- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchainby Bill Toulas on September 5, 2026 at 2:29 pm
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). […]
- OpenAI admits it didn’t disclose rogue AI wiki hijacking incidentby Ax Sharma on September 5, 2026 at 11:11 am
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model “misalignment” rather than a security breach. […]
- IDScan sued over alleged data breach affecting 153 million driversby Bill Toulas on September 4, 2026 at 4:56 pm
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. […]
- Critical Citrix NetScaler auth bypass now leveraged in attacksby Sergiu Gatlan on September 4, 2026 at 3:25 pm
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. […]
- Microsoft says some users can’t open the Teams desktop clientby Sergiu Gatlan on September 4, 2026 at 2:30 pm
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. […]
- 39 New Methods That Compromise Passkey Authenticationby Sponsored by Token on September 4, 2026 at 2:01 pm
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. […]
- New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privilegesby Sergiu Gatlan on September 4, 2026 at 1:22 pm
An anonymous security researcher who uses the “Nightmare Eclipse” handle released a CrowdStrike Falcon zero-day exploit named “FalconFlank” that lets attackers escalate privileges on up-to-date Windows systems. […]
- Exchange Online outage causes email delays, ‘Server busy’ errorsby Sergiu Gatlan on September 4, 2026 at 12:22 pm
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. […]
- Google warns of new Chrome zero-day flaw exploited in attacksby Bill Toulas on September 4, 2026 at 11:48 am
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. […]
- French hospital fined €500,000 after breach exposes data of 727,000by Bill Toulas on September 3, 2026 at 10:01 pm
France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. […]
- Coder’s registry infrastructure compromised to push malicious modulesby Bill Toulas on September 3, 2026 at 8:04 pm
Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. […]
- HPE patches critical ArubaOS-CX remote code execution flawby Bill Toulas on September 3, 2026 at 6:28 pm
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. […]
- Microsoft: KB5120998 mouse reset bug affects only non-English PCsby Sergiu Gatlan on September 3, 2026 at 3:22 pm
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. […]
Bleeping Computer Cyber Security
We are an ethical website cyber security team and we perform security assessments to protect our clients.





