Information Security News Blog
Hackers have begun exploiting a critical Windows vulnerability that allows remote code execution on a target computer without requiring an account or any user interaction whatsoever. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)...
A single click on a maliciously crafted link was sufficient to trigger a severe data breach through Microsoft Copilot Personal. Astonishingly, without any further user interaction, the assistant would begin scanning connected emails, calendars,...
The Medusa threat group has attacked more than 500 U.S. critical infrastructure organizations since June 2021. As recently as February 2025, American authorities had counted just over 300 confirmed victims, meaning the roster of...
More than 50,000 Berlin households risk not receiving their housing benefit payments on time following a hacker attack on the city government’s information systems. The disruption has affected not only benefit payments, but also...
The Clop threat group is likely using a purpose-built web shell to steal data from PTC Windchill and FlexPLM servers. The malware is engineered specifically around Windchill’s internal architecture: it connects to the application...
In a stunning display of cyber aggression, a lone operator successfully infiltrated over 14,500 Dahua security cameras within a mere five weeks. Alarmingly, the attacker meticulously planted a hidden backdoor account on nearly 2,000...
Microsoft finds itself unable to release the inaugural cumulative update for Exchange Server Subscription Edition according to its original schedule. Initially anticipated by the close of the first half of 2026, the Exchange SE...
Malicious actors brazenly targeted developers utilizing counterfeit packages deployed simultaneously across two highly prominent repositories. Cybercriminals stealthily introduced 16 malicious libraries into RubyGems and strategically placed another 37 within the npm registry. They meticulously...
Ransomware attackers disrupted the engineering systems of Manitoba’s largest hospital, in the Canadian province. Following a cyberattack at the Health Sciences Centre in Winnipeg, problems emerged in the centralized control of ventilation, air conditioning,...
Israeli cryptocurrency company Bits of Gold has warned customers of a personal data leak following an incident within a third-party support system. Attackers may have obtained names, national ID numbers, email addresses, phone numbers,...
An AI agent designed to hunt for vulnerabilities independently discovered a flaw within a public Snowflake repository and used it to gain access to the company’s internal Jira system. The vulnerability had existed for...
Iranian intelligence agencies have intensified their efforts to compromise Israeli journalists. Threat actors aggressively target media personnel through WhatsApp and Telegram. Specifically, they impersonate familiar individuals to build trust. Afterwards, they offer interviews, collaborative...