Infosecurity News

  1. China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor

    A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT

  2. CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach

    The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents

  3. Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

    A high-severity flaw in Cisco Catalyst SD-WAN Manager disclosed in early June was exploited as early as March

  4. Twenty Million US IP Connections Used by Proxy Services

    Digital Citizens Alliance report claims that millions of Americans may have unwittingly had IP connections used by cybercriminals

  5. Trust in Automated AI Vulnerability Scanning Collapses to 9%, New Study Finds

    Cobalt study finds 20-percentage-point drop in number of organizations relying solely on AI automation for testing

  6. New CISA Guide Helps Agencies Adopt SASE For Zero Trust

    New CISA guidance shows federal agencies how to use SASE to move from legacy TIC 2.0 to zero trust

  7. macOS Flaw Lets Standard Users Disable EDR and MDM

    macos-xpc-flaw-disable-edr-mdm-standard-user-xm-cyber

  8. Major Increase in Ransomware Attacks Targeting Europe, Warns New Report

    Analysis of ransomware incidents by researchers at Black Kite found that attacks have risen by over 50% in the last year, with supply chain attacks increasing

  9. Researchers Trick AI Browsers Into Leaking Credentials

    LayerX tricked AI browsers including ChatGPT Atlas and Comet into bypassing their guardrails

  10. Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers

    Operation Endgame seized around 50 domains and nearly 200 active IP-based servers associated with the infostealers

  11. macOS Backdoor Uses Prompt Injection to Evade AI Triage

    SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools

  12. KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

    Customers of the affected Japanese email services are “strongly advised” to change their email passwords

  13. Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

    An NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malware

  14. AI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuest

    New ReliaQuest study reveals the six ways AI is practically being used in attacks today

  15. UK Museums Face Cybersecurity Risks, MPs Warn

    Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber

  16. Lookalike npm Package Hides a Multi-Stage Windows RAT

    JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT

  17. OpenAI Expands Daybreak to Help Defenders Patch Flaws

    OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws

  18. Trump Issues Executive Order to Fast-Track Post-Quantum Migration

    All US federal agencies will have to complete their post-quantum cryptography transition by 2031, according to a new Trump Executive Order

  19. GTA 6 Scams Emerge as Pre-Orders Open

    Cybercriminals launch fake GTA 6 pre-order sites offering early access for crypto payments

  20. Scattered Spider Teens Convicted of TfL Cyber-Attack

    Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plot

What’s Hot on Infosecurity Magazine?