Information Security News Blog
-
The password is no longer the main barrier: EvilTokens made users themselves confirm access for attackers on a genuine Microsoft page, then handed its clients working tokens. Over several months, the platform helped compromise...
-
Researchers have uncovered a vast network of AI gateways that conceals the real users behind requests sent to Claude, OpenAI, Gemini, xAI, and other models. Team Cymru first counted 10,867 such servers, then, after...
-
While Windows Defender may appear fully operational to the casual observer, it can be covertly frozen on outdated threat signatures. The cybersecurity researcher Abdelhamid Naceri, operating under the pseudonym Nightmare Eclipse, recently released BigDiskBuster....
The iPhone has acquired a formidable defense against attacks that circumvent traditional device compromise: iOS 27 now intelligently detects subtle indicators that a legitimate owner is being actively coerced into transferring funds, altering passwords,...
A solitary IP address, meticulously monitored by GreyNoise since early June, ultimately served as the primary entry point for a massive, multi-pronged cyberespionage campaign. This sophisticated operation simultaneously targeted diverse system classes, including WordPress...
A sophisticated cyberattack, which historically demanded an entire syndicate of skilled operators, now merely requires a handful of concise commands and a few hours of execution by autonomous AI tools. Gambit Security recently documented...
Penetration testing is ceasing to be a rare checkup and turning into a tool of constant digital monitoring. Palo Alto Networks has unveiled Unit 42 Continuous Frontier AI Defense, a service that uses Claude...
Public Wi-Fi remains one of the easiest places to get burned. Session hijacking, ARP spoofing on flat networks, DNS interception at the router level: none of these need a sophisticated attacker, just an unencrypted...
A DJI drone may keep hovering in the air while a nearby attacker, without any password, alters its connectivity settings, reboots the aircraft, or attempts to sever the pilot from control. The problem has...
A catastrophic vulnerability that lurked silently within the Linux kernel for nearly 14 years is now actively weaponized in real-world cyberattacks, alongside two other critical errors. The United States Cybersecurity and Infrastructure Security Agency...
Attacking a vulnerable DIR-822A router requires neither an administrative password nor any interaction from the device owner. A malicious actor simply needs to reside on the same local network and transmit a maliciously crafted...
A voice assistant on Mac could become someone else’s microphone and remote control at once: a zero-day found in the AI agent Muse lets an ordinary local process intercept the user’s dictation and make...
On September 22, OpenAI began rolling out GPT-6 Sol and GPT-6 Luna for Codex and ChatGPT Work. Sol is built for complex code and tasks in which the AI works through tools step by...
A critical hole in an SD-WAN management hub has already crossed from advisory to real-world attack: Arista has confirmed exploitation of a VeloCloud Orchestrator vulnerability that, under a certain configuration, lets a remote attacker...
The Irish Data Protection Commission recently announced a staggering fine of 403 million euros, approximately 463 million dollars, against Google for its improper handling of user location data. Prior to this landmark ruling, numerous...