Information Security News Blog
A vulnerability has been discovered in early builds of OpenVPN, allowing attackers to execute arbitrary commands on a user’s machine. The flaw affects versions from 2.7_alpha1 through 2.7_beta1 and poses a serious threat to...
In a recent report, researchers from Varonis Threat Labs reminded the cybersecurity community of a deceptive technique used by phishers to disguise malicious links as legitimate ones. This method, based on how browsers render...
Google has unveiled a completely reimagined development experience within Google AI Studio, known as “vibe coding.” This new capability enables the creation of fully fledged multimodal applications from a single text description — without...
KeePwn A python script to help red teamers discover KeePass instances and extract secrets. Features & Roadmap KeePass Discovery Look for KeePass installation files through SMB C$ share. Accept multiple target sources (IP, CIDR,...
Microsoft has begun testing a new Windows 11 feature that prompts users to run a memory diagnostic after encountering a Blue Screen of Death (BSOD). The feature is designed to improve overall system stability...
search_vulns can be used to search for known vulnerabilities in software. To achieve this, the tool utilizes a locally built vulnerability database, currently containing: CVE information from the National Vulnerability Database (NVD) Enhanced NVD information from VulnCheck...
Microsoft has become the defendant in a lawsuit filed by the Australian Competition and Consumer Commission (ACCC), which accuses the company of misleading millions of users by effectively forcing them to migrate to more...
Several media outlets have once again circulated false claims of a supposed large-scale data breach affecting Gmail, alleging the compromise of 183 million user accounts. The reports stemmed from an announcement by Troy Hunt,...
The BlueNoroff group — long linked to Lazarus — has begun incorporating generative AI into operations targeting executives and developers of blockchain projects, Kaspersky GReAT researchers reported at the Security Analyst Summit 2025 in...
A newly discovered vulnerability in ChatGPT Atlas, the experimental browser developed by OpenAI, allows attackers to silently inject malicious commands into the AI’s persistent memory, enabling the execution of arbitrary code on behalf of...
Seventy-two nations gathered in Hanoi, Vietnam, to sign the world’s first United Nations Convention on Cybercrime, establishing a global legal framework to counter digital threats. The document—years in the making—is set to become the...
Cyberthreat analysts are reporting active exploitation of a critical vulnerability in Windows Server Update Services (WSUS), identified as CVE-2025-59287. Merely days after Microsoft released an emergency patch and CISA added the flaw to its...