NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

A Critical Flaw in NASA’s System Exposes Spacecraft to Potential Hacking NASA has recently disclosed a serious vulnerability in its Automated Interface Test (AIT)-GUI, a system used for testing and validating spacecraft commands. The flaw, which affects multiple missions, could allow unauthenticated attackers to issue commands to the spacecraft, raising concerns about the security of … Read more

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated hacking campaign, allegedly linked to Russian threat actors, has been exploiting a previously unknown vulnerability in Google’s OAuth authentication system to hijack user accounts on multiple platforms. The hackers are also using WhatsApp’s link-sharing feature to gain unauthorized access to sensitive information, leaving thousands of users vulnerable to identity theft and data breaches. … Read more

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

A Devastating Supply Chain Attack Hits Rust Developers, Exposing Millions of Users to Build-Time Malware A sophisticated attack on the Rust programming language’s supply chain has compromised hundreds of crates, leaving millions of users vulnerable to build-time malware. The attackers exploited a vulnerability in the `cargo` package manager, injecting malicious code into popular libraries used … Read more

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

Malware on Android Devices Creates New Path for Data Theft, Even When Phones Are Offline A newly discovered strain of malware has found a way to extract sensitive data from offline Android devices by exploiting nearby infected gadgets. The Manic Android Malware uses Bluetooth Low Energy (BLE) signals to locate and connect with other compromised … Read more

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

A Devastating New Form of DDoS Attacks is Wreaking Havoc on Web Servers, Leveraging HTTP/3 Translation for Catastrophic Amplification The cybersecurity landscape has just taken a dark turn with the emergence of a novel and highly effective form of Distributed Denial-of-Service (DDoS) attacks. Dubbed “CDN Tsunami,” this technique exploits a vulnerability in the HTTP/3 protocol, … Read more

Why “Shady AI” is Security’s Next Big Governance Problem

A growing concern in cybersecurity is emerging from an unlikely source: the intersection of artificial intelligence and identity exposure. Recent research has revealed a disturbing trend, where compromised identities are being used as a “key” to unlock active attack paths across multiple domains. Dubbed “Shady AI,” this phenomenon highlights the evolving nature of cyber threats … Read more

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Cybersecurity experts have discovered a disturbing trend in which AI-generated exploit scripts are being used to target Siemens S7 Programmable Logic Controllers (PLCs) in critical infrastructure across the United States. These PLCs, commonly found in industrial control systems, power plants, and other high-stakes operations, play a crucial role in maintaining public safety and economic stability. … Read more

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Cybersecurity Threats Exposed: A Wave of Vulnerabilities Hits Multiple Platforms A recent wave of vulnerabilities has exposed critical weaknesses in several popular platforms, allowing attackers to gain unauthorized access and wreak havoc on compromised systems. Among the affected parties are developers using Gogs, a self-hosted Git platform, and users of n8n, a workflow automation tool. … Read more

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A New Form of Android Malware Exfiltrates Data from Offline Devices Cybersecurity researchers have uncovered a sophisticated piece of malware that can extract sensitive data from offline Android devices by using nearby infected phones as “data bridges.” This novel approach to mobile malware allows attackers to bypass traditional security measures, raising concerns about the vulnerability … Read more

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

A Devastating New Form of DDoS Attack Exploits HTTP/3 Translation, Leaving Websites Reeling In a shocking revelation, security researchers have uncovered a catastrophic new form of Distributed Denial-of-Service (DDoS) attack that exploits the translation mechanism in HTTP/3 protocol, amplifying the assault by up to 350 times. This tsunami-like assault has left numerous high-profile websites scrambling … Read more