Infosecurity News

Attackers Hijack Three ccTLDs to Obtain Google Certificates
Attackers compromised .gh, .sl and .as registries to obtain unauthorized HTTPS certificates

ASOS Confirms Data Breach Linked to Stolen Employee Credentials
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers

Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024

Chinese Hacker Deployed AI in Campaign Against South Korean Banks
CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms

Critical Flaw in Multiple Atlassian Products Exploited in the Wild
A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck

Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography

FBI and Secret Service Warn of FortiBleed Lockout Threat
The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted

OT Coalition Urges CISA to Mandate Federal OT Security
OTCC urged CISA to mandate baseline security requirements for federal operational technology

Attackers Hide AI Prompt Injections Inside Phishing Emails
Barracuda finds phishing emails designed to manipulate both human users and AI assistants

Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading
A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged in gaming-item trading

Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns
A Yubico survey identified a significant gap between awareness and adoption of secure methods of authentication in enterprises

Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One
Ethical hackers have already found 32 zero days in various products at Pwn2Own Ireland

Danish CPR Breach Highlights Challenge of Supply Chain Risk
A breach of 8.8 million citizens on the Danish Central Register of Persons (CPR) occurred via third-party access

ClickFix Attack Hides VBScript Payload in Browser Cache
ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit

Nikkei Discloses Two Employee Cloud Account Compromises
Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails

Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
The IBM subsidiary has also announced its Lightwell Clearinghouse is now available to all customers

Critical Medical Devices Unable to Support PQC Transition
Forescout found that just 6% of Internet of Medical Things (IoMT) and 16% of medical OT are capable of supporting post quantum cryptography

ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
ASOS customers have received a seemingly legitimate push notifications claiming the retailer’s IT systems have been breached through a Snowflake breach

Police Urge Passkey Use After Surge in Cybercrime Profits
Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually

Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims



