Industry Context — Common BS Fingerprints in Media, News & Publishing
BleepingComputer
(https://bleepingcomputer.com) 📸 Data Snapshot: May 28, 2026Analyze the raw signals below. How would a machine score this business’s credibility?
Here are the exact signals captured from up to six pages of the site — the same raw inputs the evaluation engine analyzed. They are grouped by signal type so you can weigh each the way the machine does.
🏗️ Semantic Structure — heading hierarchy & page identity (Info Density · Commodity Fingerprint)
HOMEPAGE BleepingComputer | Cybersecurity, Technology News and Support (https://bleepingcomputer.com)
BleepingComputer | Cybersecurity, Technology News and Support
BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and how to protect your devices.
HEADING_REPEATED_BODY News in the Security category (https://bleepingcomputer.com/news/security/)
News in the Security category
News in the Security category
HEADING_REPEATED_BODY Viewing the profile for Sergiu Gatlan (https://bleepingcomputer.com/author/sergiu-gatlan/)
Viewing the profile for Sergiu Gatlan
BleepingComputer author profile for Sergiu Gatlan.
NAV_HEADER_HEADING_REPEATED_BODY Glassworm botnet disrupted after resilient C2 infrastructure takedown (https://bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/)
Glassworm botnet disrupted after resilient C2 infrastructure takedown
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.
📝 The Narrative — clean text per page (Info Density · Semantic Coherence)
HOMEPAGE (https://bleepingcomputer.com) BleepingComputer | Cybersecurity, Technology News and Support
[IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown] [H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown [IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw] [H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw [IMG: Windows 11 KB5089573 update released with performance improvements] [H4] Windows 11 KB5089573 update released with performance improvements [IMG: Charter confirms data breach after ShinyHunters extortion threat] [H4] Charter confirms data breach after ShinyHunters extortion threat [IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown] [H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown [IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw] [H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw [IMG: Windows 11 KB5089573 update released with performance improvements] [H4] Windows 11 KB5089573 update released with performance improvements [IMG: Charter confirms data breach after ShinyHunters extortion threat] [H4] Charter confirms data breach after ShinyHunters extortion threat [IMG: ThreatLocker] Latest Articles [IMG: Hacker bitcoin] Security [H4] GPU mining malware spreads via SEO poisoning, AI chatbots Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. Ionut Ilascu May 27, 2026 05:31 PM [IMG: Comment Count] 0 [IMG: CompTIA] Deals [H4] This CompTIA IT learning path is only $40 through 6/14 Ready to stop guessing your way through IT learning? Get The Complete 2026 CompTIA Certification Training Bundle for just $39.99 with code SAVE20 through June 14. BleepingComputer Deals May 27, 2026 02:07 PM [IMG: Comment Count] 0 [IMG: Push Security] [H4] Browser & Identity Attacks Matrix: Map your exposure to 51 identity attack techniques [Free Resource] Check out the open-source matrix for browser-based attack techniques. AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — Push Security's Browser & Identity Attacks Matrix maps every technique in one open-source framework. Push Security Sponsorship [IMG: Can you enforce strong Active Directory password rules without frustrating users?] Security [H4] Can you enforce strong Active Directory password rules without frustrating users? Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users. Specops Software May 27, 2026 10:00 AM [IMG: Comment Count] 0 [IMG: GlassWorm] Security [H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. Ionut Ilascu May 27, 2026 09:28 AM [IMG: Comment Count] 0 [IMG: FBI] Security [H4] FBI warns of in-person data theft attacks from extortion gang The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. Sergiu Gatlan May 27, 2026 07:51 AM [IMG: Comment Count] 0 [IMG: Sam] Deals [H4] Your grocery routine’s easiest upgrade is a Sam’s Club membership for just $25 Buying in bulk gets the attention, but convenience is what keeps people coming back. A 1-year Sam's Club Membership for $25 (MSRP $60) makes it easy to test the theory—and a surprisingly practical case for