Security News > 2021

The Christmas Day bombing in downtown Nashville led to phone and data service outages and disruptions over hundreds of miles in the southern U.S., raising new concerns about the vulnerability of U.S. communications. The blast seriously damaged a key AT&T network facility, an important hub that provides local wireless, internet and video service and connects to regional networks.

Over 100,000 Zyxel devices are potentially vulnerable to a secret backdoor caused by hardcoded credentials used to update firewall and AP controllers' firmware. Niels Teusink of Dutch cybersecurity firm EYE discovered a secret hardcoded administrative account in the latest 4.60 patch 0 firmware for some Zyxel devices.

Over 100,000 Zyxel devices are potentially vulnerable to a secret backdoor caused by hardcoded credentials used to update firewall and AP controllers' firmware. Niels Teusink of Dutch cybersecurity firm EYE discovered a secret hardcoded administrative account in the latest 4.60 patch 0 firmware for some Zyxel devices.

This article provides two ways you can download the latest Windows 10 ISO images from Microsoft. Microsoft recommends using their Windows 10 Media Creation Tool to download the latest ISO image or create a bootable USB drive.

Delicious seafood pasta dish — includes squid — from America’s Test Kitchen. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Read...

This holiday edition cover the latest ransomware news from the past two weeks, including known ransomware attacks and law enforcement takedowns. Of particular interest is the Air Forward attack as it was done by the new Hades ransomware operation that began operating last month and has been busy racking up victims.

Next, up the popularity of collaborative business tools, such as Zoom, Skype and Trello, spurred on by the work-from-home trend, triggered a flood of inbox attacks. Beyond inbox impersonation fraud, business email compromise and email phishing attacks, criminals leveraged clever technical traps to ensnare victims.

Below we list the ten most popular stories at BleepingComputer during 2020 with a summary of each. With the public exploit released, Microsoft warned that threat actors quickly adopted them and exploited the ZeroLogon vulnerability in attacks.