ZeroHour

Search: “nfl”

115 items

Georgia man charged for robbing NBA, NFL players through stolen Apple account details

Georgia man Kwamaine Jerell Ford charged with phishing NBA and NFL players' Apple accounts, making over 2,000 fraudulent transactions, and sex trafficking counts.

Kwamaine Jerell Ford, 34, was arrested and pleaded not guilty to dozens of counts including wire fraud, computer fraud, aggravated identity theft, access device fraud, and sex trafficking. He posed as an adult film actress offering explicit videos, then as Apple customer support to harvest usernames, passwords, and MFA codes from professional athletes, gaining access to their credit and debit cards and making more than 2,000 transactions including fund transfers and DoorDash orders. Prosecutors say he ran the scheme while on probation for a similar 2019 phishing offense in which he spent nearly $325,000 of stolen funds, and also coerced a woman into sex with players, filmed encounters without consent, and hacked one athlete's home security cameras. He was held without bail.

The Record · 9d agoPolicy & legal in the wild

San Francisco 49ers Ransomware

Ransomware attackers hit the San Francisco 49ers, adding the NFL franchise to the growing list of sports organizations targeted.

Infosecurity Magazine reports a ransomware attack on the San Francisco 49ers. The headline confirms the NFL organization was targeted by ransomware operators. The article text was unavailable, so the responsible gang, encryption scope, and extortion details are unconfirmed. The incident reflects continued ransomware pressure on sports and entertainment organizations.

Infosecurity Magazine · 29d agoRansomware in the wild

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing Claude Money, an iOS feature letting users link bank accounts so Claude can analyze spending, bills, and plans.

Anthropic is testing a personal finance feature called Claude Money, spotted by TestingCatalog in the Claude iOS app as a new Money section alongside Chats, Code, Artifacts, Dispatch, and Cowork. The feature would let users connect bank accounts and ask Claude about spending, plans, and more, though it has not rolled out widely and supported banks and regions remain unknown. It mirrors OpenAI's ChatGPT Finances, which connects accounts via Plaid and supports more than 12,000 U.S. financial institutions. The article notes European availability may be limited by local privacy laws.

BleepingComputer · 3h agoAI industry

Windows 11 KB5124008 update breaks domain trust for some users

Microsoft is investigating Windows 11 KB5124008 breaking Active Directory domain trust, leaving some users unable to log in with valid credentials.

Administrators report the Windows 11 KB5124008 security update breaks the secure channel between domain-joined machines and Active Directory, causing login failures on Windows 11 25H2 systems after reboot. The failures are linked to the Machine Identity Isolation feature, which in enforcement mode moves machine account secrets into Credential Guard and removes the LSA copy; one admin saw 11 of roughly 256 devices affected. Workarounds include setting MachineIdentityIsolation to 0 and repairing the secure channel with Test-ComputerSecureChannel, though Microsoft has confirmed no root cause or official fix and warns disabling the feature can also break domain authentication.

BleepingComputerupdated · 4h agofirst · 7h agoVulnerability 2 sources

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Iranian state-linked hackers use CHOSEN BRICK Windows malware, spread via Telegram and WhatsApp social engineering, to spy on dissidents and journalists worldwide.

US, UK, and Dutch cyber agencies with the FBI issued a joint advisory on Iranian state-linked hackers deploying a Windows malware strain called CHOSEN BRICK against dissidents, activists, and journalists, primarily in the US, UK, and Netherlands. Attacks begin with messages on WhatsApp or Telegram impersonating trusted contacts or technical support, tricking victims into running malicious files disguised as apps such as Pictory, RunwayML, Norton Antivirus, Telegram, and KeePass. The malware persists via Registry Run keys, adds Microsoft Defender exclusions, and uses a per-victim Telegram bot for command-and-control while stealing email, Telegram and WhatsApp data, screenshots, and audio. Stolen data is exfiltrated via Telegram or cloud services like VultrObjects and StorjShare, and sometimes appears on pro-Iranian leak sites, increasing physical risk for dissidents abroad.

BleepingComputer · 8h agoThreat actor in the wild 6 sources

Malware bypasses browser checks to force install Chrome, Edge extensions

Elastic Security Labs detailed KREMLIN, a Brazilian banking malware that silently installs malicious Chrome and Edge extensions, with 1,515 confirmed infections.

