BTC$85,190+0.77% LTC$69.87+3.93% XMR$543.25+0.03%
TorPortal TorPortalMarkets, mirrors, dark web news

All TorPortal news from BleepingComputer

50 stories pulled from BleepingComputer, newest first. We do not run this source, we just index what they publish.

Latest from BleepingComputer

Click a headline for the full story or jump straight to the original.

GitLab warns of critical RCE vulnerability in AI Gateway service
BleepingComputer · Oct 2, 2026 · 2 min read

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
US sanctions Tren de Aragua gang members in ATM hacks crackdown
BleepingComputer · Oct 2, 2026 · 2 min read

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States.
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
BleepingComputer · Oct 2, 2026 · 7 min read

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level…
Dell asks admins to patch max severity CSM flaws as soon as possible
BleepingComputer · Oct 2, 2026 · 2 min read

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
Microsoft’s X account hacked in crypto pump-and-dump scheme
BleepingComputer · Oct 2, 2026 · 3 min read

Microsoft’s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
BleepingComputer · Oct 1, 2026 · 4 min read

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
Autonomous AI agents tried to hack US, Canadian government websites
BleepingComputer · Oct 1, 2026 · 4 min read

Autonomous AI agents tried to hack US, Canadian government websites

Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics.
Microsoft says threat actors are ahead in the early AI race
BleepingComputer · Oct 1, 2026 · 3 min read

Microsoft says threat actors are ahead in the early AI race

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams…
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
BleepingComputer · Oct 1, 2026 · 3 min read

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator.
The Day-One Hole in Zero Trust Architecture
BleepingComputer · Oct 1, 2026 · 5 min read

The Day-One Hole in Zero Trust Architecture

Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before…
Kiteworks patches max severity code injection vulnerability
BleepingComputer · Oct 1, 2026 · 2 min read

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.
Microsoft enables Windows settings backup by default for orgs
BleepingComputer · Oct 1, 2026 · 2 min read

Microsoft enables Windows settings backup by default for orgs

Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2.
Hackers stole Pentagon personnel records of over 3 million people
BleepingComputer · Oct 1, 2026 · 2 min read

Hackers stole Pentagon personnel records of over 3 million people

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon's human resources management system in October 2025.
Metamask discloses security incident affecting its infrastructure
BleepingComputer · Oct 1, 2026 · 1 min read

Metamask discloses security incident affecting its infrastructure

On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure.
Russian state hackers use new RedFlick technique to push malware
BleepingComputer · Sep 30, 2026 · 3 min read

Russian state hackers use new RedFlick technique to push malware

The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor.
DIVD says Zammad zero-days enabled AI-driven network breach
BleepingComputer · Sep 30, 2026 · 2 min read

DIVD says Zammad zero-days enabled AI-driven network breach

The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system.
Over 543,000 valid credentials exposed in public GitHub repositories
BleepingComputer · Sep 30, 2026 · 2 min read

Over 543,000 valid credentials exposed in public GitHub repositories

More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data.
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
BleepingComputer · Sep 30, 2026 · 2 min read

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
Cisco warns of new SD-WAN zero-day exploited in attacks
BleepingComputer · Sep 30, 2026 · 2 min read

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
BleepingComputer · Sep 30, 2026 · 7 min read

AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped…
Microsoft to block Entra ID script injection attacks starting October
BleepingComputer · Sep 30, 2026 · 2 min read

Microsoft to block Entra ID script injection attacks starting October

Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month.
TeamViewer urges users to patch severe flaws “as soon as possible”
BleepingComputer · Sep 30, 2026 · 2 min read

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.
Bitget hacked via zero-day in third-party security products
BleepingComputer · Sep 30, 2026 · 2 min read

Bitget hacked via zero-day in third-party security products

Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products.
Microsoft is rolling out Linux container support to WSL
BleepingComputer · Sep 30, 2026 · 2 min read

Microsoft is rolling out Linux container support to WSL

Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available.
Signal adds encypted local backup support to iOS, desktop apps
BleepingComputer · Sep 29, 2026 · 2 min read

Signal adds encypted local backup support to iOS, desktop apps

Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows).
Custom ChatGPTs push ClickFix attacks to deploy RAT malware
BleepingComputer · Sep 29, 2026 · 3 min read

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
FBI tells ShinyHunters members to turn themselves in after recent arrest
BleepingComputer · Sep 29, 2026 · 3 min read

FBI tells ShinyHunters members to turn themselves in after recent arrest

The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders.
Hackers exploit Citrix NetScaler zero-day to deploy web shells
BleepingComputer · Sep 29, 2026 · 5 min read

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks.
Former US Air Force members sent to prison over BEC attacks
BleepingComputer · Sep 29, 2026 · 2 min read

Former US Air Force members sent to prison over BEC attacks

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns.
Windows 11 2026 Update released, here's everything you need to know
BleepingComputer · Sep 29, 2026 · 2 min read

Windows 11 2026 Update released, here's everything you need to know

Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it.
New Spectre v2 attack variant leaks Linux root password hash in minutes
BleepingComputer · Sep 29, 2026 · 4 min read

New Spectre v2 attack variant leaks Linux root password hash in minutes

A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
Automated AI agent used to breach cybersecurity nonprofit DIVD
BleepingComputer · Sep 29, 2026 · 2 min read

Automated AI agent used to breach cybersecurity nonprofit DIVD

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy."
Catch threats before they escalate with real-time Identity Telemetry
BleepingComputer · Sep 29, 2026 · 4 min read

Catch threats before they escalate with real-time Identity Telemetry

Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity…
Vietnamese man charged in $16 million 'pig butchering' crypto scam
BleepingComputer · Sep 29, 2026 · 2 min read

Vietnamese man charged in $16 million 'pig butchering' crypto scam

A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency.
Kiteworks patches critical flaw, brings customer systems online
BleepingComputer · Sep 29, 2026 · 2 min read

Kiteworks patches critical flaw, brings customer systems online

American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · Sep 29, 2026 · 2 min read

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
Japan's Keio confirms ransomware attack disrupted business systems
BleepingComputer · Sep 28, 2026 · 2 min read

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.
Times Car confirms data breach affecting 6.6 million user accounts
BleepingComputer · Sep 28, 2026 · 2 min read

Times Car confirms data breach affecting 6.6 million user accounts

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.
Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer · Sep 28, 2026 · 2 min read

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
Over 16,000 Supabase databases expose PII, passwords, auth tokens
BleepingComputer · Sep 28, 2026 · 2 min read

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.
JadePuffer agentic AI attacks target Azure, destroy cloud resources
BleepingComputer · Sep 28, 2026 · 2 min read

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
BleepingComputer · Sep 28, 2026 · 5 min read

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how…
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
BleepingComputer · Sep 28, 2026 · 2 min read

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million.
US soldier gets 70 months in prison for extorting 10 tech, telecom firms
BleepingComputer · Sep 28, 2026 · 2 min read

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024.
CISA orders feds to patch exploited Citrix flaws by Wednesday
BleepingComputer · Sep 28, 2026 · 3 min read

CISA orders feds to patch exploited Citrix flaws by Wednesday

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
BleepingComputer · Sep 27, 2026 · 1 min read

OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email

OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website.
Citrix confirms two NetScaler RCE zero-days exploited in attacks
BleepingComputer · Sep 27, 2026 · 4 min read

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws.
Cloudflare fixes Containers cross-tenant flaw exposing customer data
BleepingComputer · Sep 27, 2026 · 2 min read

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host.
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
BleepingComputer · Sep 27, 2026 · 1 min read

Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors

Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
BleepingComputer · Sep 26, 2026 · 4 min read

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on…