Information Security News Blog
xurlfind3r is a command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn’t interact directly with...
Monsta FTP CVE-2025-34299 Exploit Python exploit for the RCE vulnerability in Monsta FTP (CVE-2025-34299). This vulnerability allows arbitrary PHP code execution on the Monsta FTP server by exploiting the downloadFile functionality which allows downloading files...
Ryūjin is a research-grade protector and obfuscator built to explore Bin2Bin transformation techniques. It is suitable for security researchers, reverse engineers, anti-cheat and anti-tamper developers, and others studying binary protection. Ryūjin focuses on transforming...
Over the past quarter, the ransomware ecosystem has entered a new phase that markedly reshapes its familiar balance of power. Where the market once revolved around large, entrenched operators with stable infrastructures, it has...
One of the largest supply-chain attacks ever recorded in the npm ecosystem has been uncovered, marking a historic event for open-source repositories. According to Amazon’s researchers, the registry faced an unprecedented “flooding” of packages...
ASUS has released new firmware addressing a critical authentication-bypass vulnerability affecting several DSL-series home routers. Catalogued as CVE-2025-59367, the flaw allows a remote attacker to access the device without any credentials whatsoever. The attack...
Microsoft’s Head of Windows, Pavan Davuluri, found himself under fire several days ago after outlining plans to transform Windows into what he called an “agentic OS,” centered on AI and automation. The idea was...
WiFi 7, the latest generation of wireless networking, promises breathtaking speeds and far greater stability — yet it also brings an unfamiliar set of technical subtleties. Home routers are shifting to triple-band configurations, and...
The automaker Jaguar Land Rover has released its financial results for the period from July to September, confirming that the recent attack on its infrastructure has become one of the most severe crises the...
The recent surge in activity surrounding an XWiki vulnerability underscores how swiftly weaknesses in widely used platforms can be transformed into launchpads for large-scale attacks. The unfolding pattern makes clear that once the first...
The United States has announced a new series of guilty pleas in a case involving schemes that enabled North Korean citizens to earn income through remote work at American companies. According to the Department...
In several countries, recent months have brought a new wave of covert surveillance operations targeting defense institutions and high-level government structures. According to the Israel National Digital Agency (INDA), the activity represents a prolonged...