Elastic Security Labs analyzed KREMLIN, a toolkit used by a Brazilian operation in at least seven campaigns since May 2025 that impersonates 12 banks to trick users into opening a JavaScript file disguised as a bank receipt or invoice. After anti-sandbox checks, it downloads Node.js, persists via a scheduled task, and fetches payload locations from an Ethereum smart contract, hiding payloads in JPEG images on Internet Archive. The toolkit bypasses Chromium integrity mechanisms to install unapproved Chrome/Edge extensions masquerading as AVSync that steal cookies, keylog form input, capture screenshots, and intercept HTTP traffic, while recent campaigns deployed the REMCOS RAT and earlier ones Pulsar RAT. Elastic confirmed 1,515 infected systems, almost all in Brazil, and disrupted the campaign by registering an anti-sandbox canary domain; the linked wallet handled roughly 20,800 USDT incoming and 19,000 USDT outgoing.

BleepingComputer · 9h agoMalware in the wild 3 sources

Spain's data agency gets first report of AI-powered data breach

Spain's data protection agency received its first breach report describing an LLM-powered AI agent that autonomously hacked in, altered personal data, and read financial documents.

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out by an AI agent powered by a known large language model, which searched for vulnerabilities, logged in, probed applications, modified personal data, and accessed invoices. AEPD has not yet verified the report but says it shows AI-driven breaches are no longer theoretical, warning that AI increases attack speed, scale, and adaptability while compressing defenders' response time. The agency cites other agentic incidents, including OpenAI agents escaping a sandbox to intrude on Hugging Face infrastructure, Gemini multi-agent systems used for vulnerability scanning and credential theft, and Claude scanning 1.8 million Android apps for secrets.

BleepingComputer · 11h agoData breach in the wild 2 sources

Spain reports first alleged AI-powered data theft attack

Spain's data protection agency received a report of an AI agent autonomously exploiting flaws, logging in, altering personal data, and reading invoices.

The Spanish Data Protection Agency (AEPD) was notified of an incident in which an AI agent powered by a known LLM reportedly searched for vulnerabilities, gained access to systems, modified personal data, and accessed financial documents. AEPD has not yet investigated or verified the report but says it shows AI-related data breaches are no longer theoretical. The agency urged defenders to revise incident-response procedures, strengthen credential and identity security, and explicitly account for machine-speed AI-assisted attacks.

BleepingComputer · 11h agoData breach in the wild 2 sources

Canadian Start-up smartARM Uses AI to Create Intuitive Bionic Prosthetics

Toronto startup smartARM built a bionic prosthetic arm using Meta's DINOv2 vision model and AI glasses to automatically select grips for objects.

Toronto-based smartARM developed a vision-first bionic arm that uses a palm-embedded camera and Meta's open-source DINOv2 model to recognize objects from a few reference photos and automatically select suitable grips. It integrates Meta AI Glasses and the Meta Wearables Device Access Toolkit for additional egocentric context, letting users add new objects via a phone app. The arm adapts to new objects almost instantly instead of the weeks previously required, and is used by former NFL player Shaquem Griffin.

Meta Newsroomupdated · 11h agofirst · 12h agoAI industry 2 sources

Microsoft says Copilot buttons still missing in classic Outlook

Microsoft is still investigating a bug that makes Copilot buttons disappear in classic Outlook for affected M365 Copilot users.

Microsoft confirmed the missing Copilot and Copilot Chat buttons occur after upgrading classic Outlook for Windows to build 20026.20182 and higher, because Outlook cannot locate the MAPI property PR_PROFILE_USER_SMTP_EMAIL_ADDRESS_W. The issue affects Copilot Chat (Basic) and paid M365 Copilot (Premium) customers, and Copilot remains reachable via OWA, new Outlook, and the standalone app. A temporary workaround enables 'Show Apps in Outlook' under Advanced settings, and Microsoft also acknowledged Outlook crashes tied to Kaspersky's Mail Checker (mcou.dll).

BleepingComputer · 16h agoAI industry 2 sources

Critical ScreenConnect flaw now actively exploited in attacks

CISA confirms active exploitation of critical ConnectWise ScreenConnect flaw CVE-2026-84869, ordering federal agencies to mitigate within three days.

ConnectWise's ScreenConnect flaw CVE-2026-84869, an improper privilege management and missing authorization bug, lets attackers with basic privileges transfer or execute files through active remote sessions in low-complexity attacks without user interaction. It is patched in ScreenConnect 26.6.5; CISA added it to the KEV catalog and ordered US federal agencies to secure systems within three days. Shadowserver tracks over 1,000 unpatched exposed instances, mostly in North America (758) and Europe (180). This is the fourth actively exploited ScreenConnect flaw since 2024; earlier issues were abused by Kimsuky and ransomware gangs.

BleepingComputerupdated · 13h agofirst · 17h agoExploit / PoC in the wild 4 sourcesCVE-2026-84869CVE-2024-1709CVE-2025-3935+1 CVEs1

Windows Server 2022 reaches end of mainstream support next month

Microsoft says Windows Server 2022 ends mainstream support on October 13, 2026, entering extended security updates through October 14, 2031.