rethinking how you shop. BleepingComputer Deals May 27, 2026 07:12 AM [IMG: Comment Count] 0 [IMG: cPanel] Security [H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. Sergiu Gatlan May 27, 2026 06:06 AM [IMG: Comment Count] 0 [IMG: Law enforcement arrest] Security [H4] Dutch police arrests suspect linked to Ajax football club hack The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. Sergiu Gatlan May 27, 2026 05:09 AM [IMG: Comment Count] 0 [IMG: Windows 11] Microsoft [H4] Windows 11 KB5089573 update released with performance improvements Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. Sergiu Gatlan May 27, 2026 04:33 AM [IMG: Comment Count] 1 [IMG: Hacker] Security [H4] KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. Ionut Ilascu May 26, 2026 04:07 PM [IMG: Comment Count] 0 [IMG: Charter Communications] Security [H4] Charter confirms data breach after ShinyHunters extortion threat U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. Lawrence Abrams May 26, 2026 03:46 PM [IMG: Comment Count] 2 [IMG: Cybersecurity ethical hacking penetration testing] Deals [H4] Nine ethical hacking & penetration testing courses for $30 Breaking into cybersecurity can feel overwhelming, as there are many tools to learn and skills to focus on. The All-in-One Ethical Hacking & Penetration Testing Bundle provides a structured way to get started in cybersecurity, and it is available for a one-time payment of $29.99 (regularly $180). BleepingComputer Deals May 26, 2026 02:11 PM [IMG: Comment Count] 0 [IMG: How Varonis Atlas integrates Claude Compliance API for AI governance] Security [H4] How Varonis Atlas integrates Claude Compliance API for AI governance AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. Varonis May 26, 2026 10:01 AM [IMG: Comment Count] 0 [IMG: Microsoft Defender for Endpoint] Microsoft, Security [H4] Microsoft Defender can now automatically isolate hacked endpoints Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. Sergiu Gatlan May 26, 2026 08:19 AM [IMG: Comment Count] 0 [IMG: Automation] Security [H4] Webinar: Too many tools are slowing network incident response IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident response times. BleepingComputer May 26, 2026 08:16 AM [IMG: Comment Count] 0 [IMG: This lifetime PDF editor is just $65 with code SAVE5 through 5/31] Deals [H4] This lifetime PDF editor is just $65 with code SAVE5 through 5/31 PDFs have a ability to turn simple tasks into frustrating experiences. Need to edit a sentence? Different app. Convert a file? Different app. Sign something? Another app. UPDF changes that by being able to complete most PDF tasks in one application, and it's available for a one-time price of $64.97 (MSRP: $149.99) through May 31. BleepingComputer Deals May 26, 2026 07:12 AM [IMG: Comment Count] 0 [IMG: Drupal] Security [H4] CISA orders feds to patch actively exploited Drupal vulnerability CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Sergiu Gatlan May 26, 2026 04:46 AM [IMG: Comment Count] 0 [IMG: Windows Server] Microsoft [H4] Microsoft: Domain Controller lookup may fail on Windows Server 2016 Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. Sergiu Gatlan May 26, 2026 03:41 AM [IMG: Comment Count] 0 [IMG: 7-Eleven] Security [H4] 7-Eleven data breach exposes personal information of 185,000 people The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. Sergiu Gatlan May 26, 2026 03:01 AM [IMG: Comment Count] 0 [IMG: ClaudeChats] Artificial Intelligence, Software [H4] Anthropic’s restricted Claude Mythos model may be coming to Claude Code Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. Mayank Parmar May 25, 2026 01:07 PM [IMG: Comment Count] 0 1 2 3 4 5 View More [IMG: ThreatLocker] Upcoming Webinar [IMG: Webinar] Popular Stories [IMG: Microsoft 365 phishing] FBI warns of Kali365 phishing service targeting Microsoft 365 accounts [IMG: ClaudeChats] Anthropic’s restricted Claude Mythos model may be coming to Claude Code [IMG: Microsoft Defender for Endpoint] Microsoft Defender can now automatically isolate hacked endpoints Sponsor Posts [IMG: AI is a data-breach time bomb: Read the new report] AI is a data-breach time bomb: Read the new report [IMG: 33% Rise in Healthcare Credential Theft in 2025: What you need to know] 33% Rise in Healthcare Credential Theft in 2025: What you need to know [IMG: Protect Your Business from Ecommerce Fraud] Protect Your Business from Ecommerce Fraud [IMG: Overdue a password health-check? Audit your Active Directory for free] Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar [IMG: Webinar]
