top of page
Search


Infy Hackers Resume Operations with New C2 Servers After Iran Internet Blackout Ends
The elusive Iranian threat group known as Infy (aka Prince of Persia) has evolved its tactics as part of efforts to hide its tracks, even as it readied new command-and-control (C2) infrastructure coinciding with the end of the widespread internet blackout the regime imposed at the start of January 2026. "The threat actor stopped maintaining its C2 servers on January 8 for the first time since we began monitoring their activities," Tomer Bar, vice president of security resea
Feb 4


Organizations Warned of Exploited Linux Vulnerabilities
An attacker can exploit the bug by sending crafted Telnet commands to set the USER variable, bypass authentication, and obtain a root shell, gaining remote code execution (RCE) on vulnerable systems, SafeBreach explains . Read more.
Jan 26


Security Breach: Shiny Objects and the Power of Preparation
"You don't have to get hacked to understand how you can get hacked." - Itzik Kotler, the co-founder and CTO of SafeBreach Find out more.
Jan 7


Increased sophistication showcased by reemergent Prince of Persia APT
HackRead reports Iranian advanced persistent threat operation Prince of Persia, also known as Infy, has reemerged with expanded targeting and a more sophisticated attack arsenal almost three years after it went on hiatus. Despite continuing to harness the Foudre and Tonnerre malware pair, Prince of Persia has gone to update the former, which has been launched upon Foudre's discovery of high-value targets, according to a SafeBreach analysis. Read more.
Dec 18, 2025


Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations
SafeBreach analysts identified this renewed activity after a three-year dormant period, noting the group’s transition to more resilient operational security practices. Their research highlighted the group’s use of distinct malware families, Foudre and Tonnerre, which now feature advanced capabilities for persistence and data theft. The investigation also linked the operation to a specific persona, “Ehsan,” suggesting a centralized and human-operated management of the campaig
Dec 18, 2025


Cyberattacks by Iranian Nation-State APTs Targeting Vital Infrastructure
Researchers at SafeBreach Labs have uncovered fresh activity from the Iranian state-sponsored hacking group known as “Prince of Persia” (also referred to as “Infy”), revealing that the threat actor has been silently operating sophisticated malware campaigns since resurfacing in 2025 after a three-year hiatus. Read more.
Dec 18, 2025


Quick Share’s Security Leap: Android’s File-Sharing Shield
In the ever-evolving landscape of mobile technology, Google’s Quick Share is poised for a significant security upgrade. According to recent reports, the file-sharing feature could soon integrate with Android’s Advanced Protection Program, potentially revolutionizing how users safeguard their data during transfers. This development comes amid growing concerns over unauthorized access and file theft in an increasingly connected world. The rumor, first highlighted by Android Aut
Oct 27, 2025


Vulnerability in Windows RPC protocol: Spoofing and impersonation attacks reported
SafeBreach experts have disclosed details of a vulnerability in the Windows Remote Procedure Call (RPC) protocol, patched by Microsoft in the July 2025 update. The flaw, CVE-2025-49760 , allowed an attacker to conduct spoofing attacks and impersonate a legitimate server using the Windows storage mechanism. Ron Ben Yizak discussed the discovery at the DEF CON 33 conference. Read more.
Sep 20, 2025


New Win-DoS Flaws Could Weaponize Windows Domain Controllers for DDoS Attacks
A newly discovered attack method could allow hackers to crash public Windows domain controllers (DCs) worldwide and weaponize them for...
Aug 10, 2025


Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home
For likely the first time ever, security researchers from Safebreach have shown how AI can be hacked to create real-world havoc, allowing...
Aug 5, 2025


Safebreach research shows Google Calendar invites let researchers hijack Gemini to leak user data
By sending a calendar invite with an embedded prompt injection, often hidden in the event title, attackers can potentially exfiltrate...
Aug 3, 2025


*NEW* SAFEBREACH PROPAGATE
Gain Visibility Beyond the Breach Augment your breach and attack simulation (BAS) deployment with automated attack path validation...
Apr 30, 2025


SafeBreach leverages Visa Threat Intelligence for payment fraud prevention
SafeBreach, a breach and attack simulations company, has expanded its collaboration with Visa to leverage the company’s Threat...
Apr 10, 2025


Google Released Second Fix for Quick Share Flaws After Patch Bypass
The patches Google rolled out last year to address vulnerabilities in the Quick Share data transfer utility that could lead to remote...
Apr 2, 2025


SafeBreach launches enhanced MSSP program
The program provides a clear framework for partners to establish consistent client engagement expectations, ensuring successful...
Mar 25, 2025


Safebreach launches platform for enterprise cyber risk view
SafeBreach has unveiled a new platform aimed at providing a comprehensive view of cyber risk in enterprise environments. The newly...
Feb 1, 2025


Unpatched Active Directory Flaw Can Crash Any Microsoft Server
One of two critical Active Directory Domain Controller vulnerabilities patched by Microsoft last month goes beyond the original...
Jan 1, 2025


This Windows Update exploit is downright terrifying
Windows Update may occasionally backfire with faulty patches , but for the most part, it’s meant to keep us safe from the latest threats....
Aug 10, 2024


Design flaw could allow hackers to roll back Microsoft Windows updates
Some of Microsoft’s most important tools for protecting Windows users from malicious hackers can be twisted into being used in attacks,...
Aug 6, 2024


Researchers claim Windows Defender can be fooled into deleting databases
Researchers at US/Israeli infosec outfit SafeBreach last Friday discussed flaws in Microsoft and Kaspersky security products that can...
Apr 21, 2024
bottom of page
