Information Security News Blog
-
To achieve the complete subjugation of a Cisco mail gateway, an attacker now requires only a single, meticulously crafted email. The critical vulnerability designated as CVE-2026-76461 is actively weaponized in real-world attacks. Terrifyingly, it...
-
A critical GitLab vulnerability, bearing the maximum possible CVSS score of 10, has officially transitioned from a theoretical urgent update into a verified, real-world threat. The Cybersecurity and Infrastructure Security Agency (CISA) definitively confirmed...
-
On September 11, manufacturers of digital products sold in the European Union became obligated to report actively exploited vulnerabilities and severe security incidents to the authorities. They must send an initial warning within 24...
This time, the theoretical threat of agentic hacking unequivocally escaped the confines of the laboratory. GreyNoise meticulously detailed a terrifying, real-world campaign launched against PaperCut NG/MF, where a solitary human operator commanded hundreds of...
A seemingly innocuous link transformed a popular Chinese character input application into a vulnerable gateway for espionage. The security firm Gen exposed a sophisticated exploit chain utilized by the UNC3569 threat group to infect...
In the near future, a cyberattack paralyzing a commercial airline within the United States will be legally classified as an uncontrollable circumstance provided the carrier diligently adhered to mandatory cybersecurity protocols. Effective October 19,...
The sanctity of the secret ballot in Georgia fractured profoundly, absent any physical machine tampering, network infiltration, or illicit access to proprietary source code. Max Springer, an intrepid specialist from Princeton University, merely invested...
Revolut handed strangers copies of passports, verification selfies, and the financial histories of some clients, mistaking fraudulent requests for the official approaches of a government agency. On September 12, 2026, the British fintech confirmed...
Researchers have discovered a key embedded in the code of the Shinobi video surveillance system, through which an outsider could gain access to the user database and camera settings without a login or password....
A small model reads a text and answers “safe.” Then the very same text reaches a more powerful AI, which finds a hidden command within and executes it. Check Point Research has laid bare...
An ordinary QR code, ostensibly designed for seamlessly transferring screenshots, has alarmingly materialized as a clandestine gateway directly into the memory architecture of the console. On September 10, Nintendo officially cautioned owners across the...
Android ransomware is no longer confined to locking files: Mantax Otax transforms an infected smartphone into a spying instrument and a channel of pressure on its owner at once. Zimperium has described the malware,...
A collection of local Linux vulnerabilities has acquired a second life as weaponized code engineered for total root compromise. NebuSec disclosed a series of critical kernel vulnerabilities and published fully functional exploits, meticulously verified...
Plex is once again urging owners of home media servers to act before any technical explanation appears. On September 1, the company demanded that users update Plex Media Server to version 1.43.3 or newer,...
An Android feature devised to separate personal and corporate applications has become a hiding place for banking fraud. Group-IB has described the pairing of Gigabud and Vwork, which, in a confirmed chain, creates a...