Information Security News Blog

A conceptual image showing an AI coding agent executing a hidden malicious command from a compromised Git repository. 0

GitSpawn Exposes AI Coding Agents

A seemingly ordinary project folder can transform into a dangerous trap. This trap springs before the developer even executes their first command. Manifold Security researchers recently discovered a critical vulnerability class named GitSpawn. These...

A conceptual illustration of the Project Watershed 250 initiative securing critical water utility infrastructure against cyberattacks. 0

White House Launches Project Watershed 250

The White House officially initiated a six-month pilot program named Project Watershed 250 in Texas. This vital initiative aims to discover practical methods for shielding American water and wastewater systems from sophisticated cyberattacks. Participating...

An abstract visual representation of the powerful OpenAI Astra model independently identifying vulnerabilities and constructing zero-day exploits. 0

OpenAI Classifies Astra as Critical Threat

Artificial intelligence recently breached a crucial internal OpenAI boundary. Basic safeguards against malicious requests simply no longer suffice. The company officially recognized Astra as its first model possessing critical cybersecurity capabilities. During rigorous testing,...

A conceptual image of a deceptive software download mimicking legitimate applications 0

Deceptive Software Campaign Exposed

A routine software search recently transformed into a critical entry point for severe malware infections. Microsoft recently exposed a sophisticated counterfeit installer campaign. Participants in this operation meticulously cloned the websites of renowned software...

A conceptual image showing the United States Department of Justice seizing domains connected to the QTFY hacking group. 0

US Seizes Domains Linked to QTFY Group

The United States successfully seized the domains of two prominent hacking platforms. The Department of Justice and the FBI allege the Chinese state-sponsored group QTFY operated these platforms. The group utilized these domains to...

Langflow CVE-2026-0768 exploitation harvesting OpenAI and AWS keys from an exposed AI application server 0

Langflow Flaw Exploited to Steal OpenAI and AWS Keys

Servers for developing AI applications have become vaults of valuable secrets, accessible through a single unprotected request. Attackers have begun exploiting the critical vulnerability CVE-2026-0768 in Langflow to extract OpenAI and AWS keys, administrator...

Nearly 22,000 internet-facing Exchange servers remain unpatched against CVE-2026-62911, an authentication bypass that can hijack every user's mailbox 0

22,000 Exchange Servers Exposed to Mailbox-Hijack Flaw

Corporate email can fall into an attacker’s hands after the compromise of a single low-privilege account. Nearly 22,000 internet-facing Microsoft Exchange servers have not received the fix for CVE-2026-62911, a flaw that allows every...

A conceptual image illustrating a fake MP4 file concealing malicious code 0

Fake MP4 Files Conceal Malware

Sometimes, threat actors utilize video files not for mere viewing, but for cunning concealment. Censys specialists recently discovered a sophisticated malware campaign. This campaign actively deploys structurally sound, yet entirely unplayable MP4 files. These...

A visual representation of the Andrew Tate War Room data leak exposing secret courses on bribery and manipulation 0

Secret Tate War Room Courses Exposed

Andrew Tate’s exclusive “War Room” sold far more than basic financial and relationship advice. A massive data leak recently exposed highly secretive internal courses. These materials instructed members on bribing government officials and police...