SUB-PAGE (https://bleepingcomputer.com/news/security/) News in the Security category
[IMG: ThreatLocker] HomeNews in the Security category News in the Security category [IMG: Hacker bitcoin] [H4] GPU mining malware spreads via SEO poisoning, AI chatbots Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. Ionut Ilascu May 27, 2026 05:31 PM [IMG: Comment Count] 0 [IMG: Can you enforce strong Active Directory password rules without frustrating users?] [H4] Can you enforce strong Active Directory password rules without frustrating users? Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users. Specops Software May 27, 2026 10:00 AM [IMG: Comment Count] 0 [IMG: Push Security] [H4] Browser & Identity Attacks Matrix: Map your exposure to 51 identity attack techniques [Free Resource] Check out the open-source matrix for browser-based attack techniques. AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — Push Security's Browser & Identity Attacks Matrix maps every technique in one open-source framework. Push Security Sponsorship [IMG: GlassWorm] [H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. Ionut Ilascu May 27, 2026 09:28 AM [IMG: Comment Count] 0 [IMG: FBI] [H4] FBI warns of in-person data theft attacks from extortion gang The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. Sergiu Gatlan May 27, 2026 07:51 AM [IMG: Comment Count] 0 [IMG: cPanel] [H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. Sergiu Gatlan May 27, 2026 06:06 AM [IMG: Comment Count] 0 [IMG: Law enforcement arrest] [H4] Dutch police arrests suspect linked to Ajax football club hack The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. Sergiu Gatlan May 27, 2026 05:09 AM [IMG: Comment Count] 0 [IMG: Hacker] [H4] KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. Ionut Ilascu May 26, 2026 04:07 PM [IMG: Comment Count] 0 [IMG: Charter Communications] [H4] Charter confirms data breach after ShinyHunters extortion threat U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. Lawrence Abrams May 26, 2026 03:46 PM [IMG: Comment Count] 2 [IMG: How Varonis Atlas integrates Claude Compliance API for AI governance] [H4] How Varonis Atlas integrates Claude Compliance API for AI governance AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. Varonis May 26, 2026 10:01 AM [IMG: Comment Count] 0 [IMG: Microsoft Defender for Endpoint] [H4] Microsoft Defender can now automatically isolate hacked endpoints Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. Sergiu Gatlan May 26, 2026 08:19 AM [IMG: Comment Count] 0 [IMG: Automation] [H4] Webinar: Too many tools are slowing network incident response IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident response times. BleepingComputer May 26, 2026 08:16 AM [IMG: Comment Count] 0 [IMG: Drupal] [H4] CISA orders feds to patch actively exploited Drupal vulnerability CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Sergiu Gatlan May 26, 2026 04:46 AM [IMG: Comment Count] 0 [IMG: 7-Eleven] [H4] 7-Eleven data breach exposes personal information of 185,000 people The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. Sergiu Gatlan May 26, 2026 03:01 AM [IMG: Comment Count] 0 [IMG: Microsoft 365 phishing] [H4] FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). Lawrence Abrams May 25, 2026 08:45 AM [IMG: Comment Count] 0 [IMG: Ghost CMS] [H4] Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. Bill Toulas May 24, 2026 10:12 AM [IMG: Comment Count] 2 [IMG: Hand data data leak hacker] [H4] Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. Lawrence Abrams May 23, 2026 04:48 PM [IMG: Comment Count] 0 [IMG: FIOD] [H4] Netherlands seizes 800 servers of hosting firm enabling cyberattacks Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. Bill Toulas May 22, 2026 01:24 PM [IMG: Comment Count] 1 [IMG: Hackers] [H4] Former US execs plead guilty to aiding tech support scammers Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. Sergiu Gatlan May 22, 2026 11:32 AM [IMG: Comment Count] 0 [IMG: Trend Micro] [H4] Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Sergiu Gatlan May 22, 2026 09:39 AM [IMG: Comment Count] 0 [IMG: Drupal] [H4] Drupal: Critical SQL injection flaw now targeted in attacks Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. Bill Toulas May 22, 2026 09:14 AM [IMG: Comment Count] 1 1 2 3 4 5 [IMG: ThreatLocker] Upcoming Webinar [IMG: Webinar] Popular Stories [IMG: Microsoft 365 phishing] FBI warns of Kali365 phishing service targeting Microsoft 365 accounts [IMG: ClaudeChats] Anthropic’s restricted Claude Mythos model may be coming to Claude Code [IMG: Microsoft Defender for Endpoint] Microsoft Defender can now automatically isolate hacked endpoints Upcoming Webinar [IMG: Webinar]
