Information Security News Blog
According to Boiling Steam, the number of Windows games running reliably on Linux has reached its highest level since tracking began. The analysis draws on data from ProtonDB, a platform that aggregates user reports...
Researcher Jose Pino unveiled a proof-of-concept for a vulnerability in the Blink rendering engine used by Chromium-based browsers, demonstrating how a single web page can, within seconds, incapacitate numerous popular browsers and halt a...
New research has revealed that even the most advanced hardware-based data isolation technologies from leading chip manufacturers—Nvidia Confidential Compute, AMD SEV-SNP, and Intel SGX/TDX—fail to withstand inexpensive physical attacks. These mechanisms, collectively known as...
A vulnerability in the Google Messages app for Wear OS has jeopardized the privacy of millions of smartwatch owners, allowing third-party applications to send messages on behalf of users without requesting permissions or confirmation....
Former L3Harris defense contractor employee Peter Williams has pleaded guilty in a U.S. federal court to two counts of theft of trade secrets, admitting that he sold eight zero-day vulnerabilities to a Russian intermediary...
The ongoing PhantomRaven campaign has targeted developers via the npm registry, disseminating dozens of malicious packages across the ecosystem in a short span. Embedded within these packages, malicious code harvests authentication tokens, CI/CD secrets,...
As early as 2026, Google Chrome will adopt a new security policy, requiring HTTPS connections by default when accessing public websites. Google announced that with the release of version 154, scheduled for October next...
A newly uncovered phishing campaign, identified by researchers at the Internet Storm Center, showcases a remarkably unconventional method of evading email filters—by embedding invisible characters within message headers. Specifically, the attackers employ soft hyphen...
The 2025 At-Bay InsurSec Rankings report recorded a sharp surge in cyberattacks linked to email and remote access—two channels responsible for nearly 90% of all incidents among the company’s clients. Analysts highlight that generative...
SHELLSILO is a cutting-edge tool that translates C syntax into syscall assembly and its corresponding shellcode. It streamlines the process of constructing and utilizing structures, assigning variables, and making system calls. With this tool,...
A vulnerability has been discovered in early builds of OpenVPN, allowing attackers to execute arbitrary commands on a user’s machine. The flaw affects versions from 2.7_alpha1 through 2.7_beta1 and poses a serious threat to...
In a recent report, researchers from Varonis Threat Labs reminded the cybersecurity community of a deceptive technique used by phishers to disguise malicious links as legitimate ones. This method, based on how browsers render...