Information Security News Blog

F5 BIG-IP Access Policy Manager vulnerability and CISA KEV catalog warning 0

Active Zero-Day Attacks Target F5 BIG-IP Gateways

Penetrating an enterprise F5 corporate gateway may no longer require a compromised password or even a valid user account. The manufacturer recently disclosed a catastrophic vulnerability embedded within the BIG-IP Access Policy Manager (APM),...

Terraform Registry architecture diagram illustrating supply chain compromise 0

Infrastructure as Code Weaponized Against Developers

Infrastructure code has horrifyingly metamorphosed into a convenient snare for developer workstations. Cybersecurity firm Aikido recently unearthed malicious code deeply embedded within dual Terraform providers and twin Go modules. The company classifies this terrifying...

Roundcube Webmail login interface depicting an active SQL injection vulnerability 0

Active Exploitation Targets Roundcube Webmail Servers

A critical vulnerability can easily outlive its official patch if system administrators fail to update their servers expeditiously. Precisely this perilous scenario is currently unfolding surrounding the widely deployed Roundcube Webmail platform. Malicious actors...

Bitget cryptocurrency exchange logo and abstract blockchain transaction visualization 0

Bitget Confirms $351.6 Million Cryptocurrency Heist

The prominent cryptocurrency exchange Bitget has officially confirmed a catastrophic security breach, resulting in the theft of approximately $351.6 million following unauthorized transfers originating from a segment of its hot wallet infrastructure. The attack...

Windows Defender update failure error interface 0

BigDiskBuster Freezes Windows Defender Updates

While Windows Defender may appear fully operational to the casual observer, it can be covertly frozen on outdated threat signatures. The cybersecurity researcher Abdelhamid Naceri, operating under the pseudonym Nightmare Eclipse, recently released BigDiskBuster....

iOS 27 Trust Insights architecture, Impersonation Risk Detection social engineering prevention, Apple anti-fraud framework 0

iOS 27 Introduces Impersonation Risk Detection

The iPhone has acquired a formidable defense against attacks that circumvent traditional device compromise: iOS 27 now intelligently detects subtle indicators that a legitimate owner is being actively coerced into transferring funds, altering passwords,...

Kapibala attacker infrastructure map targeting WordPress and Zyxel devices 0

Kapibala Attacker Plunders Government Databases

A solitary IP address, meticulously monitored by GreyNoise since early June, ultimately served as the primary entry point for a massive, multi-pronged cyberespionage campaign. This sophisticated operation simultaneously targeted diverse system classes, including WordPress...

Autonomous AI agents executing a cyberattack on an e-commerce platform 0

Autonomous AI Agents Orchestrate Massive Data Breach

A sophisticated cyberattack, which historically demanded an entire syndicate of skilled operators, now merely requires a handful of concise commands and a few hours of execution by autonomous AI tools. Gambit Security recently documented...