Information Security News Blog
Researchers at IBM X-Force have uncovered new operations by the Chinese threat group Hive0154, better known as Mustang Panda. Analysts observed the simultaneous deployment of an upgraded variant of the Toneshell backdoor alongside a...
Cybersecurity researcher Jeremiah Fowler has reported a major data breach linked to Hello Gym, a company that provides telephony services for the fitness industry in the United States and Canada. The exposed dataset contained...
The hacker collective WhiteCobra has launched a large-scale campaign targeting users of popular code editors including VS Code, Cursor, and Windsurf. Researchers at Koi Security uncovered 24 malicious extensions hosted on official repositories such...
Microsoft has reminded users that in just one month it will officially end support for the much-loved Windows 10. Beginning October 14, 2025, the operating system will no longer receive security patches, bug fixes,...
A leak of internal data from within the Great Firewall ecosystem has revealed the export of censorship and surveillance technologies far beyond the borders of the PRC. On September 9, 2025, an anonymous whistleblower...
Red AI Range (RAR) is a comprehensive security platform designed specifically for AI red teaming and vulnerability assessment. It creates realistic environments where security professionals can systematically discover, analyze, and mitigate AI vulnerabilities through...
Huntress found itself at the center of a heated debate following the publication of a study its own researchers had initially described as a lighthearted mishap. Beneath the playful tone, however, lay material that...
The world of Linux and its surrounding ecosystem is experiencing turbulent times. Developers are divided over how to integrate Rust into the kernel, key contributors are departing, and core subsystems are being handed over...
Experts at Straiker have reported the discovery of a new tool called Villager, which since its release in July has been downloaded nearly 10,000 times from the official PyPI repository. Marketed as a client...
Researchers at ESET have reported the emergence of a new ransomware strain dubbed HybridPetya, which blends techniques from the notorious Petya and NotPetya families while adding the ability to bypass Secure Boot on UEFI-based...
Samsung has released its September security updates for Android, addressing a critical zero-day vulnerability that had already been exploited in active attacks. The flaw, tracked as CVE-2025-21043 and rated 8.8 on the CVSS scale,...
On Thursday, the Helsinki Court of Appeal delivered a ruling that stirred widespread public reaction. Alexander Kivimäki, the 28-year-old convicted of hacking the Vastaamo psychotherapy center and carrying out subsequent extortion, was released from...