Information Security News Blog
-
Even a prayer app proved unable to keep others’ secrets. Click To Pray, the official app of the Pope’s Worldwide Prayer Network, exposed the names, email addresses, and other data of hundreds of thousands...
-
Google is introducing a unified naming system for the hacker groups its specialists track. Instead of labels like APT1 and a jumble of unrelated identifiers, attackers will now receive memorable two-word aliases. The transition...
-
A link intended for a colleague can unexpectedly transform into a public showcase for the entire internet. Consequently, hundreds of private user dialogues from Claude AI recently materialized within Google search results. Search Engines...
Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the...
Android’s crowning convenience for power users may soon vanish as Google endeavors to fortify system security. Company engineers have proposed prohibiting devices from connecting to their internal debugging service via local loopback addresses a...
Unmasking the Concealed Remote Code Execution Flaw A critical remote code execution (RCE) flaw in self-hosted GitLab installations lay concealed for nearly six weeks. Although GitLab patched the underlying vulnerability on June 10, the...
Covert Sabotage of Critical Infrastructure Iranian threat actors have developed sophisticated techniques to covertly manipulate programmable logic controllers (PLCs), ensuring that human operators remain completely oblivious to hazardous system alterations. Within the United States,...
Microsoft has successfully patched a severe vulnerability within the Windows Event Logging Service, a flaw that permitted malicious actors to execute arbitrary code remotely across a network. This critical defect afflicts a vast array...
Memory Corruption Vectors in Redis Streams and RedisBloom Even an applied security patch does not invariably seal a legacy vulnerability. A newly published suite of proof-of-concept demonstrations has exposed remote code execution capabilities within...
Bypassing the Code: A Compromise of Trust An unidentified threat actor effectively liquidated the entirety of the cryptocurrency protocol AFX Trade without exploiting a single vulnerability within its underlying smart contract code. Instead, the...
The Inversion of State-Sponsored Cyber Heists For years, state-sponsored North Korean cyber operatives conducted audacious digital heists across international borders to siphon foreign currency and sustain the regime’s nuclear weapons program. However, this established...
The Strategic Value of Silent Persistence Iranian threat actors operate with significantly greater stealth than conventionally perceived. Rather than executing immediate, high-profile disruptive attacks, these adversaries meticulously maintain long-term, covert access within compromised networks....
Zero-Click Administrative Takeover Malicious actors have discovered a method to infiltrate Check Point security management infrastructure completely bypassing password authentication, instantaneously acquiring paramount administrative privileges. The corporation has officially confirmed active exploitation of this...
Evolution of the Golden Chickens Ecosystem Cybercriminals operating within the TAG-195 ecosystem have fundamentally restructured their malware architecture, adopting a highly modular approach. Consequently, compromised systems now only receive the specific functionalities required for...
An Unprotected Directory Exposes Espionage Operations A single overlooked server misconfiguration inadvertently exposed the inner workings of an entire China-nexus cyber espionage infrastructure. Cybersecurity specialists at Group-IB gained access to an exposed directory, uncovering...