Information Security News Blog
Myanmar’s military is loudly proclaiming its “fight against scammers,” detonating buildings inside the notorious KK Park complex on the Thai border. Yet satellite imagery and expert assessments reveal that the destruction affects only a...
RedExt is a sophisticated browser data analysis framework designed for authorized red team operations. It combines a Manifest V3 Chrome extension with a Flask-based C2 server to provide comprehensive browser data collection and analysis...
RingReaper is a simple post-exploitation agent for Linux designed for those who need to operate stealthily, minimizing the chances of being detected by EDR solutions. The idea behind this project was to leverage io_uring, the new...
The hacker collective known as Scattered LAPSUS$ Hunters — which has spent this year extorting dozens of corporations and selling stolen data — has proven to be built, in no small part, around a...
Hackers breached U.S. radio stations and broadcast fabricated alerts and streams of obscenities live on air, prompting the FCC to once again remind broadcasters of the fundamentals of cybersecurity. The intruders seized control of...
A malicious extension has been discovered in the Chrome catalog — an add-on that, without the owner’s knowledge, inserts a hidden fee into Solana transactions and diverts it to a wallet controlled by the...
Censys researchers have detailed a new web-attack technique known as EtherHiding, in which attackers conceal malicious code inside smart contracts on the Binance Smart Chain test network and deliver it through counterfeit CAPTCHA pages....
ASUS continues to patch dangerous flaws in its home routers following a wave of attacks targeting the AiCloud service. The company has released a new firmware version addressing nine vulnerabilities, including a critical authentication...
Cato Networks has unveiled a new attack technique, dubbed HashJack, which conceals malicious AI prompts behind the “#” symbol within legitimate URLs — coercing AI-powered browsers into executing them while remaining invisible to traditional...
The CodeRED alert platform operated by OnSolve and maintained by the risk-management firm Crisis24 has fallen victim to a major cyberattack — an incident that disrupted emergency-notification systems relied upon by government agencies and...
Ordinary mergers and acquisitions are unexpectedly becoming a convenient point of entry for extortionists: operators of the Akira ransomware are infiltrating the networks of large companies through vulnerable SonicWall appliances inherited along with the...
The FBI has reported a surge in fraudulent schemes involving the takeover of financial accounts and warned that such attacks may intensify as the holiday shopping season approaches. According to the agency, more than...