APT Infy, also called Prince of Persia, is active again after years of silence.
New research shows operations never stopped, and the toolset quietly evolved.
Updated malware, stronger C2 defenses, and fresh global victims point to a long-term espionage program
New research shows operations never stopped, and the toolset quietly evolved.
Updated malware, stronger C2 defenses, and fresh global victims point to a long-term espionage program
Microsoft Brokering File System Elevation of Privilege Vulnerability (CVE--2025-29970).
NIST tried to pull the pin on NTP servers after blackout caused atomic clock drift.
Merry Hacking Xmas! Kali Linux NetHunter 2025.4 released!
Android 16 support, new devices with injection, Evil Twin AP pages, Magisk v28.1+ support, and more! https://kali.org/blog/kali-linux-2025-4-release ❄️🎄📱⌚📡
Android 16 support, new devices with injection, Evil Twin AP pages, Magisk v28.1+ support, and more! https://kali.org/blog/kali-linux-2025-4-release ❄️🎄📱⌚📡
There’s so much stolen data in the world, South Korea will require face scans to buy a SIM.
UK Government Acknowledges It Is Investigating Cyber Incident After Media Reports.
Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale.
Spotify music library scraped by pirate activist group and made available as a torrent.
Includes 86M audio files, now circulating in bulk torrents totaling ~300 terabytes.
Spotify is "actively investigating the incident."
Includes 86M audio files, now circulating in bulk torrents totaling ~300 terabytes.
Spotify is "actively investigating the incident."
INTERPOL led a cybercrime sweep across Africa. 574 arrests and $3M recovered after targeting BEC, extortion, and ransomware in 19 countries.
Separately, a Ukrainian Nefilim ransomware affiliate pleaded guilty in the U.S.
Separately, a Ukrainian Nefilim ransomware affiliate pleaded guilty in the U.S.
Purdue University tested deepfake detectors where they actually break: real, compressed social media video.
Not clean demos. Not lab data.
The benchmark shows why false-acceptance rate matters more than accuracy when camera feeds drive access and trust.
Not clean demos. Not lab data.
The benchmark shows why false-acceptance rate matters more than accuracy when camera feeds drive access and trust.
A critical RCE flaw (CVSS 9.9) was found in the n8n workflow automation platform.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
CVE-2025-68613 lets authenticated users execute arbitrary code, enabling full instance takeover, data access, and system-level actions.
More than 103k exposed instances are observed globally.
A malicious WhatsApp API package on npm quietly hands attackers full account access.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
56,000+ downloads later, “lotusbail” is intercepting every message and secretly linking attacker devices during login.
Vivaldi, a browser company from Iceland and Norway. We make a browser for all major platforms that's big on privacy and customization. Employee-owned, user-focused, and built for people who want actual control over their browsing 🧰
A truly decentralized Signal alternative messenger app with default E2EE, onion-routed messaging, no phone number or email required, and fully open source clients and servers https://alternativeto.net/software/session/about/ #session
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations
Медицинская лаборатория Гемотест (Gemotest) - 6,341,495 breached accounts.