Information Security News Blog

OpenSSL DTLS memory leak vulnerability code illustration 0

OpenSSL DTLS Memory Leak: Unpacking CVE-2026-84782

A malfunction within the DTLS retransmission mechanism transformed the routine recovery of a lost message into a critical memory leak. The architects of OpenSSL have formally disclosed vulnerability CVE-2026-84782, assigning it a severe CVSS...

Conceptual visualization of the DarkSword iOS exploit targeting a compromised Ukrainian news website 0

Ukraine CERT-UA Warns of Escalating Mobile Cyberattacks

Ukrainian cybersecurity specialists have issued a stark warning regarding a severe, escalating wave of cyberattacks specifically targeting the smartphones of military personnel and government officials. According to the comprehensive CERT-UA report for the first...

KillSec ransomware group leak site replaced by a law enforcement seizure notice during Operation KillSwitch led by Europol 0

KillSec Ransomware Group Taken Down in Europol Raid

A Ransomware Gang With a Teenage Boss Even the extortion business turns out to have surprisingly young leadership. The international Operation KillSwitch has crippled the infrastructure of KillSec. Investigators believe the group’s main operator...

Screenshot of a malicious PHP web shell disguised as a standard Citrix NetScaler CSS file 0

Hackers Camouflage PHP Web Shells as Citrix CSS Files

A seemingly innocuous cascading style sheet (CSS) address upon a standard Citrix login page has metamorphosed into an elaborate camouflage for covert, persistent remote access. The elite LevelBlue cybersecurity team unearthed a sophisticated post-exploitation...

Custom ChatGPT bot interface mimicking a service error to trigger the ClickFix RAT infection chain 0

ClickFix RAT Disguised as Custom ChatGPT Bot Strikes

The most compelling element of this novel cyberattack resides not upon a disparate phishing domain, but directly within the authentic ChatGPT interface. Huntress unveiled a sophisticated campaign wherein adversaries engineered custom GPTs, masquerading them...

Google Threat Intelligence Group statistical dashboard showcasing AI-driven vulnerability discovery trends 0

AI Discovery Shifts Focus to Critical Vulnerabilities

Artificial intelligence has begun to exert a profound influence, accelerating the velocity of vulnerability discovery and fundamentally altering the nature of the identified flaws. Researchers at Google have unearthed a critical distinction: fully half...

Conceptual code snippet demonstrating the JSON Web Signature authentication bypass in Python Authlib 0

Authlib Flaw Allows JSON Web Signature Authentication Bypass

Authlib fundamentally exists to distinguish authenticated, trusted data from malicious forgery. However, a meticulously crafted JSON Web Signature (JWS) enables attackers to bypass this critical verification process entirely without necessitating any cryptographic signature. The...