Category: Information Security
Check Point researchers have uncovered a new campaign known as the so-called YouTube Ghost Network—a web of hijacked YouTube accounts used to distribute malware disguised as game cheats and pirated software. At the heart...
A newly discovered vulnerability in FreeBSD components responsible for IPv6 configuration allows an attacker on the same local network to remotely execute arbitrary code on a target system. The flaw affects all supported versions...
Have you ever considered how much of your personal time is quietly consumed by those “universally beloved” online advertising banners? More than you might expect. According to a new report from AdGuard, the total...
In an industry where artificial intelligence increasingly sets the rules of the game, one startup has found itself at the center of a high-profile scandal. A hacker known by the alias “Kira” exposed the...
Cisco has warned that threat actors are already exploiting a critical vulnerability in its widely deployed products, one that enables a complete takeover of affected systems, and that no patch was available at the...
Arctic Wolf reports the first confirmed intrusions into customer networks in which attackers logged into FortiGate devices via FortiCloud SSO shortly after the disclosure of two critical authentication-bypass vulnerabilities—CVE-2025-59718 and CVE-2025-59719. According to the...
French law enforcement authorities have arrested a 22-year-old man suspected of orchestrating a recent cyberattack against the country’s Ministry of the Interior. The incident occurred in mid-December and affected the ministry’s internal email servers....
Researchers at iVerify have identified a new Android remote access trojan dubbed Cellik, which blends the capabilities of full-fledged spyware with the ability to masquerade as legitimate applications from Google Play. The malware is...
The Kimwolf botnet has drawn intense scrutiny after researchers at QiAnXin XLab reported that it had infected more than 1.8 million Android-based devices. The compromised army includes smart TVs, set-top boxes, and tablets, all...
Since early December 2025, SOC teams in Japan have been observing a wave of attacks exploiting React2Shell (CVE-2025-55182)—a remote code execution vulnerability in React/Next.js that already has a public proof of concept and is...
In October 2025, experts at Kaspersky Lab uncovered a new wave of targeted attacks attributed to the ForumTroll group. Whereas earlier campaigns primarily focused on organizations, this iteration shifted its attention to individuals—political scientists,...
Researchers at Gen have reported a new WhatsApp account-takeover technique dubbed GhostPairing. The attack appears mundane and arouses little suspicion, yet it ultimately grants attackers full access to a victim’s chats, media files, and...