Information Security News Blog

Cloudflare Containers infrastructure diagram showing cross-tenant data vulnerability and thin provisioning 0

Cloudflare Resolves Cross-Tenant Data Exposure Flaw

A terminated container is theoretically engineered to vanish entirely, alongside all its ephemeral data. However, within Cloudflare’s sprawling infrastructure, fragments of this sensitive information inexplicably survived the previous owner of the physical disk block....

Fake Cloudflare CAPTCHA ClickFix interface leading to Psychedelic Stealer installation 0

Psychedelic Stealer Weaponizes Compromised Websites

A perilous trap may now await visitors upon seemingly familiar digital terrain: malicious actors have systematically compromised several legitimate Ukrainian websites, covertly embedding a fraudulent Cloudflare verification gateway. This deceptive interface cunningly orchestrates the...

CERT Polska AI analysis laboratory analyzing MikroTik RouterOS binary files 0

CERT Polska Dissects the MikroTrick RouterOS Exploit

Following MikroTik’s abrupt release of an emergency security update, the elite CERT Polska team required approximately one hour of forensic analysis to pinpoint the underlying critical vulnerability. By meticulously scrutinizing the architectural modifications within...

File notification API architecture vulnerability flowchart across Android Linux macOS Windows 0

File Notification APIs Expose User Actions

An operating system might steadfastly refuse to surrender a foreign file’s contents, yet it frequently still broadcasts precisely when operations occur upon it. A dedicated research team from Graz University of Technology has demonstrated...

F5 BIG-IP Access Policy Manager vulnerability and CISA KEV catalog warning 0

Active Zero-Day Attacks Target F5 BIG-IP Gateways

Penetrating an enterprise F5 corporate gateway may no longer require a compromised password or even a valid user account. The manufacturer recently disclosed a catastrophic vulnerability embedded within the BIG-IP Access Policy Manager (APM),...

Terraform Registry architecture diagram illustrating supply chain compromise 0

Infrastructure as Code Weaponized Against Developers

Infrastructure code has horrifyingly metamorphosed into a convenient snare for developer workstations. Cybersecurity firm Aikido recently unearthed malicious code deeply embedded within dual Terraform providers and twin Go modules. The company classifies this terrifying...

Roundcube Webmail login interface depicting an active SQL injection vulnerability 0

Active Exploitation Targets Roundcube Webmail Servers

A critical vulnerability can easily outlive its official patch if system administrators fail to update their servers expeditiously. Precisely this perilous scenario is currently unfolding surrounding the widely deployed Roundcube Webmail platform. Malicious actors...

Bitget cryptocurrency exchange logo and abstract blockchain transaction visualization 0

Bitget Confirms $351.6 Million Cryptocurrency Heist

The prominent cryptocurrency exchange Bitget has officially confirmed a catastrophic security breach, resulting in the theft of approximately $351.6 million following unauthorized transfers originating from a segment of its hot wallet infrastructure. The attack...