Information Security News Blog
-
A DJI drone may keep hovering in the air while a nearby attacker, without any password, alters its connectivity settings, reboots the aircraft, or attempts to sever the pilot from control. The problem has...
-
A catastrophic vulnerability that lurked silently within the Linux kernel for nearly 14 years is now actively weaponized in real-world cyberattacks, alongside two other critical errors. The United States Cybersecurity and Infrastructure Security Agency...
-
Attacking a vulnerable DIR-822A router requires neither an administrative password nor any interaction from the device owner. A malicious actor simply needs to reside on the same local network and transmit a maliciously crafted...
A voice assistant on Mac could become someone else’s microphone and remote control at once: a zero-day found in the AI agent Muse lets an ordinary local process intercept the user’s dictation and make...
On September 22, OpenAI began rolling out GPT-6 Sol and GPT-6 Luna for Codex and ChatGPT Work. Sol is built for complex code and tasks in which the AI works through tools step by...
A critical hole in an SD-WAN management hub has already crossed from advisory to real-world attack: Arista has confirmed exploitation of a VeloCloud Orchestrator vulnerability that, under a certain configuration, lets a remote attacker...
The Irish Data Protection Commission recently announced a staggering fine of 403 million euros, approximately 463 million dollars, against Google for its improper handling of user location data. Prior to this landmark ruling, numerous...
The September Windows 11 update, specifically KB5124008, is now heavily associated with a fresh wave of severe system failures on computers equipped with AMD Radeon graphics cards. Users running Windows 11 versions 24H2 and...
GitHub has successfully rewritten the entire Copilot runtime environment, transitioning from TypeScript to Rust. Astonishingly, Copilot’s own artificial intelligence agents generated the vast majority of this new codebase. This monumental migration consumed approximately three...
The PAYLOAD extortion operators recently targeted a Middle Eastern manufacturing enterprise without executing a single encryptor payload on any Windows machine. After successfully acquiring domain administrator privileges, the malicious actors weaponized Active Directory Group...
The intense controversy surrounding LG Smart TVs did not erupt over a single, disputed toggle switch. Instead, the debate ignited over the nebulous boundary separating perceived “constant eavesdropping” and the undeniable reality of automated...
Chinese cybercriminals increasingly abandon the traditional dark web infrastructure. Operations involving sophisticated phishing campaigns, stolen credit card trafficking, money laundering, and the recruitment of accomplices have migrated overwhelmingly to Telegram. Within this messaging platform,...
Four severe vulnerabilities deeply embedded within the Linux kernel, lurking undetected for 10 to 21 years, finally have functional public exploits. Consequently, these critical flaws allow attackers to achieve root privilege escalation. These vulnerabilities...
The prominent cybersecurity firm CrowdSec recently acknowledged a significant data breach. Attackers successfully exfiltrated source code from approximately 170 private GitHub repositories. A malicious actor initially duplicated this proprietary code on May 22, 2026....
An attempt to download a film through a familiar torrent tracker could infect a computer even without the tracker itself being hacked. Attackers compromised iTorrents.org, a popular repository of torrent files, and made the...