Information Security News Blog
-
Revolut handed strangers copies of passports, verification selfies, and the financial histories of some clients, mistaking fraudulent requests for the official approaches of a government agency. On September 12, 2026, the British fintech confirmed...
-
Researchers have discovered a key embedded in the code of the Shinobi video surveillance system, through which an outsider could gain access to the user database and camera settings without a login or password....
-
A small model reads a text and answers “safe.” Then the very same text reaches a more powerful AI, which finds a hidden command within and executes it. Check Point Research has laid bare...
An ordinary QR code, ostensibly designed for seamlessly transferring screenshots, has alarmingly materialized as a clandestine gateway directly into the memory architecture of the console. On September 10, Nintendo officially cautioned owners across the...
Android ransomware is no longer confined to locking files: Mantax Otax transforms an infected smartphone into a spying instrument and a channel of pressure on its owner at once. Zimperium has described the malware,...
A collection of local Linux vulnerabilities has acquired a second life as weaponized code engineered for total root compromise. NebuSec disclosed a series of critical kernel vulnerabilities and published fully functional exploits, meticulously verified...
Plex is once again urging owners of home media servers to act before any technical explanation appears. On September 1, the company demanded that users update Plex Media Server to version 1.43.3 or newer,...
An Android feature devised to separate personal and corporate applications has become a hiding place for banking fraud. Group-IB has described the pairing of Gigabud and Vwork, which, in a confirmed chain, creates a...
One of the most sensitive aviation databases proved to be guarded less securely than a rudimentary web service. On June 3, Kinryū Labs uncovered a staggering 220,783,700 records concerning passengers and flight crews within...
Passkeys were originally conceived as the ultimate cure for phishing, yet threat actors have ingeniously discovered a darker role for this technology. Currently, an attacker merely needs to telephone an employee while masquerading as...
A Wi-Fi repeater costing a mere 3 pounds has emerged as a device harboring a pre-configured, concealed backdoor, effectively inviting complete system compromise. Penetration tester Kieran Smith meticulously dissected the firmware of an unbranded...
A clandestine pathway into the N-central server, bypassing all credential requirements, has once again been discovered, and this time, the vulnerability commands the absolute maximum severity rating. N-able has issued a dire warning regarding...
The pledge to return the lion’s share of the stolen bitcoin proved no mere bluff. The unknown parties who style themselves “white hats” sent 3,400 BTC, worth roughly $263 million, back to the Liquid...
Artificial intelligence in attacks has ceased to be a mere accelerant for routine and has begun assuming entire segments of an operation. On September 8, the Google Threat Intelligence Group described the shift from...
The September Patch Tuesday became the largest security update release in Microsoft’s history. The company closed 966 vulnerabilities, two of which attackers had already wielded in real-world attacks. Previous records proved short-lived: in July,...