Information Security News Blog
-
Cybercriminals have transformed ScreenConnect into a weaponized mechanism capable of infecting other ScreenConnect systems during standard connections. The modified client automatically detects a new session, dispatches malicious scripts via the native file transfer feature,...
-
The N-central urgent patch series received another continuation just one day after the previous update. Specifically, N-able resolved CVE-2026-86218. This flaw allows remote code execution on the server before authentication. Consequently, the vulnerability earned...
-
Researchers at Calif developed the first zero-click worm for WeChat. This WeChat zero-click worm spreads through automated calls across iOS and Android platforms. Tencent has already mitigated this critical threat on their servers. Why...
Germany is poised to consolidate its defenses against hackers, rogue drones, and saboteurs into a singular, cohesive military logic. Following the alarming attack at Leipzig/Halle Airport, the national authorities are formulating a comprehensive package...
Naval forces may soon possess the capability to bolster their drone defenses as effortlessly as a vessel loads a new cargo module. Destinus, OMT Group, and CUBEDIN are collaboratively engineering a containerized module featuring...
Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary...
Berlin’s steadfast refusal to capitulate to extortionists has culminated in the exposure of one of the most substantial German government data breaches in recent history. The Rhysida ransomware syndicate unceremoniously published approximately 1.44 million...
TL;DR Researchers at the Citizen Lab and the SHARE Foundation confirmed a mercenary spyware attack in Serbia. A zero-click exploit delivered Pegasus spyware to an iPhone belonging to a pro-democracy student activist. Meanwhile, independent...
Ukrainian law enforcement agencies dismantled a sophisticated network of fraudulent cryptocurrency platforms in Kyiv. These illicit operations systematically siphoned assets from users spanning more than twenty nations. Investigators have definitively identified sixty-two victims thus...
Rockwell Automation has closed more than a dozen vulnerabilities in software and controllers used at industrial facilities. The gravest of these flaws permit the disabling of control-system components, the execution of code on a...
TL;DR On September 6, 2026, N-able released an urgent security update fixing an actively exploited zero-day flaw. The critical N-central vulnerability allows remote unauthenticated attackers to execute arbitrary code with root privileges. Consequently, administrators...
Malicious actors have commenced active attacks against Citrix NetScaler infrastructure. They are exploiting the critical vulnerability designated as CVE-2026-19490. This severe flaw enables remote adversaries to circumvent authentication protocols entirely. Consequently, they gain illicit...
Ordinary advertising networks have suddenly become a severe physical danger for military units. Therefore, the United States Armed Forces deactivated ad trackers on official devices amid Middle East targeting reports. This decisive action followed...
An unexpected request originating from corporate technical support frequently appears entirely innocuous. This perception persists until an employee unwittingly surrenders computer control directly to an unknown individual. Microsoft recently exposed a highly active campaign...
A job offer on a freelance marketplace could end in the complete loss of control over one’s computer. U.S. authorities have accused a 40-year-old man of orchestrating a multi-year campaign whose participants dispatched malicious...