Information Security News Blog
-
Targeting the Crown Jewels of the Digital Age Malicious extortionists increasingly target not merely conventional documents and databases, but rather the most invaluable digital assets within corporate infrastructures. The JADEPUFFER syndicate has engineered sophisticated...
-
Emergence of AgentBaiting Threat Vector The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Context Protocol (MCP) server repositories to distribute malicious loads. Notably,...
-
Stealthy Infiltration Tactics A sophisticated new malware conceals itself within standard software development processes. Furthermore, it perfectly mimics legitimate automation tools. Security systems frequently overlook this hidden threat entirely. Meanwhile, the malicious program actively...
The Emergence of a New Attack Vector Mobile artificial intelligence assistants, designed to operate smartphones autonomously, represent a novel tool for cyberattacks. Specialists have demonstrated that an attacker merely needs to install a standard...
Millions of vehicles across the United States carry a concealed device meant to guard them against theft. Instead, that device has allowed strangers to open doors, silence alarms, and immobilise engines. Many owners have...
The Funky Mantis extortion group has transformed an ordinary file-encryption toolkit into a fully fledged commercial service. Members now manage affiliates, sell access to compromised networks, and oversee negotiations with victims. Researchers have found...
South Korea’s Ministry of Foreign Affairs has disclosed a leak of personal data belonging to staff at headquarters, overseas missions, and other users of the National Diplomatic Academy’s training system. Unknown attackers exploited a...
A single vulnerable VPN gateway can lay open an entire corporate network. Affiliates of the Qilin extortion group are already turning a fresh PAN-OS GlobalProtect flaw to precisely that purpose. Arctic Wolf specialists have...
Connecting an AI agent to your working services transforms a familiar integration into something restless. The access chain to your data never stops shifting. ChatGPT and Claude connectors can quietly acquire new capabilities. They...
Unveiling the HollowGraph Threat A cloud calendar can conceal far more than mundane appointments; the HollowGraph malware exploits Microsoft 365 to clandestinely receive commands and transmit pilfered files. Cybersecurity experts at Group-IB have detected...
Critical Pre-Authentication Breach Hackers have begun breaching corporate systems via a critical ServiceNow RCE vulnerability. This severe flaw allows them to infiltrate servers without an account and execute arbitrary code. Cybersecurity specialists at Defused...
Advanced Obfuscation Protocols The more arduous a malicious payload is to discern within disk boundaries and memory allocations, the longer it enjoys uninterrupted latency. The illicit Cruciferra crypter service elegantly harmonizes disparate obfuscation methodologies...
Cybercriminals have found a way to weaponise Windows’ faith in digital signatures. They compromised the workstation of a DigiCert employee and intercepted certificates bound for the company’s customers. A Chinese cybercrime group stood behind...
US authorities have seized more than a thousand domains that illegally broadcast matches from the 2026 FIFA World Cup. Many such sites did more than infringe copyright. They could also seed visitors’ devices with...
The smartphone hacking market typically operates in absolute secrecy. However, a recent lawsuit has exposed the inner workings of a major firm. The Canadian firm Magnet Forensics recently sued a former contractor and a...