Category: Information Security
ServiceNow recently addressed three maximum-severity vulnerabilities residing within its AI Platform. Astonishingly, each individual flaw received a perfect 10.0 rating on the CVSS 4.0 scale. Furthermore, a potential attacker requires absolutely no authentication or...
Malicious code no longer necessarily requires complex obfuscation to successfully evade neural network detection. Sometimes, merely inserting a specific phrase within a comment suffices. The artificial intelligence will subsequently refuse to continue its analysis...
Companies have only a few months left to fortify their defenses before AI markedly accelerates real-world cyberattacks. OpenAI issued that warning in an open letter endorsed by 128 organizations, among them Google, Microsoft, Anthropic,...
The Iranian group Tortoiseshell continues to broaden both its toolset and the geography of its operations. Group-IB specialists have uncovered previously unknown malware samples and additional server infrastructure tied to the group. Among the...
A debilitating cyberattack targeting a modest supplier of critical equipment for American water utilities resulted in the catastrophic leakage of hundreds of gigabytes of highly sensitive data. Consequently, this alarming breach immediately prompted a...
Barely 19 hours after releasing an emergency patch for PaperCut NG and MF, the company had to prepare a replacement. Researchers uncovered several ways to circumvent the original safeguard, and they also identified yet...
Remote-access systems without open ports are meant to shrink the attack surface. Yet a single flaw in authorization checks can push the risk back up to the application layer. A UltraViolet Cyber researcher discovered...
For the third consecutive day, a massive Distributed Denial-of-Service (DDoS) attack continues to severely disrupt Norway’s state digital services. The overwhelming overload upon the shared infrastructure directly impacted critical authorization systems, electronic signatures, and...
Modern defense systems confront a frustrating paradox. As artificial intelligence models become increasingly powerful, their built-in restrictions severely impede specialists attempting to analyze genuine cyberattacks. David Bianco, a distinguished researcher at Cisco Talos, astutely...
NVIDIA graphics cards employ specialized error-correcting memory capable of detecting and repairing random data corruption on its own. A new attack called GPUThor has demonstrated that even this protection can be circumvented, leading to...
A WordPress site administrator’s password could be changed by an attacker without ever logging in. A critical vulnerability in the popular Pods plugin allowed an unauthenticated outsider to bypass several layers of security checks...
Hackers have found a way to weaponize ordinary Notion notifications to steal employee credentials. The group DOUBLOON DREDGER creates fake executive accounts, sends out document-sharing invitations, and routes victims through a chain of PDF...