Information Security News Blog
Wscan is a web security scanner that focuses on WEB security. It pays homage to Nmap, which has been open source for 25 years. We also plan to continuously update and keep Wscan open...
An updated patch set for the GRUB2 bootloader has been released publicly, addressing six vulnerabilities at once, most of which stem from accessing memory after it has been freed. Such flaws could potentially allow...
The United Kingdom’s National Crime Agency has announced that it has dismantled an intricate financial network used by intelligence services to bankroll the operations of a spy ring linked to former Wirecard executive Jan...
Hackers gained access on 10 November to Princeton University’s database, which contained the personal information of individuals connected to the institution — alumni, donors, and students. In October, similar breaches struck the University of...
Israel’s NSO Group is attempting to overturn a ruling by a California federal court that ordered the company to cease using WhatsApp’s infrastructure to deliver its Pegasus spyware. The legal dispute has dragged on...
Microsoft has released the out-of-band cumulative update KB5072753 to correct a known issue in which the November hotfix KB5068966 for Windows 11 was repeatedly reinstalled on the same systems. The flaw affected devices running...
Specialists from Group-IB have released an in-depth analysis of the long-running UNC2891 campaign, which demonstrates how inventive modern attack schemes against ATM networks have become. At the center of the operation was a compact...
The NAFFCO company—renowned for large-scale fire-safety projects throughout the Middle East—has found itself at the center of intense discussion following a dark-web post alleging a massive data breach. The incident has drawn widespread attention...
The investigation into the corporate data breach affecting Salesforce customers continues to widen. The company is now examining how third-party Gainsight applications became the channel through which unauthorized parties gained access to client information....
A cyber incident at Almaviva, a key contractor for Italy’s national railway group FS Italiane, has resulted in a massive cache of internal documents appearing on the dark web. The scale of the leak...
LdrShuffle Stealthy code execution via modification of the EntryPoint of loaded modules at runtime. Summary Windows processses have various modules loaded at runtime. Each of theses modules has a DllMain() function defined, which will be invoked on process...
A large-scale TamperedChef campaign has once again drawn the attention of security researchers, as attackers continue distributing malware through counterfeit installers of popular applications. This method of disguising malicious payloads as familiar software enables...