Information Security News Blog

Funky Mantis ransomware affiliate panel coordinating DevMan locker deployments against healthcare and critical infrastructure targets 0

Funky Mantis Ransomware Runs a Full RaaS Platform

The Funky Mantis extortion group has transformed an ordinary file-encryption toolkit into a fully fledged commercial service. Members now manage affiliates, sell access to compromised networks, and oversee negotiations with victims. Researchers have found...

South Korea diplomatic academy breach exposing foreign ministry staff credentials through the KNDA e-learning platform vulnerability 0

South Korea Diplomatic Academy Breach Hits Diplomats

South Korea’s Ministry of Foreign Affairs has disclosed a leak of personal data belonging to staff at headquarters, overseas missions, and other users of the National Diplomatic Academy’s training system. Unknown attackers exploited a...

CVE-2026-0257 Qilin ransomware attack chain from PAN-OS GlobalProtect authentication bypass to domain-wide Windows encryption 0

CVE-2026-0257 Qilin Ransomware Hits GlobalProtect

A single vulnerable VPN gateway can lay open an entire corporate network. Affiliates of the Qilin extortion group are already turning a fresh PAN-OS GlobalProtect flaw to precisely that purpose. Arctic Wolf specialists have...

AI connector risk as Claude and ChatGPT connectors silently gain new tools and write permissions 0

AI Connector Risk: They Change Every Nine Minutes

Connecting an AI agent to your working services transforms a familiar integration into something restless. The access chain to your data never stops shifting. ChatGPT and Claude connectors can quietly acquire new capabilities. They...

HollowGraph Microsoft 365 malware exploiting calendar events for C2 communications 0

HollowGraph Malware Exploits Microsoft 365 Calendars

Unveiling the HollowGraph Threat A cloud calendar can conceal far more than mundane appointments; the HollowGraph malware exploits Microsoft 365 to clandestinely receive commands and transmit pilfered files. Cybersecurity experts at Group-IB have detected...

ServiceNow RCE vulnerability exploitation diagram, CVE-2026-6875 sandbox bypass attack, ServiceNow critical security flaw 0

ServiceNow RCE Vulnerability Exploited in the Wild

Critical Pre-Authentication Breach Hackers have begun breaching corporate systems via a critical ServiceNow RCE vulnerability. This severe flaw allows them to infiltrate servers without an account and execute arbitrary code. Cybersecurity specialists at Defused...