Category: Information Security
The latest iteration of the macOS stealer known as MacSync has learned to infiltrate victims’ machines almost “like a legitimate application.” According to Jamf, it is now distributed as a signed Swift app packaged...
Commercial robots have proved far less secure than many assume. Security researchers are increasingly demonstrating that certain machines can be taken over in a matter of minutes, and that flaws in software logic can...
The world’s largest online black markets may no longer reside in the dark web, but openly on Telegram itself. According to analysts, a sprawling network of Chinese-language “guarantor markets” has taken root on the...
A critical vulnerability in the globally used workflow automation platform n8n allows attackers to execute arbitrary code remotely. Tracked as CVE-2025-68613, the flaw carries an exceptionally high CVSS score of 9.9 out of 10....
U.S. law enforcement authorities have announced the seizure of a domain used in a large-scale scheme to steal bank accounts. According to the U.S. Department of Justice, the site—web3adspanels[.]org—served as a control hub for...
Threat actors have begun repurposing a legitimate server monitoring tool as a ready-made platform for remotely controlling systems that have already been compromised. According to the Ontinue Cyber Defense Center, recent incidents involve Nezha,...
A malicious package named lotusbail has been uncovered in the npm repository, masquerading as a library for working with WhatsApp Web while quietly siphoning conversations and granting attackers persistent access to user accounts. According...
Spotify has blocked a number of accounts after the Anna’s Archive team publicly released a dataset collected from the streaming platform. According to the group, the trove comprises 86 million audio files and an...
OpenAI has released a security update for ChatGPT Atlas, a browser equipped with a built-in “agent mode” that can browse the web and act within it almost like a human—clicking, typing, and carrying out...
Direct navigation—when a user manually types a website address into the browser—has become markedly more dangerous. Researchers at Infoblox have found that the vast majority of “parked” domains are now configured to automatically funnel...
The U.S. Department of Justice has brought charges against dozens of individuals in connection with a wave of ATM thefts carried out using the Ploutus malware. The department announced that two federal grand juries...
Nigerian authorities have arrested an individual believed to be one of the developers behind RaccoonO365, a phishing-as-a-service platform that enabled criminals to mass-produce fake Microsoft login pages and harvest victims’ usernames and passwords. Acting...