Information Security News Blog
-
A debilitating cyberattack targeting a modest supplier of critical equipment for American water utilities resulted in the catastrophic leakage of hundreds of gigabytes of highly sensitive data. Consequently, this alarming breach immediately prompted a...
-
Barely 19 hours after releasing an emergency patch for PaperCut NG and MF, the company had to prepare a replacement. Researchers uncovered several ways to circumvent the original safeguard, and they also identified yet...
-
Remote-access systems without open ports are meant to shrink the attack surface. Yet a single flaw in authorization checks can push the risk back up to the application layer. A UltraViolet Cyber researcher discovered...
Windows 11 is preparing to abandon its all-or-nothing approach to how ordinary desktop applications access the camera, microphone, and location data. Microsoft has begun testing individual, per-app permissions, allowing users to deny access to...
For the third consecutive day, a massive Distributed Denial-of-Service (DDoS) attack continues to severely disrupt Norway’s state digital services. The overwhelming overload upon the shared infrastructure directly impacted critical authorization systems, electronic signatures, and...
Even a minuscule error can demand dozens of reboots. This happens if the system freezes before reaching the login screen. Linus Torvalds recently resolved a tricky Linux 7.3 kernel bug. Artificial intelligence assisted him...
Modern defense systems confront a frustrating paradox. As artificial intelligence models become increasingly powerful, their built-in restrictions severely impede specialists attempting to analyze genuine cyberattacks. David Bianco, a distinguished researcher at Cisco Talos, astutely...
NVIDIA graphics cards employ specialized error-correcting memory capable of detecting and repairing random data corruption on its own. A new attack called GPUThor has demonstrated that even this protection can be circumvented, leading to...
A WordPress site administrator’s password could be changed by an attacker without ever logging in. A critical vulnerability in the popular Pods plugin allowed an unauthenticated outsider to bypass several layers of security checks...
Corporate video meetings are increasingly attracting attention not only from employees but from automated services as well, prompting Microsoft to roll out new protections within Teams. Administrators will now be able to fully block...
Hackers have found a way to weaponize ordinary Notion notifications to steal employee credentials. The group DOUBLOON DREDGER creates fake executive accounts, sends out document-sharing invitations, and routes victims through a chain of PDF...
The notorious ShinyHunters group, meticulously tracked and scrutinized by ReliaQuest for months, audaciously decided to reverse roles. The malevolent actors launched a targeted assault against ReliaQuest personnel, successfully compromising a single employee account. Judging...
Occasionally, technological reliability hinges less upon inherent architectural age and more upon the fundamental lack of incentive for exploitation. Cybersecurity luminary Mikko Hyppönen eloquently identifies this fascinating phenomenon as “security by obsolescence.” Antiquated software...
Malware doesn’t necessarily need to communicate with an attacker’s server to remain under their control. Researcher Dominic Reichel discovered a previously unknown Windows backdoor called Sleepwalker, which sits silently in memory and waits for...
Two distinct Microsoft SharePoint vulnerabilities have seamlessly merged to form a devastating, fully operational exploit chain. This formidable combination empowers malicious actors to execute arbitrary code remotely on a targeted server, completely bypassing the...