Microsoft Copilot sessions - BleepingComputer

Technology January 15, 2026

Researchers identified an attack method dubbed “Reprompt” that could allow attackers to infiltrate a user’s Microsoft Copilot session and issue commands to exfiltrate sensitive data. By hiding ...