Information Security News Blog
-
An enormous fragment of early Steam history suddenly became accessible for public scrutiny over a decade later. A colossal archive, spanning roughly 12 to 13 terabytes, is currently circulating rapidly across the internet. This...
-
The US Department of Justice has had to amend a resounding statement about the Chinese hacking group QTFY. After the first release, the impression formed that the attackers had successfully penetrated the networks of...
-
Malicious tools strive to blend into ordinary network traffic, but the new Miraak framework has gone further and transformed a cloud PostgreSQL database into a full-fledged channel for controlling infected computers. Blackpoint Cyber specialists...
A cyberattack on one of Australia’s largest book distributors has been disrupting deliveries across the country for roughly six weeks. After intruders breached the systems of Alliance Distribution Services, bookshops are receiving less stock,...
Open registration on developer platforms generally streamlines onboarding processes. However, concerning Gitea, this convenience inadvertently transformed a critical vulnerability into an easily accessible intrusion point. The Shadowserver Foundation recently identified a staggering 8,393 internet-facing...
ServiceNow recently addressed three maximum-severity vulnerabilities residing within its AI Platform. Astonishingly, each individual flaw received a perfect 10.0 rating on the CVSS 4.0 scale. Furthermore, a potential attacker requires absolutely no authentication or...
Malicious code no longer necessarily requires complex obfuscation to successfully evade neural network detection. Sometimes, merely inserting a specific phrase within a comment suffices. The artificial intelligence will subsequently refuse to continue its analysis...
Companies have only a few months left to fortify their defenses before AI markedly accelerates real-world cyberattacks. OpenAI issued that warning in an open letter endorsed by 128 organizations, among them Google, Microsoft, Anthropic,...
Incidents where autonomous AI agents execute commands too literally are increasingly transcending mere amusing anecdotes. These errors are culminating in genuine, catastrophic data loss. Recently, developer Sebastien Guillemot experienced a severe setback. The Claude...
The Iranian group Tortoiseshell continues to broaden both its toolset and the geography of its operations. Group-IB specialists have uncovered previously unknown malware samples and additional server infrastructure tied to the group. Among the...
A debilitating cyberattack targeting a modest supplier of critical equipment for American water utilities resulted in the catastrophic leakage of hundreds of gigabytes of highly sensitive data. Consequently, this alarming breach immediately prompted a...
Barely 19 hours after releasing an emergency patch for PaperCut NG and MF, the company had to prepare a replacement. Researchers uncovered several ways to circumvent the original safeguard, and they also identified yet...
Remote-access systems without open ports are meant to shrink the attack surface. Yet a single flaw in authorization checks can push the risk back up to the application layer. A UltraViolet Cyber researcher discovered...
Windows 11 is preparing to abandon its all-or-nothing approach to how ordinary desktop applications access the camera, microphone, and location data. Microsoft has begun testing individual, per-app permissions, allowing users to deny access to...
For the third consecutive day, a massive Distributed Denial-of-Service (DDoS) attack continues to severely disrupt Norway’s state digital services. The overwhelming overload upon the shared infrastructure directly impacted critical authorization systems, electronic signatures, and...