Information Security News Blog
Australian researchers have tested whether large language models can infer passwords from personal information — and found that, for now, they are almost entirely ineffectual. In a new study, the team at the Future...
The Tomiris group launched a new wave of cyber-espionage in early 2025, targeting high-level political and diplomatic institutions. According to Kaspersky Lab, the attacks focused on ministries of foreign affairs, state agencies, and intergovernmental...
OpenAI has disclosed a security incident at the third-party web-analytics provider Mixpanel that affected a subset of users of the platform.openai.com API service. The event did not involve any breach of OpenAI’s own systems,...
Microsoft is tightening the security of Microsoft Entra ID sign-ins, planning to block all third-party script execution on the authentication page and allow only Microsoft-owned domains and trusted inline scripts. This change, part of...
Apple Podcasts has begun launching itself spontaneously, displaying peculiar religious and “educational” programs and, in some cases, directing users to potentially malicious websites. Researchers have discovered that the app can be triggered invisibly from...
The Japanese brewing giant Asahi has revealed that a September cyberattack resulted in one of the most significant data incidents in its history: the personal information of more than 1.5 million people was put...
Google continues to recalibrate the terms of its free AI access amid surging demand. The company has reduced the daily allowance for image generation in its Nano Banana Pro model and revised the wording...
Expanding Microsoft Teams’ capabilities for working with external users brings not only convenience, but also new vulnerabilities. The Ontinue team has detailed a technique that exploits the peculiarities of guest access to bypass Microsoft...
The “Bloody Wolf” group is expanding its targeted campaign across Central Asia, deploying NetSupport RAT and impersonating government agencies. According to Group-IB specialists, the attacks that began in Kyrgyzstan in the summer of 2025...
GreyNoise Labs has unveiled GreyNoise IP Check, an online service that allows users to determine whether their IP address has been observed participating in suspicious scanning activity linked to botnets or residential proxy networks....
During AWS’s major outage in October, Fortinet specialists uncovered a new botnet, ShadowV2, built on Mirai-derived malware and targeting IoT devices worldwide. According to FortiGuard Labs, the campaign appeared to be a “trial run”...
Myanmar’s military is loudly proclaiming its “fight against scammers,” detonating buildings inside the notorious KK Park complex on the Thai border. Yet satellite imagery and expert assessments reveal that the destruction affects only a...