SUB-PAGE (https://bleepingcomputer.com/author/sergiu-gatlan/) Viewing the profile for Sergiu Gatlan
HomeViewing author profile for Sergiu Gatlan [H2] Sergiu Gatlan Forum Profile:serghei Get in touch: [IMG: Author Photo] [H5] Author Bio Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips. Sergiu Gatlan News Virus Removal Guides Tutorials News 1 2 3 4 5 [IMG: FBI warns of in-person data theft attacks from extortion gang Image] [H4] FBI warns of in-person data theft attacks from extortion gang The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. Sergiu Gatlan May 27, 2026 07:51 AM [IMG: Comment Count] 0 [IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw Image] [H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. Sergiu Gatlan May 27, 2026 06:06 AM [IMG: Comment Count] 0 [IMG: Dutch police arrests suspect linked to Ajax football club hack Image] [H4] Dutch police arrests suspect linked to Ajax football club hack The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. Sergiu Gatlan May 27, 2026 05:09 AM [IMG: Comment Count] 0 [IMG: Windows 11 KB5089573 update released with performance improvements Image] [H4] Windows 11 KB5089573 update released with performance improvements Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. Sergiu Gatlan May 27, 2026 04:33 AM [IMG: Comment Count] 1 [IMG: Microsoft Defender can now automatically isolate hacked endpoints Image] [H4] Microsoft Defender can now automatically isolate hacked endpoints Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. Sergiu Gatlan May 26, 2026 08:19 AM [IMG: Comment Count] 0 [IMG: CISA orders feds to patch actively exploited Drupal vulnerability Image] [H4] CISA orders feds to patch actively exploited Drupal vulnerability CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Sergiu Gatlan May 26, 2026 04:46 AM [IMG: Comment Count] 0 [IMG: Microsoft: Domain Controller lookup may fail on Windows Server 2016 Image] [H4] Microsoft: Domain Controller lookup may fail on Windows Server 2016 Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. Sergiu Gatlan May 26, 2026 03:41 AM [IMG: Comment Count] 0 [IMG: 7-Eleven data breach exposes personal information of 185,000 people Image] [H4] 7-Eleven data breach exposes personal information of 185,000 people The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. Sergiu Gatlan May 26, 2026 03:01 AM [IMG: Comment Count] 0 [IMG: Former US execs plead guilty to aiding tech support scammers Image] [H4] Former US execs plead guilty to aiding tech support scammers Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. Sergiu Gatlan May 22, 2026 11:32 AM [IMG: Comment Count] 0 [IMG: Trend Micro warns of Apex One zero-day exploited in the wild Image] [H4] Trend Micro warns of Apex One zero-day exploited in the wild Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. Sergiu Gatlan May 22, 2026 09:39 AM [IMG: Comment Count] 0 [IMG: Ubiquiti patches three max severity UniFi OS vulnerabilities Image] [H4] Ubiquiti patches three max severity UniFi OS vulnerabilities Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges. Sergiu Gatlan May 22, 2026 08:00 AM [IMG: Comment Count] 2 [IMG: US and Canada arrest and charge suspected Kimwolf botnet admin Image] [H4] US and Canada arrest and charge suspected Kimwolf botnet admin U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. Sergiu Gatlan May 22, 2026 05:01 AM [IMG: Comment Count] 0 [IMG: Apple blocked over $11 billion in App Store fraud in 6 years Image] [H4] Apple blocked over $11 billion in App Store fraud in 6 years Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. Sergiu Gatlan May 21, 2026 11:11 AM [IMG: Comment Count] 1 [IMG: Max severity Cisco Secure Workload flaw gives Site Admin privileges Image] [H4] Max severity Cisco Secure Workload flaw gives Site Admin privileges Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges. Sergiu Gatlan May 21, 2026 09:58 AM [IMG: Comment Count] 0 [IMG: Microsoft warns of new Defender zero-days exploited in attacks Image] [H4] Microsoft warns of new Defender zero-days exploited in attacks On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. Sergiu Gatlan May 21, 2026 03:49 AM [IMG: Comment Count] 0 Sergiu Gatlan News Virus Removal Guides Tutorials
SUB-PAGE (https://bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/) Glassworm botnet disrupted after resilient C2 infrastructure takedown
