Information Security News Blog
The FBI has reported a surge in fraudulent schemes involving the takeover of financial accounts and warned that such attacks may intensify as the holiday shopping season approaches. According to the agency, more than...
Cybercriminals no longer need to coax ChatGPT or Claude Code into assisting with malware development or data-theft scripts. A whole class of specialized language models now exists expressly for offensive operations. One such system...
RAITrigger The RPC-function RAiForceElevationPromptForCOM from the appinfo.dll library allows SYSTEM coercion. This only works on domain joined systems. It turns out, that this function can be called from any low privileged user (not to spawn a process) but to...
Malicious activity has once again surged within the npm ecosystem. This time, it is the second wave of the Shai-Hulud attack—an operation that mirrors the logic of the September campaign but unfolds with far...
Accumulated failures in Windows 11 version 24H2 have led to situations in which the system, under certain conditions, loses portions of its interface immediately upon the first login after updating. Users encounter vanishing shell...
The steady complication of familiar Windows tools has once again drawn attention to Microsoft’s Notepad, which for decades remained a minimalist editor devoid of superfluous features. Now the company is redefining its role, adding...
Amazon has begun revealing details of its internal Autonomous Threat Analysis system, created to accelerate vulnerability detection and the development of defensive measures. Confronted with an ever-growing codebase and increasingly sophisticated attack techniques, the...
Superbox drew consumer attention with promises of access to more than 2,200 television channels and streaming services without a subscription, all for a one-time payment of roughly $400. Yet an examination of the device...
Fake Windows updates have entered a new cycle of ClickFix campaigns, according to researchers at Huntress. Attackers are increasingly replacing bot-check pages with full-screen blue windows that perfectly mimic the Windows update interface. As...
The North Atlantic Alliance is beginning a sweeping modernization of its technical infrastructure, having secured a major contract with Google Cloud. Under the agreement, NATO will gain access to a sealed, fully air-gapped version...
The U.S. Federal Cybersecurity Agency has issued a warning about a surge in targeted attacks involving commercial surveillance tools and remote-access software. Threat actors have increasingly focused on users of popular messaging platforms, seeking...
A recent incident involving malicious files in the 3D-graphics ecosystem has revealed how vulnerable even familiar tools can become when used alongside automated features. On popular model-sharing platforms, attackers have begun uploading Blender projects...