Complex search queries have their own way to communicate with the server. The Internet Engineering Council (IETF) has approved a new HTTP method called QUERY, which will allow you to transfer large sets of conditions without giant addresses and the unsuitable for such a task of the POST method...
Millions of links to channels, chat rooms, bots and Telegram profiles suddenly turned into non-working addresses. A short domain t.me has ceased to open in browsers around the world after the operator of the .me domain zone has disabled it at the level of the global DNS system. The messenger...
The debugging function, built into every Android smartphone for developers, suddenly found itself in the hands of scammers and turned into a tool for completely capturing someone else's device.
We are talking about the RedHook Trojan, aimed at Android smartphones. The malware was...
Full-fledged extra charger penalty test - five hosts, four compromised, lateral movement passed - for $ 28.50 in API-chick-hikes to LLM. The manual pentest of a similar horse is cost the customer $ 15000-$50000. The annual pentest once a year against this rate is a statistical formality. Below I...
Monday, 9:15. The first day of probability breach in a company with a valid ISO 27001 certificate, a five-analyst of five analysts and a 120-page security strategy. By 11:30 BloodHound has shown the way to Domain Admin through a service account svc_backup - Password Summer2021!It hasn't changed...
The attackers massively hack websites around the world and install hidden means on servers to remotely manage them. The campaign has already affected many small and medium-sized companies in Australia, but the attacks are not limited to one country.
The Australian Cyber Security...
A malicious request for a change in code can be checked without a single comment, and a few days later force the AI assistant imperceptibly to take out the secrets of the project. To attack, it is enough to hide the instructions inside a regular PNG file, which the code verification systems do...
For almost six months, the internal passwords and keys of the American cyber agency were in public access on GitHub, and the agency received automatic notifications nine times and did not respond to them. The U.S. Cybersecurity and Infrastructure Protection Agency (CISA) acknowledged errors...
Thirteen CVE with a score of 9.0 to 10.0 for the first half of 2026 - in one library, which the continent marked deprecated in 2023. According to The Hacker News, each leads to the execution of arbitrary code on the host system. Three of them, CVE-2026-43997, CVE-2026-44005 and CVE-2026-44006 -...
In October 2025, the extortion group ShinyHunters launched a darknet platform with the data of six organizations - Albertsons, Fujifilm, Gap, Qantas, Engen Resources, Vietnam Airlines - and announced the compromising about a billion records from Salesforce-instorms of 39 companies. Among the...
Corporate storage is usually disconnected only at serious risk, and Progress Software asked clients to immediately stop the ShareFile Storage Zone Controller servers because of a reliable external threat.
The company temporarily blocked ShareFile accounts that work through Storage Zone...
A stable distribution is valued primarily for predictability, and Debian 13.6 strengthens it with a large set of fixes for Linux kernels, server software and virtualization tools. The Debian project released the sixth interim update of the Debian 13 trickee on July 11, 2026. No surprises...
The stolen key to the package registry allowed the attacker to upload five infected versions of jscrambler with IronWorm malware into the NPm. The attack was studied by experts Socket, JFrog, SafeDep and StepSecurity.
Socket noticed the first malicious version six minutes after...
One domain - sempersim[.]su - lit up in the ThreatFox fudge as C2 for LokiBot. After four DNS beer from this single indicator, I went to a cluster of 25+ hosts: iCloud phishing domains, Xworm and Remcos infrastructure on dynamic DNS services, a total CIDR range with 464 suspicious domains. Two...
In May 2026, Qualys Threat Research Unitrevealed CVE-2026-46333- logical error in __ptrace_may_access()Linux kernel. Bag lived in a mainline code for nine years, startingwith v4.10-rc1 (November 2016). Four working exploits - againstDefault installations Debian 13, Ubuntu 24.04/26.04, Fedora 43...
Home Wi-Fi can spoil not only a thick concrete wall or a weak router. Sometimes the connection disappears from a dinner in a microwave, an aquarium between rooms, a large mirror, or a TV that reflects a radio signal to the side. In winter, snow, frost and overloaded networks are added to...