Install
Infosecurity Magazine is the award winning online magazine dedicated to the strategy, insight and technology of information security The award winning online magazine dedicated to the strategy, insight and technology of information security
- 1,111articles · 365d
- 3+ day agolatest article
- Sep 14, 2025earliest in window
- 97%with images
- 357avg words
- cybersecurity 961
- security 933
- technology 573
- artificial intelligence 451
- malware 435
- ai 386
- cyber security news 342
- cybercrime 328
- cyber security 301
- business 241
- vulnerability 197
- data breach 173
- ransomware 166
- computer security 157
- software 133
- cyberattacks 126
- tech 119
- vulnerabilities 116
- windows 114
- phishing 110
- Science & Technology 648
- Crime & Law 437
- Computers & Electronics 423
- Software 379
- News 280
- Conflict, War & Peace 230
- Internet & Telecom 143
- Science & Nature 140
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Researcher Shares CrowdStrike Privilege Escalation Zero Day
6+ day, 22+ hour ago (383+ words) A security researcher has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike. The individual, identified by their online moniker “Nightmare Eclipse” (aka Infinite Nightmare, MSNightmare) posted the details to GitHub on September 3. “FalconFlank is…...
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
4+ week, 55+ min ago (197+ words) Read more on WordPress plugin flaws: Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites The issue stems from a type confusion error in the plugin’s registration and automatic-login flow. Wordfence, a security plugin for WordPress, found that…...
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
1+ mon, 2+ week ago (417+ words) A cryptomining operation has been observed abandoning root access on compromised Linux servers in favor of impersonating low-privileged users, a deliberate downgrade designed to avoid the alerts that root activity triggers in a security operations center (SOC). According to new…...
Ubuntu snap-confine Vulnerability Enables Local Root Access
1+ mon, 3+ week ago (487+ words) A newly disclosed vulnerability in the Ubuntu component that isolates snap applications has been found to hand full root access to any local user on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. According to new research from the Qualys Threat Research…...
Progress Restores ShareFile Storage Access After Exploit Concerns
1+ mon, 4+ week ago (232+ words) After a four-day security suspension, Progress has restored access to its ShareFile Storage Zones Controller. Progress Software detected “a credible external security threat” on July 10 that prompted the company to temporarily suspend the service. The service was resumed on July…...
Hackers Exploit Maximum Severity Adobe ColdFusion Flaw
2+ mon, 6+ day ago (323+ words) Adobe has urged ColdFusion customers to patch their instances immediately after at least one maximum severity flaw was reported as being exploited by attackers. The software giant released patches for 11 CVEs on June 30 in the APSB26-68 bulletin. Six of these were…...
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
2+ mon, 1+ week ago (430+ words) A new cyber threat group linked to the Iranian government has been targeting Israeli government and IT organizations since early 2026, according to Check Point Research. The group, tracked by the Tel Aviv-headquartered cybersecurity firm as ‘Cavern Manticore,’ shares technical overlaps…...
Researcher Explains Release of Undisclosed Zero-Day Exploits
2+ mon, 1+ week ago (1052+ words) A pseudonymous security researcher has released over 30 proof-of-concept exploits for zero-day vulnerabilities in open-source projects without disclosing them to the maintainers first. The dump, called ‘Exploitarium,’ was shared publicly on GitHub by an individual going by name ‘bikini’ and ‘ashdfrkl…...
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
2+ mon, 1+ week ago (418+ words) A critical authentication bypass in SimpleHelp's remote monitoring and management (RMM) software has been exploited to deliver two previously unseen malware families, after attackers forged a login token to seize control of a managed network. New analysis from security firm…...
Cisco Vulnerability Exploited Months Before Disclosure, Google Warns
2+ mon, 2+ week ago (550+ words) A threat actor started exploiting a severe vulnerability in Cisco products at least two months before the flaw was disclosed, a new Google report warned. Tracked as CVE-2026-20245, this high-severity (CVSS 7.8) privilege escalation vulnerability stems from insufficient validation of user-supplied…...