<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Breaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!</description><link>https://bsky.app/profile/bleepingcomputer.com</link><title>@bleepingcomputer.com - BleepingComputer</title><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlw2zzba3m26</link><description>A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages.&#xA;https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/</description><pubDate>15 May 2026 15:30 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlw2zzba3m26</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlvvbozols2g</link><description>​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations.&#xA;https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/</description><pubDate>15 May 2026 13:47 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlvvbozols2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlvt7yf34f2u</link><description>Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm.&#xA;https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</description><pubDate>15 May 2026 13:10 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlvt7yf34f2u</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlvp3zjubq2m</link><description>Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the database.&#xA;https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/</description><pubDate>15 May 2026 11:57 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlvp3zjubq2m</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlvmhejdec2k</link><description>Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was &#34;by design.&#34;&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/</description><pubDate>15 May 2026 15:09 +0000</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlvmhejdec2k</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlvdjpognn2k</link><description>Microsoft is introducing a new Windows Update capability that will allow it to remotely roll back problematic Windows drivers delivered through Windows Update.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-to-automatically-roll-back-faulty-windows-drivers/</description><pubDate>15 May 2026 08:30 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlvdjpognn2k</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlv23astef2k</link><description>On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/</description><pubDate>15 May 2026 05:40 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlv23astef2k</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mltvr6umjm26</link><description>The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data.&#xA;https://www.bleepingcomputer.com/news/security/teampcp-hackers-advertise-mistral-ai-code-repos-for-sale/</description><pubDate>14 May 2026 18:51 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mltvr6umjm26</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mltpy4c7vx2f</link><description>Hackers are leveraging a critical authentication bypass vulnerability in the WordPress plugin Burst Statistics to obtain admin-level access to websites.&#xA;https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/</description><pubDate>14 May 2026 17:07 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mltpy4c7vx2f</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mltmrobuwa2u</link><description>Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices.&#xA;https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/</description><pubDate>14 May 2026 16:10 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mltmrobuwa2u</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mltjbqch4y2w</link><description>OpenAI says two employees&#39; devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.&#xA;https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/</description><pubDate>14 May 2026 15:07 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mltjbqch4y2w</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mltijjlpn62k</link><description>On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days.&#xA;https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/</description><pubDate>14 May 2026 14:54 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mltijjlpn62k</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlt5vpxyzi2g</link><description>An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.&#xA;https://www.bleepingcomputer.com/news/security/18-year-old-nginx-vulnerability-allows-dos-potential-rce/</description><pubDate>14 May 2026 11:44 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlt5vpxyzi2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlss44trd72l</link><description>Initial access broker KongTuke has moved to Microsoft Teams for social engineering attacks, taking as little as five minutes to gain persistent access to corporate networks.&#xA;https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/</description><pubDate>14 May 2026 08:12 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlss44trd72l</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlskvi4wpo2m</link><description>Dell confirmed that its SupportAssist software is causing blue-screen crashes on some Windows systems following a wave of user reports about random reboots affecting Dell devices since Friday.&#xA;https://www.bleepingcomputer.com/news/software/dell-confirms-its-supportassist-software-causes-windows-bsod-crashes/</description><pubDate>14 May 2026 06:03 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlskvi4wpo2m</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlsh4etayt2v</link><description>The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laundering charges.&#xA;https://www.bleepingcomputer.com/news/security/us-charges-suspected-dream-market-admin-arrested-in-germany/</description><pubDate>14 May 2026 04:56 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlsh4etayt2v</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlscdil7ah26</link><description>Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300)  that allows attackers to run malicious code as root.&#xA;https://www.bleepingcomputer.com/news/security/new-fragnesia-linux-flaw-lets-attackers-gain-root-privileges/</description><pubDate>14 May 2026 03:30 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlscdil7ah26</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlrdrkii332u</link><description>West Pharmaceutical Services disclosed that it was the target of a cyberattack that resulted in data exfiltration and system encryption.&#xA;https://www.bleepingcomputer.com/news/security/west-pharmaceutical-says-hackers-stole-data-encrypted-systems/</description><pubDate>13 May 2026 18:23 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlrdrkii332u</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlrcgme7dm26</link><description>The Iran-linked hacking group MuddyWater (a.k.a. Seedworm, Static Kitten) launched a broad cyber-espionage campaign targeting at least nine high-profile organizations across multiple sectors and countries.&#xA;https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-major-south-korean-electronics-maker/</description><pubDate>13 May 2026 17:59 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlrcgme7dm26</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlr53j5mtz2m</link><description>A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary code.&#xA;https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/</description><pubDate>13 May 2026 16:24 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlr53j5mtz2m</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlqqhej2yc2u</link><description>A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.&#xA;https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/</description><pubDate>13 May 2026 12:38 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlqqhej2yc2u</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlqnewnxjv2v</link><description>Microsoft has addressed a known issue causing some Windows 11 systems to boot into BitLocker recovery after installing the April 2026 Windows security updates.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-issue-only-for-windows-11-users/</description><pubDate>13 May 2026 11:43 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlqnewnxjv2v</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlqjntua2r2g</link><description>Microsoft has fixed a Windows Autopatch bug that caused driver updates restricted by administrative policies to be deployed on some Autopatch-managed Windows devices in the European Union.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-autopatch-bug-installing-restricted-drivers/</description><pubDate>13 May 2026 10:36 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlqjntua2r2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlqdpsszxm2m</link><description>Foxconn, the world&#39;s largest electronics manufacturer, says some of its North American factories are now working to resume normal operations after a cyberattack.&#xA;https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/</description><pubDate>13 May 2026 08:50 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlqdpsszxm2m</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlqalnufa42u</link><description>Microsoft says some customers are experiencing issues downloading and installing Office on their Windows 365 devices.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-install-office-on-windows-365-devices/</description><pubDate>13 May 2026 07:54 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlqalnufa42u</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlovvryoxx2g</link><description>The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company&#39;s Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.&#xA;https://www.bleepingcomputer.com/news/security/us-govt-seeks-instructure-testimony-on-massive-canvas-cyberattack/</description><pubDate>12 May 2026 19:10 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlovvryoxx2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlomb2647k2f</link><description>The Information Commissioner&#39;s Office has fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) over a cyberattack that exposed the personal data of 663,887 customers and employees.&#xA;https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/</description><pubDate>12 May 2026 16:17 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlomb2647k2f</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlok74jbhh2g</link><description>Signal has introduced new in-app confirmations and warning messages as additional safeguards against phishing and social engineering attempts that could lead to various forms of fraud.&#xA;https://www.bleepingcomputer.com/news/security/signal-adds-security-warnings-for-social-engineering-phishing-attacks/</description><pubDate>12 May 2026 15:40 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlok74jbhh2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlohu2yt2s2g</link><description>Microsoft has released the Windows 10 KB5087544 extended security update to fix the May 2026 Patch Tuesday vulnerabilities and resolve an issue with the new Remote Desktop warnings.&#xA;https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5087544-extended-security-update/</description><pubDate>12 May 2026 14:58 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlohu2yt2s2g</guid></item><item><link>https://bsky.app/profile/bleepingcomputer.com/post/3mlofur2pnz26</link><description>Fortinet has released security patches for two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to run commands or arbitrary code.&#xA;https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-rce-flaws-in-fortisandbox-and-fortiauthenticator/</description><pubDate>12 May 2026 14:23 -0400</pubDate><guid isPermaLink="false">at://did:plc:kbdifeeymt5ppkl4gtq3i7be/app.bsky.feed.post/3mlofur2pnz26</guid></item></channel></rss>