Information Security News Blog
-
The September Patch Tuesday became the largest security update release in Microsoft’s history. The company closed 966 vulnerabilities, two of which attackers had already wielded in real-world attacks. Previous records proved short-lived: in July,...
-
Photoshop has received an uncommonly weighty patch in which nearly every remediated flaw leads to the execution of foreign code. Adobe has released update APSB26-130 for Photoshop 2025 and 2026 on both Windows and...
-
ClickFix has abandoned its habit of knocking at PowerShell and has taken up residence directly inside the browser. Cisco Talos has disclosed a campaign in which the victim is invited to paste JavaScript into...
A user may enter the correct password, complete MFA verification, and still lose their Microsoft 365 account. The phishing platform BigBear 2.0 intercepts the authenticated session after the second factor and delivers the attacker...
Suspected North Korean hackers may have spied on South Korean organizations for years using trojanized Linux system services and an HAProxy backdoor. Rapid7 researchers discovered a previously unknown set of malicious tools. These tools...
Cybercriminals have transformed ScreenConnect into a weaponized mechanism capable of infecting other ScreenConnect systems during standard connections. The modified client automatically detects a new session, dispatches malicious scripts via the native file transfer feature,...
The N-central urgent patch series received another continuation just one day after the previous update. Specifically, N-able resolved CVE-2026-86218. This flaw allows remote code execution on the server before authentication. Consequently, the vulnerability earned...
Researchers at Calif developed the first zero-click worm for WeChat. This WeChat zero-click worm spreads through automated calls across iOS and Android platforms. Tencent has already mitigated this critical threat on their servers. Why...
Germany is poised to consolidate its defenses against hackers, rogue drones, and saboteurs into a singular, cohesive military logic. Following the alarming attack at Leipzig/Halle Airport, the national authorities are formulating a comprehensive package...
Naval forces may soon possess the capability to bolster their drone defenses as effortlessly as a vessel loads a new cargo module. Destinus, OMT Group, and CUBEDIN are collaboratively engineering a containerized module featuring...
Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary...
Berlin’s steadfast refusal to capitulate to extortionists has culminated in the exposure of one of the most substantial German government data breaches in recent history. The Rhysida ransomware syndicate unceremoniously published approximately 1.44 million...
TL;DR Researchers at the Citizen Lab and the SHARE Foundation confirmed a mercenary spyware attack in Serbia. A zero-click exploit delivered Pegasus spyware to an iPhone belonging to a pro-democracy student activist. Meanwhile, independent...
Ukrainian law enforcement agencies dismantled a sophisticated network of fraudulent cryptocurrency platforms in Kyiv. These illicit operations systematically siphoned assets from users spanning more than twenty nations. Investigators have definitively identified sixty-two victims thus...
Rockwell Automation has closed more than a dozen vulnerabilities in software and controllers used at industrial facilities. The gravest of these flaws permit the disabling of control-system components, the execution of code on a...