Information Security News Blog
-
An unexpected request originating from corporate technical support frequently appears entirely innocuous. This perception persists until an employee unwittingly surrenders computer control directly to an unknown individual. Microsoft recently exposed a highly active campaign...
-
A job offer on a freelance marketplace could end in the complete loss of control over one’s computer. U.S. authorities have accused a 40-year-old man of orchestrating a multi-year campaign whose participants dispatched malicious...
-
For the enterprise telephone exchange Sangoma Switchvox, accepting a single specially crafted XML request suffices for a stranger on the internet to reach the server’s command shell. This critical vulnerability is already being probed...
A seemingly ordinary project folder can transform into a dangerous trap. This trap springs before the developer even executes their first command. Manifold Security researchers recently discovered a critical vulnerability class named GitSpawn. These...
GitHub has been turned into a shop window for malware, and the victim need neither open a suspicious archive nor visit a counterfeit website. Researchers at Avyukt Security have uncovered Operation RepoGhost, in which...
The White House officially initiated a six-month pilot program named Project Watershed 250 in Texas. This vital initiative aims to discover practical methods for shielding American water and wastewater systems from sophisticated cyberattacks. Participating...
A document meant to affirm one’s identity has become merchandise for criminals. On the dark web, a marketplace named Nexus has surfaced, peddling digital copies of more than 153 million driver’s licenses belonging to...
A critical vulnerability has surfaced in Prompty, Microsoft’s open-source project for building applications on top of large language models. The flaw let a specially prepared .prompty file escape ordinary template processing and run arbitrary...
Artificial intelligence recently breached a crucial internal OpenAI boundary. Basic safeguards against malicious requests simply no longer suffice. The company officially recognized Astra as its first model possessing critical cybersecurity capabilities. During rigorous testing,...
A routine software search recently transformed into a critical entry point for severe malware infections. Microsoft recently exposed a sophisticated counterfeit installer campaign. Participants in this operation meticulously cloned the websites of renowned software...
The United States successfully seized the domains of two prominent hacking platforms. The Department of Justice and the FBI allege the Chinese state-sponsored group QTFY operated these platforms. The group utilized these domains to...
Servers for developing AI applications have become vaults of valuable secrets, accessible through a single unprotected request. Attackers have begun exploiting the critical vulnerability CVE-2026-0768 in Langflow to extract OpenAI and AWS keys, administrator...
Corporate email can fall into an attacker’s hands after the compromise of a single low-privilege account. Nearly 22,000 internet-facing Microsoft Exchange servers have not received the fix for CVE-2026-62911, a flaw that allows every...
Sometimes, threat actors utilize video files not for mere viewing, but for cunning concealment. Censys specialists recently discovered a sophisticated malware campaign. This campaign actively deploys structurally sound, yet entirely unplayable MP4 files. These...
Andrew Tate’s exclusive “War Room” sold far more than basic financial and relationship advice. A massive data leak recently exposed highly secretive internal courses. These materials instructed members on bribing government officials and police...