Information Security News Blog

Telegram Desktop HTML export XSS vulnerability demonstration interface 0

Telegram Desktop HTML Export Conceals XSS Vulnerability

A routine export of Telegram correspondence could inadvertently transform a saved chat history into a covert instrument for message theft. Security researchers uncovered a pernicious vulnerability residing within Telegram Desktop. This critical flaw permitted...

Android smartphone screen displaying root access alongside manufacturer logos 0

Zero-Permission Android Apps Exploit Manufacturer Code

An entirely ordinary Android application, devoid of any requested permissions, can now seize absolute control over contemporary flagship smartphones. Calif researcher Lucas Maar brilliantly demonstrated a devastating attack vector targeting devices from Samsung, Xiaomi,...

Red Heron exploiting Gitea N-day flaw to deploy Linux rootkit 0

Red Heron Weaponizes Gitea Flaw for Source Code Theft

In a matter of mere days, a publicly disclosed exploit targeting Gitea rapidly metamorphosed into an industrialized instrument for source code theft. The Red Heron threat group ruthlessly automated the discovery of vulnerable servers,...

GitLab interface with a warning overlay indicating active vulnerability exploitation 0

Critical GitLab Flaw Transitions to Active Global Threat

A critical GitLab vulnerability, bearing the maximum possible CVSS score of 10, has officially transitioned from a theoretical urgent update into a verified, real-world threat. The Cybersecurity and Infrastructure Security Agency (CISA) definitively confirmed...

Sogou Input Method backdoor attack flow and GRAYRABBIT deployment 0

Sogou Input Method Exploited in Espionage Campaign

A seemingly innocuous link transformed a popular Chinese character input application into a vulnerable gateway for espionage. The security firm Gen exposed a sophisticated exploit chain utilized by the UNC3569 threat group to infect...

AI-powered de-anonymization of voting records and ballot scanning vulnerability 0

AI Weaponized to Shatter Georgia’s Secret Ballot

The sanctity of the secret ballot in Georgia fractured profoundly, absent any physical machine tampering, network infiltration, or illicit access to proprietary source code. Max Springer, an intrepid specialist from Princeton University, merely invested...

Revolut data breach fake government email request exposing passports selfies and Bitcoin history 0

Revolut Leaks Passports to a Fake Government Request

Revolut handed strangers copies of passports, verification selfies, and the financial histories of some clients, mistaking fraudulent requests for the official approaches of a government agency. On September 12, 2026, the British fintech confirmed...