[IMG: ThreatLocker] HomeNewsSecurityGlassworm botnet disrupted after resilient C2 infrastructure takedown [H1] Glassworm botnet disrupted after resilient C2 infrastructure takedown By [H6] Ionut Ilascu May 27, 2026 09:28 AM 0 [IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown] The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. In a coordinated operation conducted yesterday, CrowdStrike, Google, and The Shadowserver Foundation cut off the botnet operators’ access to four distinct command-and-control (C2) channels designed to resist conventional disruption efforts. Glassworm campaigns have been ongoing since October 2025 and initially targeted developers with malicious OpenVSX and Microsoft VS Code extensions that stole cryptocurrency wallets and developer credentials. Later attack waves extended to GitHub repositories and npm packages, with one campaign in March impacting more than 400 software artifacts. In a more recent attack, Glassworm operators planted dozens of dormant extensions on OpenVSX that would activate the malicious component after an update. One reason the Glassworm threat has survived this long is its C2 infrastructure, which relies on non-traditional communication channels that are difficult to take down. “The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C2 servers behind multiple layers of indirection,” CrowdStrike notes. The researchers say that “Glassworm's operators built their infrastructure for resilience,” and taking down the botnet required hitting the four C2 channels simultaneously: Solana blockchain: C2 server addresses are encoded in the memo fields of blockchain transactions, creating an immutable, publicly accessible dead drop that cannot be taken offline by conventional means. BitTorrent Distributed Hash Table (DHT): The GlasswormRAT queries the BitTorrent peer-to-peer network for configuration data stored against hardcoded public keys, leveraging a global decentralized network with no single point of failure. Public calendar service: Glassworm uses Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths. Direct server connections: Traditional C2 infrastructure hosted on commercial VPS providers served as the final payload delivery mechanism. Glassworm command-and-control architecturesource: CrowdStrike Because of this architecture, disrupting a single channel would have little impact on the Glassworm operation, as communications could shift to another channel, allowing the threat actor to maintain control. “All four channels had to be disrupted simultaneously in a coordinated effort. As a result, infected machines can no longer receive new instructions or payloads,” CrowdStrike says. Following the disruption, all machines compromised in a Glassworm attack are beaconing to the IP address 164.92.88[.]210 operated by CrowdStrike. Organizations are advised to look for this network indicator and take immediate remediation action. Additionally, the researchers have published YARA rules to confirm infections on suspected hosts. [IMG: article image] [H2] The Validation Gap: Automated Pentesting Answers One Question. You Need Six. Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.This guide covers the 6 surfaces you actually need to validate. Download Now [H3] Related Articles: FBI warns of in-person data theft attacks from extortion gang7-Eleven confirms data breach claimed by the ShinyHunters gangGitHub confirms breach of 3,800 repos via malicious VSCode extensionInside a Crypto Drainer: How to Spot it Before it Empties Your WalletGitHub links repo breach to TanStack npm supply-chain attack CryptoCurrency Data Theft Developer GlassWorm Supply Chain Takedown [H5] Ionut Ilascu Ionut Ilascu is a technology writer with a focus on all things cybersecurity. The topics he writes about include malware, vulnerabilities, exploits and security defenses, as well as research and innovation in information security. His work has been published by Bitdefender, Netgear, The Security Ledger and Softpedia. [H5] Post a Comment Community Rules [H6] You need to login in order to post a comment Not a member yet? Register Now [H3] You may also like: [IMG: ThreatLocker] Upcoming Webinar [IMG: Webinar] Popular Stories [IMG: Microsoft 365 phishing] FBI warns of Kali365 phishing service targeting Microsoft 365 accounts [IMG: ClaudeChats] Anthropic’s restricted Claude Mythos model may be coming to Claude Code [IMG: Microsoft Defender for Endpoint] Microsoft Defender can now automatically isolate hacked endpoints Sponsor Posts [IMG: Protect Your Business from Ecommerce Fraud] Protect Your Business from Ecommerce Fraud [IMG: AI is a data-breach time bomb: Read the new report] AI is a data-breach time bomb: Read the new report [IMG: 33% Rise in Healthcare Credential Theft in 2025: What you need to know] 33% Rise in Healthcare Credential Theft in 2025: What you need to know [IMG: Overdue a password health-check? Audit your Active Directory for free] Overdue a password health-check? Audit your Active Directory for free Upcoming Webinar [IMG: Webinar]
