Category: Information Security
A coalition of more than thirty human rights, consumer protection, and child advocacy organizations has urged the U.S. Federal Trade Commission (FTC) to halt Meta’s initiative that would allow the company to use private...
Hacktivists have infiltrated Canada’s critical infrastructure systems, altering control parameters across several facilities — actions that authorities warn could have led to dangerous consequences. The incident marks yet another example of cyberattacks carried out...
Several U.S. government agencies have expressed support for a Commerce Department initiative exploring a potential ban on TP-Link devices, according to The Washington Post, which cites sources familiar with the internal discussions. Among them...
Google has released new data detailing the performance of Android’s built-in protection systems designed to combat fraudulent calls and messages. According to the company, these safeguards block over 10 billion suspicious contacts every month,...
The Eclipse Foundation has revoked several compromised access tokens associated with publishing extensions to the open Open VSX repository. The investigation was prompted by a report from Wiz, a company specializing in cloud security....
A sharp surge in attacks targeting PHP servers, Internet of Things (IoT) devices, and cloud gateways has been recorded by researchers from the Qualys Threat Research Unit (TRU). According to their findings, the escalation...
Researcher Jose Pino unveiled a proof-of-concept for a vulnerability in the Blink rendering engine used by Chromium-based browsers, demonstrating how a single web page can, within seconds, incapacitate numerous popular browsers and halt a...
New research has revealed that even the most advanced hardware-based data isolation technologies from leading chip manufacturers—Nvidia Confidential Compute, AMD SEV-SNP, and Intel SGX/TDX—fail to withstand inexpensive physical attacks. These mechanisms, collectively known as...
A vulnerability in the Google Messages app for Wear OS has jeopardized the privacy of millions of smartwatch owners, allowing third-party applications to send messages on behalf of users without requesting permissions or confirmation....
Former L3Harris defense contractor employee Peter Williams has pleaded guilty in a U.S. federal court to two counts of theft of trade secrets, admitting that he sold eight zero-day vulnerabilities to a Russian intermediary...
The ongoing PhantomRaven campaign has targeted developers via the npm registry, disseminating dozens of malicious packages across the ecosystem in a short span. Embedded within these packages, malicious code harvests authentication tokens, CI/CD secrets,...
A newly uncovered phishing campaign, identified by researchers at the Internet Storm Center, showcases a remarkably unconventional method of evading email filters—by embedding invisible characters within message headers. Specifically, the attackers employ soft hyphen...