Category: Information Security
Researchers at ETH Zurich have unveiled a novel attack dubbed VMScape, bearing strong resemblance to Spectre and posing a significant threat to virtualization infrastructures. The attack enables a malicious virtual machine to extract cryptographic...
Researchers from Cybernews have reported a major data breach involving Vyro AI, a company renowned for its popular generative applications on Android and iOS. An unsecured Elasticsearch server belonging to the developer had been...
Researchers at Palo Alto Networks have reported a surge in attacks leveraging the open-source platform AdaptixC2, originally designed for penetration testing but now increasingly exploited by cybercriminals. Unit 42 specialists first detected traces of...
An unusual incident unfolded at the Spinoza campus in Amsterdam: an unknown intruder hacked into the digital payment system of five washing machines. For several weeks, students were able to use the machines free...
The UK’s Information Commissioner’s Office (ICO) has raised alarm over a troubling trend: schoolchildren are increasingly responsible for cyberattacks and data breaches within educational institutions. An analysis of 215 incidents recorded between January 2022...
A European DDoS mitigation provider has been struck by an unprecedented attack, with traffic volumes peaking at 1.5 billion packets per second. The massive wave originated from thousands of compromised IoT devices and MikroTik...
Researchers at Oligo Security have uncovered a vulnerability in Apple CarPlay that enables remote code execution with root privileges, granting attackers full control over a vehicle’s multimedia system. The flaw, registered as CVE-2025-24132, resides...
Two Kenyan documentary filmmakers have come under surveillance by state security services for their work on a film about youth-led protests. Digital forensics experts revealed that their phones had been infected with the spyware...
U.S. Senator Ron Wyden has sent a letter to the Federal Trade Commission (FTC) demanding an investigation into Microsoft, accusing the company of “gross negligence” in the field of cybersecurity. The concern stems from...
A new tool called SpamGPT has emerged on underground forums and quickly become a focal point of discussion within the cybersecurity community. The platform combines the capabilities of generative AI with a fully fledged...
In August 2024, SonicWall issued security advisory SNWLID-2024-0015, disclosing an improper access control vulnerability in SSLVPN across Gen5, Gen6, and Gen7 devices. The flaw enabled attackers to bypass restrictions and gain access under specific...
A cyber operation against a Philippine military contractor has exposed a newly discovered and highly sophisticated malicious infrastructure, codenamed EggStreme. Research conducted by Bitdefender attributes the campaign to a Chinese threat group engaged in...