Information Security News Blog
-
The malicious software known as Hydra Remote empowers an attacker to generate a covert desktop environment on an infected computer. Crucially, this secondary workspace remains entirely invisible to the legitimate device owner. The attacker...
-
The North Korean threat group Kimsuky has learned to leave behind multiple pathways back into a compromised computer, with several of them disguised as entirely ordinary software. Researchers at ENKI WhiteHat uncovered a series...
-
Intel processors feature a critical security mechanism designed specifically to prevent the Windows kernel from accessing standard application memory. However, during certain system calls, this vital protection mysteriously deactivates itself. A security specialist recently...
Cybercriminals no longer need to scour underground networks for illicit neural networks. They no longer must lease expensive servers or meticulously train custom models. Astonishingly, a standard monthly subscription, priced similarly to a streaming...
A common web server misconfiguration has left tens of thousands of Git repositories publicly accessible, exposing keys to cloud services, payment systems, and other critical resources along with them. Researchers at Intruder scanned 3.5...
For months, the group calling itself BLACKNET-00 marketed itself almost as a turnkey cyberweapon supplier, capable of attacking factories, power plants, and water supply systems. After examining actual samples of its tools, researchers discovered...
North Korean hackers are increasingly handing off stolen cryptocurrency to professional intermediaries, who blend it with other criminal proceeds and convert it into conventional currency. Between January 2024 and September 2025, North Korea stole...
An enterprising researcher successfully compelled Apple Find My to operate within an environment completely unsupported by the corporation. A 22-year-old security specialist, operating under the pseudonym Zerotistic, cleverly registered a Linux machine within Apple’s...
Malicious actors have begun utilizing artificial intelligence to rapidly engineer tools capable of compromising Siemens Programmable Logic Controllers (PLCs). United States federal agencies recently issued a severe warning regarding this active threat. The malicious...
Security experts unearthed dozens of counterfeit Firefox extensions. These malicious add-ons masqueraded as cryptocurrency wallets and standard utilities. Some programs appeared innocuous for months. Following an update, they transformed into sinister tools. They actively...
A sophisticated Chinese-speaking hacker collective, designated UAT-10147, has weaponized artificial intelligence, transforming it from a rudimentary coding assistant into a formidable attack instrument. These malicious actors deploy AI agents to hunt for vulnerabilities, forge...
The notorious banking trojan ToxicPanda has resurfaced in a significantly more formidable iteration. ToxicPanda 2.0 now possesses the capability to pilfer PINs from banking and cryptocurrency applications. It intercepts smartphone lock passwords with alarming...
mssqlbof A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself, in C. No msodbcsql.dll, no sqloledb.dll, no .NET CLR, no PowerShell. One COFF per arch, loads into every...
Attackers can force Microsoft Defender to delete its own security components using a native Windows driver. This technique affects systems from Windows 7 through Windows 11 25H2. It requires neither a software vulnerability exploit...
T-Mobile specialists were forced to literally cut a network cable to prevent hackers from penetrating the carrier’s infrastructure. The incident took place in 2024, during a large-scale espionage campaign that U.S. authorities have linked...