Information Security News Blog
-
Public exploits often transform an already patched vulnerability into a tangible threat for those who delay updates, and this exact peril now looms over administrators of vBulletin forums. On July 27, security researchers at...
-
An ordinary email attachment can serve as the perilous gateway to a sophisticated attack chain when a meticulously crafted toolkit lurks behind a seemingly benign document. Recently, analysts at 360 Advanced Threat Research uncovered...
-
Image search is one of the most mundane features of any major internet service, which is precisely why it is rarely scrutinized for security as rigorously as login forms or payment systems. This oversight...
A certificate issued to the wrong machine can transform a standard account into a domain takeover weapon. Recently, security researchers H0j3n and Aniq Fakhrul demonstrated this alarming scenario through the Certighost vulnerability. Consequently, an...
TL;DR Broadcom has patched five flaws across VMware ESX, vCenter, Workstation, and Fusion. Two of them form a critical VMware vCenter vulnerability pair, each rated 9.8 CVSS. One lets an attacker bypass authentication; the...
For years, Fastjson version 1.2.83 stood as the definitive bastion of security for the library’s legacy branch, yet a newly unearthed vulnerability has shattered this illusion. The critical flaw, designated CVE-2026-16723 (CVSS 9.0), empowers...
Corporate systems designed to securely warehouse engineering blueprints and proprietary project documentation have morphed into a lucrative extortion vector for cybercriminals. Malicious actors are actively breaching PTC Windchill and FlexPLM servers, exfiltrating invaluable intellectual...
GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. Dependabot now enforces a mandatory three-day holding period by default,...
The acoustic reverberations of keyboard strokes can betray far more information than previously imagined. Recently, a novel side-channel attack demonstrated that a brief audio recording suffices to reconstruct typed text without requiring direct compromise...
Even a prayer app proved unable to keep others’ secrets. Click To Pray, the official app of the Pope’s Worldwide Prayer Network, exposed the names, email addresses, and other data of hundreds of thousands...
Google is introducing a unified naming system for the hacker groups its specialists track. Instead of labels like APT1 and a jumble of unrelated identifiers, attackers will now receive memorable two-word aliases. The transition...
A link intended for a colleague can unexpectedly transform into a public showcase for the entire internet. Consequently, hundreds of private user dialogues from Claude AI recently materialized within Google search results. Search Engines...
Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the...
Android’s crowning convenience for power users may soon vanish as Google endeavors to fortify system security. Company engineers have proposed prohibiting devices from connecting to their internal debugging service via local loopback addresses a...
Unmasking the Concealed Remote Code Execution Flaw A critical remote code execution (RCE) flaw in self-hosted GitLab installations lay concealed for nearly six weeks. Although GitLab patched the underlying vulnerability on June 10, the...