🛡️ Trust Signals — reviews, proof links, trust-theatre flag (Trust & Proof)
| Page | Reviews | Proof links |
|---|---|---|
| / (home) | 11 | 3 |
| /news/security/ | 9 | 3 |
| /author/sergiu-gatlan/ | 7 | 3 |
| /news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/ | 6 | 3 |
🔗 Identity & Technical Layer — schema JSON-LD: identity chains, entity gaps (Identity & Authority)
Homepage schema
[
{
"@context": "https://schema.org",
"@type": "WebSite",
"url": "https://www.bleepingcomputer.com/",
"name": "BleepingComputer",
"potentialAction": {
"@type": "SearchAction",
"target": {
"@type": "EntryPoint",
"urlTemplate": "https://www.bleepingcomputer.com/search/?cx=partner-pub-0920899300397823%3A3529943228&cof=FORID%3A10&ie=UTF-8&q={search_term_string}"
},
"query-input": "required name=search_term_string"
}
},
{
"@context": "https://schema.org",
"@type": "NewsMediaOrganization",
"@id": "https://www.bleepingcomputer.com/",
"name": "BleepingComputer",
"url": "https://www.bleepingcomputer.com",
"description": "BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and how to protect your devices.",
"alternateName": [
"bleepingcomputer.com",
"BleepingComputer",
"bleepingcomputer"
],
"logo": {
"@type": "ImageObject",
"url": "https://www.bleepstatic.com/logos/bleepingcomputer-logo.png",
"height": "700",
"width": "700"
},
"ethicsPolicy": "https://www.bleepingcomputer.com/ethics-statement/",
"masthead": "https://www.bleepingcomputer.com/about/",
"foundingDate": "2004-01-26",
"founder": [
{
"@type": "Person",
"name": "Lawrence Abrams"
}
],
"sameAs": [
"https://www.linkedin.com/company/bleepingcomputer",
"https://www.wikidata.org/wiki/Q4925939",
"https://www.facebook.com/BleepingComputer",
"https://twitter.com/BleepinComputer",
"https://www.youtube.com/user/BleepingComputer"
],
"knowsAbout": [
{
"@type": "Thing",
"name": "cybersecurity"
},
{
"@type": "Thing",
"name": "cybersecurity news"
},
{
"@type": "Thing",
"name": "technology"
},
{
"@type": "Thing",
"name": "tech news"
},
{
"@type": "Thing",
"name": "microsoft news"
},
{
"@type": "Thing",
"name": "malware"
},
{
"@type": "Thing",
"name": "antivirus"
},
{
"@type": "Thing",
"name": "anti-malware"
},
{
"@type": "Thing",
"name": "vpn"
},
{
"@type": "Thing",
"name": "cyberattacks"
},
{
"@type": "Thing",
"name": "hackers"
},
{
"@type": "Thing",
"name": "windows"
},
{
"@type": "Thing",
"name": "linux"
},
{
"@type": "Thing",
"name": "hardware"
}
]
}
]
/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/
{
"@context": "https://schema.org",
"@type": "NewsArticle",
"url": "https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/",
"headline": "Glassworm botnet disrupted after resilient C2 infrastructure takedown",
"name": "Glassworm botnet disrupted after resilient C2 infrastructure takedown",
"mainEntityOfPage": {
"@type": "WebPage",
"id": "https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/"
},
"description": "The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.",
"image": {
"@type": "ImageObject",
"digitalSourceType": "trainedAlgorithmicMedia",
"url": "https://www.bleepstatic.com/content/hl-images/2026/03/17/glassworm.jpg",
"width": 1600,
"height": 900
},
"author": {
"@type": "Person",
"name": "Ionut Ilascu",
"url": "https://www.bleepingcomputer.com/author/ionut-ilascu/"
},
"keywords": [
"CryptoCurrency",
"Data Theft",
"Developer",
"GlassWorm",
"Supply Chain",
"Takedown",
"Security",
"InfoSec, Computer Security"
],
"datePublished": "2026-05-27T09:28:42-04:00",
"dateModified": "2026-05-27T09:28:42-04:00",
"publisher": {
"@type": "Organization",
"name": "BleepingComputer",
"url": "https://www.bleepingcomputer.com/",
"logo": {
"@type": "ImageObject",
"url": "https://www.bleepstatic.com/logos/bleepingcomputer-logo.png",
"width": 700,
"height": 700
}
}
}
Your Diagnosis
Before revealing the machine’s verdict, predict the BS score for each signal. Higher = more BS (more fluff, less verifiable substance). Drag each slider, then submit to compare your judgment against the engine.
