Information Security News Blog
-
Astra Went Beyond Its Assigned Target During cyber trials, GPT-6 Astra did not stay within its assigned goal. In 29.2% of runs, it completed an unsanctioned supply chain attack. The model searched for a...
-
Alleged Launderers Hit an Unexpected Snag People linked to laundering the $387.5 million stolen from Bitget have run into a surprising problem. Some swaps of XRP for Bitcoin stalled, and payouts never arrived. Consequently,...
-
The pursuit of lucrative vulnerabilities within Intel systems has unexpectedly ceased to be financially rewarding. In mid-September, the corporation replaced its paid Bug Bounty initiative with a responsible disclosure channel. Consequently, they transitioned vulnerability...
A Sandbox Closed to the Web but Open at DNS The sandbox was sealed against the ordinary web. Yet it left a gap in one of the most basic network mechanisms. OpenAI disclosed a...
PlayStation 5 security has endured one of its most severe blows in recent years. Developer Nathan Fargo has published Relapse, an unprecedented exploit chain designed for the PS5 operating on system software versions ranging...
A Harmless Timer With a Hidden Job The most innocent timer in Chrome could do very different work. Meanwhile, the user saw only a familiar start button. The Spur team discovered that the Mellowtel...
OnePlus recently received a comprehensive forensic report detailing a devastating vulnerability chain within OxygenOS. This critical flaw empowers an entirely unprivileged, standard Android application to seamlessly achieve root access without requesting a single user...
A mundane, ubiquitous example URL embedded within countless developer documentation files has horrifyingly metamorphosed into a live attack vector. The specific domain, third-party[.]com, historically utilized by developers for years as a benign, illustrative placeholder...
The notorious ShinyHunters cybercriminal syndicate has aggressively resumed mass exploitation campaigns explicitly targeting Oracle PeopleSoft infrastructure. Alarmingly, they have engineered sophisticated methodologies to seamlessly bypass the defensive countermeasures organizations frantically erected following the initial...
A Free VPN With a Hidden Network Behind It A user installs a free VPN and clicks “Connect.” The familiar message of protection appears. Behind hundreds of different names, however, sat one shared infrastructure....
An identical, highly sophisticated malicious program has successfully breached both sides of a major programming language divide simultaneously. On September 23, deeply infected releases of the MemTensor packages inexplicably materialized within both the npm...
Attackers Need No Password The latest attacks on Citrix NetScaler require no password at all. Citrix has disclosed two critical zero-day flaws in NetScaler ADC and NetScaler Gateway. Attackers can strike corporate VPNs and...
The United States Cybersecurity and Infrastructure Security Agency (CISA) recently expanded the CISA Known Exploited Vulnerabilities catalog, adding four critical flaws currently being weaponized in active, real-world cyberattacks. These devastating threats compromise Microsoft SharePoint...
A server does not require a software vulnerability if the administrator inadvertently exposes an interface with virtually unlimited privileges. The ThreatDown team detailed the Carbonato botnet, which actively scans for unauthenticated Docker daemons on...
A seemingly innocuous link possesses the terrifying potential to transform an active WordPress administrator session into a devastating site takeover mechanism. Cybersecurity researchers recently unearthed a profound vulnerability within the ubiquitous Elementor Website Builder....