Information Security News Blog
-
Malware Found in a Weather Services Network Malware has entered the operational technology (OT) network of Air Traffic and Navigation Services (ATNS), the South African operator. That network supports weather services for air traffic...
-
A Chinese Spy Group Targets Trust, Not Bugs A Chinese cyber-espionage group has chosen a new way into the circle of American AI experts. It does not use a vulnerability. It uses trust. The...
-
The very email gateway explicitly designed to filter and protect corporate correspondence inexplicably transformed into a direct avenue for total device compromise. Kiteworks recently disclosed a critical vulnerability chain residing within its Email Protection...
NEAR Intents has announced the successful identification of the individual responsible for exfiltrating approximately $3.8 million from its infrastructure. The suspected perpetrator has been granted a 48-hour window to restitute the funds, though their...
A malfunction within the DTLS retransmission mechanism transformed the routine recovery of a lost message into a critical memory leak. The architects of OpenSSL have formally disclosed vulnerability CVE-2026-84782, assigning it a severe CVSS...
Ukrainian cybersecurity specialists have issued a stark warning regarding a severe, escalating wave of cyberattacks specifically targeting the smartphones of military personnel and government officials. According to the comprehensive CERT-UA report for the first...
A Ransomware Gang With a Teenage Boss Even the extortion business turns out to have surprisingly young leadership. The international Operation KillSwitch has crippled the infrastructure of KillSec. Investigators believe the group’s main operator...
Deleting the Plugin Is Not Enough Removing the malicious plugin does not solve the problem. A leftover copy simply rebuilds the infection. The firm Sucuri analyzed the SC backdoor. It takes hold in WordPress...
Two Unknown Bugs Became Full Server Control Two unknown vulnerabilities turned the Zammad support system into an entry point with full control of the server. The Dutch Institute for Vulnerability Disclosure (DIVD) revealed the...
A seemingly innocuous cascading style sheet (CSS) address upon a standard Citrix login page has metamorphosed into an elaborate camouflage for covert, persistent remote access. The elite LevelBlue cybersecurity team unearthed a sophisticated post-exploitation...
A solitary encoded character within an HTTP request proved sufficient to circumvent the defensive perimeter of a corporate SD-WAN management center. Cisco has disclosed the remediation of a critical zero-day vulnerability afflicting the Catalyst...
The most compelling element of this novel cyberattack resides not upon a disparate phishing domain, but directly within the authentic ChatGPT interface. Huntress unveiled a sophisticated campaign wherein adversaries engineered custom GPTs, masquerading them...
Artificial intelligence has begun to exert a profound influence, accelerating the velocity of vulnerability discovery and fundamentally altering the nature of the identified flaws. Researchers at Google have unearthed a critical distinction: fully half...
Authlib fundamentally exists to distinguish authenticated, trusted data from malicious forgery. However, a meticulously crafted JSON Web Signature (JWS) enables attackers to bypass this critical verification process entirely without necessitating any cryptographic signature. The...
A solitary, glaring omission in cryptographic verification granted a 16-year-old student administrative dominion over a critical internal analytical platform at Microsoft. This infrastructure underpinned databases housing an estimated 17.3 trillion rows of data. The...