Stuck? Reveal the heuristic lens — how the deterministic page-auditor reads each signal (no AI, pure pattern rules)
These are the structural rules a local, deterministic auditor applies — the same lens you can use to judge each signal. They describe what to look for, not this company’s result.
Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.
Pull the main entities out of the H1, then check whether they actually recur through the body. A page that announces one thing and then talks about another drifts. Headings with no real sentences underneath read as pseudo-substance.
Count trust words (review, testimonial, rating, verified) against real outbound proof links (Google, Trustpilot, Clutch, G2, Yelp). Lots of trust language with zero verification links is trust theatre. Unlinked logo galleries count against it.
Look at how much sentence length varies. Natural writing varies its rhythm; templated or mass-produced copy is statistically uniform. Very low variation reads as commodity content — unless unique named entities break the pattern.
Inspect the JSON-LD. Is there an Organization or Person schema, and does it carry sameAs links to real external profiles (LinkedIn, socials)? Missing schema or no identity declaration signals an anonymous entity.
Want to apply this lens yourself? The free BS Indicator Chrome extension runs these heuristic checks live on any page. Bear in mind it is a single-page, deterministic tool — it relies only on pattern rules for the page in front of it and does not perform the cross-page semantic correlation this audit uses, so its readout is a starting lens, not the full verdict.
Based on 831 businesses audited.
BleepingComputer has 26.7 points less BS than the average for Media, News & Publishing.
Media, News & Publishing BS: BleepingComputer (bleepingcomputer.com)
BleepingComputer is a technical reporting powerhouse that operates with almost zero bullshit. It eschews the typical ‘cutting-edge solution’ marketing speak of the cybersecurity industry in favor of cited, dated, and forensically specific reporting. The only measurable noise comes from its clearly demarcated affiliate ‘Deals’ section, which is a standard commercial reality rather than editorial bullshit.
To achieve a near-zero score, consolidate the ‘Deals’ section into a separate sub-domain or a more distinct visual sidebar to ensure consumer goods do not appear in the cybersecurity ‘Latest Articles’ feed. Implement granular Person schema for staff reporters like Sergiu Gatlan, including sameAs links to professional social profiles to match the founder’s transparency level. Explicitly link ‘Comment Counts’ to a community verification policy to further differentiate user sentiment from unverified testimonials. Ensure that all sponsored posts maintain the high technical specificity of the editorial news to avoid substance-drift in paid placements.
The website perfectly aligns with the Media, News & Publishing category, specifically focusing on cybersecurity. The content demonstrates a high frequency of industry_jargon like ‘fact-checked reporting’ and ‘source verification’ while delivering on the promise of technical investigative journalism.
“The bs_score of 8 is driven by the site's exceptional specificity and technical accountability. Minor points were lost in the Commodity Fingerprint and Semantic Coherence pillars due to the presence of non-security 'Deals' (e.g., Sam's Club) and the use of 'Premier' as a generic claim. However, the Identity and Authority pillar is nearly perfect due to the high-quality NewsMediaOrganization schema provided.”
This training module utilizes a snapshot of public data from BleepingComputer, captured on May 28, 2026, to demonstrate how machine logic evaluates different types of business narratives.
Purpose: This data is presented under “Fair Use” / “Educational Exception” for the purpose of forensic semantic analysis, allowing users to compare human intuition against machine-generated evaluations.
Notice to BleepingComputer: This analysis is part of a non-adversarial audit conducted by 1 Euro SEO. The results provided by 1EuroSEO are intended as professional feedback to help improve any website’s machine-readability and authority signals. The 1EuroSEO BS Detection Tool is a free tool, and anyone can test any company to see how their content is interpreted by AI models.
Any company can use the insights for free and improve its voice by comparing it to industry clichés or competitors. When a company has updated its content, it can always submit a new audit request, which will be reflected in a new current score.
To all users: You are encouraged to visit the live site at https://bleepingcomputer.com to view the most current version of its content and learn from the source what this company is about and what it offers.