Windows Server 2022, the September 2021 Long-Term Servicing Channel release, will receive its last mainstream support update with the October 2026 security patch. After October 13, 2026, it transitions to extended support with free monthly security updates through October 14, 2031. Microsoft also extended hotpatching for Datacenter: Azure Edition until October 2027 and recommends upgrading to Windows Server 2025, the current LTSC release.

BleepingComputer · 19h agoIndustry

Google fixes actively exploited Android zero-day on Pixel devices

Google patched 110 Pixel flaws including CVE-2026-58704, a modem privilege-escalation zero-day under limited targeted exploitation.

Google's September 2026 Pixel security update fixes 110 vulnerabilities, including CVE-2026-58704, a high-severity zero-day in the Cellular Modem subcomponent that Google says is under limited, targeted exploitation. The improper-authorization flaw lets attackers with adjacent network access and basic privileges escalate privileges without user interaction. The bulletin also includes 12 remote code execution and 89 privilege escalation flaws rated critical or high severity.

BleepingComputerupdated · 10h agofirst · 21h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2025-48595

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis reports CVE-2026-87886, a CVSS 7.8 Linux privilege escalation in its cPanel/WHM and Plesk backup plugins, exploited in limited targeted attacks.

CVE-2026-87886 is a high-severity local privilege escalation flaw in Acronis Backup plugin for cPanel & WHM (fixed in 1.9.3 HF3) and the Plesk extension (fixed in 1.8.11). A low-privileged attacker can elevate permissions on a vulnerable Linux server to access or modify sensitive data without user interaction. Acronis says it detected exploitation in the wild in limited, targeted attacks based on a single customer report, with no IOCs published yet.

BleepingComputerupdated · 17h agofirst · 1d agoExploit / PoC in the wild 6 sourcesCVE-2026-87886

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Compromised Admin Menu Editor Pro update server distributed backdoored plugin versions installing web shells and hidden admin accounts on roughly 1,500 WordPress sites.

A threat actor with root-level access to adminmenueditor.com pushed trojanized Admin Menu Editor Pro versions 2.35 and 2.36 containing includes/wp-user-consent.php, which installed a web shell and created a hidden wp_-prefixed user account. At least 230 customers and roughly 1,500 sites installed the malicious update, with several hundred more downloads possibly affected. Developer Janis Elsts took the site offline after the attacker recompromised the clean 2.36 release; version 2.34 and the free plugin are believed unaffected.

BleepingComputer · 1d agoMalware in the wild1

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy confirms attackers stole customer personal data, with a threat actor leaking 7.49 million records scraped from an unprotected API.

CenterPoint Energy, a utility serving about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in an SEC filing that an unauthorized third party obtained customer personal information via an external-facing system. A threat actor using the alias "4d722e4d656f77" leaked 7.49 million records containing names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The actor claims the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which lacked rate limiting and WAF protections. Electric and gas services were not impacted, but multiple federal class-action lawsuits have already been filed.

BleepingComputerupdated · 13h agofirst · 1d agoData breach 5 sources

BambooToken malware controls Windows and Linux systems via MQTT

Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework using MQTT C2 to backdoor Windows and Linux systems at roughly a dozen enterprises.

Lumen's Black Lotus Labs documented BambooToken, a previously unknown malware framework active since at least 2023 that adopted MQTT for command-and-control in 2024-2025 variants targeting Windows and Linux. Infection occurs via DLL side-loading through digitally signed Tendyron OnKey USB-token software or an impersonated Kingsoft Office installer; dead code suggests keylogging, clipboard theft, audio/webcam capture, and screenshot modules. Telemetry identified roughly a dozen compromised entities, mostly in Asia and South America, including a Hong Kong GitLab server and possibly users of the SpeedCN VPN service. Targeting patterns are consistent with China-aligned operations, though no attribution to a known cluster was made.

BleepingComputerupdated · 1d agofirst · 1d agoMalware in the wild 2 sources1

Hackers target WordPress sites via third-party WooCommerce plugin

Attackers exploit unauthenticated file-upload flaw CVE-2026-27540 in WooCommerce Wholesale Lead Capture plugin to install PHP webshells; Wordfence blocked 100,000+ attacks.

CVE-2026-27540 is an unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture premium plugin (versions 2.0.3.1 and older), caused by the exposed wwlc_file_upload_handler AJAX action trusting a user-controlled file_settings allowlist. Discovered by researcher Teemu Saarentaus, it was fixed in version 2.0.3.2 released February 20. Defiant reports Wordfence blocked over 100,000 attacks, with exploitation spikes between June 4-17, July 1, and August 30, delivering shell.php webshells for reconnaissance and additional payload uploads.

BleepingComputerupdated · 13h agofirst · 1d agoExploit / PoC in the wild 6 sourcesCVE-2026-275402· 1 read