<?xml version='1.0' encoding='utf-8'?>
<?xml-stylesheet type="text/xsl" href="/static/rss.xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>102</id>
  <title>BleepingComputer</title>
  <updated>2026-07-27T17:29:49+00:00</updated>
  <author>
    <name>Unknown</name>
  </author>
  <link href="https://www.bleepingcomputer.com/" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>BleepingComputer - All Stories</subtitle>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/</id>
    <title>Hackers target US firms in FastJson RCE zero-day attacks</title>
    <updated>2026-07-27T15:49:44+00:00</updated>
    <author>
      <name>Bill Toulas</name>
    </author>
    <content type="html">Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/"/>
    <summary type="html">Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]</summary>
    <published>2026-07-27T15:49:44+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/</id>
    <title>Arista patches VeloCloud Orchestrator zero-day exploited in attacks</title>
    <updated>2026-07-27T14:49:44+00:00</updated>
    <author>
      <name>Lawrence Abrams</name>
    </author>
    <content type="html">Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/"/>
    <summary type="html">Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]</summary>
    <published>2026-07-27T14:49:44+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</id>
    <title>New Dysphoria DDoS botnet spreads to 200k devices worldwide</title>
    <updated>2026-07-27T13:08:15+00:00</updated>
    <author>
      <name>Bill Toulas</name>
    </author>
    <content type="html">A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/"/>
    <summary type="html">A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]</summary>
    <published>2026-07-27T13:08:15+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/</id>
    <title>New Certighost PoC exploit lets attackers hijack Windows domains</title>
    <updated>2026-07-27T13:00:25+00:00</updated>
    <author>
      <name>Lawrence Abrams</name>
    </author>
    <content type="html">A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/"/>
    <summary type="html">A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]</summary>
    <published>2026-07-27T13:00:25+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/</id>
    <title>Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin</title>
    <updated>2026-07-27T09:29:07+00:00</updated>
    <author>
      <name>Lawrence Abrams</name>
    </author>
    <content type="html">Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/"/>
    <summary type="html">Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]</summary>
    <published>2026-07-27T09:29:07+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/</id>
    <title>Coca-Cola confirms data theft in Fairlife ransomware attack</title>
    <updated>2026-07-27T07:39:51+00:00</updated>
    <author>
      <name>Bill Toulas</name>
    </author>
    <content type="html">The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/"/>
    <summary type="html">The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]</summary>
    <published>2026-07-27T07:39:51+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/</id>
    <title>Ernst &amp; Young data breach claimed by ShinyHunters extortion gang</title>
    <updated>2026-07-27T07:12:27+00:00</updated>
    <author>
      <name>Lawrence Abrams</name>
    </author>
    <content type="html">The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst &amp; Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/"/>
    <summary type="html">The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst &amp; Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]</summary>
    <published>2026-07-27T07:12:27+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/shadow-ai-agents-are-multiplying-heres-how-to-find-and-secure-them/</id>
    <title>Shadow AI agents are multiplying. Here's how to find and secure them.</title>
    <updated>2026-07-27T06:01:11+00:00</updated>
    <author>
      <name>Sponsored by Nudge Security</name>
    </author>
    <content type="html">Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/shadow-ai-agents-are-multiplying-heres-how-to-find-and-secure-them/"/>
    <summary type="html">Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]</summary>
    <published>2026-07-27T06:01:11+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/</id>
    <title>GitHub, PyPI add time-based defenses against supply chain attacks</title>
    <updated>2026-07-26T06:13:39+00:00</updated>
    <author>
      <name>Bill Toulas</name>
    </author>
    <content type="html">GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/"/>
    <summary type="html">GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]</summary>
    <published>2026-07-26T06:13:39+00:00</published>
  </entry>
  <entry>
    <id>https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/</id>
    <title>Steam forum ClickFix attacks infect gamers with XMRig cryptominers</title>
    <updated>2026-07-25T14:37:47+00:00</updated>
    <author>
      <name>Lawrence Abrams</name>
    </author>
    <content type="html">Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]</content>
    <link href="https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/"/>
    <summary type="html">Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]</summary>
    <published>2026-07-25T14:37:47+00:00</published>
  </entry>
</feed>
