Information Security News Blog
An advertisement has surfaced on the dark web offering three terabytes of data allegedly stolen from two major Russian SMS aggregators. The individual behind the post, using the pseudonym ByteToBreach, claims that the leak...
In recent weeks, a surge of phishing campaigns has emerged in which attackers impersonate popular password managers — LastPass, Bitwarden, and 1Password. Their objective is to deceive users into revealing their master password, the...
Microsoft has released its Digital Defense Report 2025, documenting a sharp surge in attacks targeting digital identities, the misuse of artificial intelligence in cybercrime, and the heightened activity of state-sponsored threat groups. According to...
Microsoft has unveiled a new tool designed to assess the effectiveness of artificial intelligence in cybersecurity. The platform, named ExCyTIn-Bench, recreates conditions closely resembling those of a threat monitoring center, enabling evaluations of how...
The October security updates for Windows 11 unexpectedly disrupted local HTTP/2 connections, causing applications to malfunction when attempting to communicate with services running on “127.0.0.1.” The issue surfaced immediately after installing the cumulative update...
The U.S. cybersecurity agency CISA has added a critical, actively exploited flaw in Adobe Experience Manager to its Known Exploited Vulnerabilities catalog: a configuration vulnerability, CVE-2025-54253, rated as a CVSS 10, which permits arbitrary...
Synacktiv researchers have documented a novel GNU/Linux rootkit, LinkPro, uncovered during an investigation into an AWS infrastructure compromise. The intrusion began with exploitation of a vulnerable Jenkins server, after which the threat actors deployed...
Flightradar24 represents the industry standard for professional flight tracking, serving over 4 million daily users worldwide through its comprehensive real-time aviation data platform. This Swedish-developed service leverages the world’s largest ADS-B receiver network, encompassing...
PolarDNS is a specialized authoritative DNS server written in Python 3.x, originally developed as a tool for security testing of DNS recursive resolvers from the server-side. It allows the operator to produce custom DNS...
ScrapPY: PDF Scraping Made Easy ScrapPY is a Python utility for scraping manuals, documents, and other sensitive PDFs to generate targeted wordlists that can be utilized by offensive security tools to perform brute force,...
Researchers at Trend Micro have documented a large-scale operation codenamed ZeroDisco, in which attackers weaponized a critical flaw in Cisco’s SNMP implementation (CVE-2025-20352, CVSS 9.0) to implant rootkits and execute arbitrary code on network...
The internal announcement system at Harrisburg International Airport in Pennsylvania was temporarily disabled after unidentified individuals gained unauthorized access on the evening of October 14, broadcasting a political message calling for “Freedom for Palestine.”...