Information Security News Blog
Microsoft has resolved an issue in Windows 11 version 24H2 that generated false CertificateServicesClient (CertEnroll) error messages. The glitch appeared after the installation of the July preview update KB5062660 and persisted through all subsequent...
Microsoft has denied any connection between the August Windows 11 security update and the wave of complaints about storage drive failures. The investigation was prompted by reports from users claiming that, after installing patch...
Microsoft is preparing to release the next major update to Windows 11. Today, the Windows Insider team announced that Windows 11 version 25H2 has entered the Release Preview channel—the final stage before the system...
WhatsApp has patched a vulnerability in its iOS and macOS client applications that had been actively exploited in zero-day targeted attacks. The flaw enabled a “zero-click” scenario, requiring no interaction from the victim. According...
At DEF CON 2025, researchers from Akamai unveiled a study on a critical vulnerability in Windows Server 2025 known as BadSuccessor (CVE-2025-53779), which allows low-privileged users to instantly escalate their access to Domain Admin....
The Netherlands has officially disclosed a cyber-espionage campaign linked to China that has impacted critical sectors across the globe. According to the Ministry of Defense, the attacks were carried out by groups tracked under...
Villain Villain is a Windows & Linux backdoor generator and multi-session handler that allows users to connect with sibling servers (other machines running Villain) and share their backdoor sessions, handy for working as a...
Google is officially preparing to enter the blockchain market — not with an experimental service, but with its very own Layer 1 network. The new project, named Google Cloud Universal Ledger (GCUL), is positioned...
Experts at ReversingLabs have uncovered a critical loophole in the VS Code Marketplace. The platform allows new extensions to be published under the same names previously used by other packages, provided those packages were...
The FBI and Dutch police have conducted a joint operation that shut down VerifTools, a major online marketplace specializing in the sale of forged documents. The servers supporting the platform were seized in Amsterdam,...
The BetterBank project, which positions itself as a decentralized banking protocol on PulseChain, suffered an exploit in which an attacker siphoned assets valued between $1 and $5 million. The root cause was a vulnerability...
Anthropic has issued a warning about a new threat emerging alongside “smart” browser extensions — websites may discreetly inject hidden commands, which an AI agent could execute without hesitation. The company unveiled a research...