Infosecurity News

  1. AI Agents Now the Enterprises Fastest Growing Exposed Attack Surface

    Sophos report warns that the rapid adoption of AI by businesses is leaving them vulnerable to a new source of cyber threats

  2. New Dolphin X Stealer Employs AI Profiling to Prioritize Targets

    Dolphin X is a new infostealer that uses AI to sort and rank victims, giving cybercriminals a faster way to identify lucrative targets

  3. Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness

    A new study of organizations which have fallen victim to ransomware suggests the rise of AI-tools being used by hackers is making life harder for defenders

  4. TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

    New TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern

  5. Open AI Claims Its AI Models Went Rogue and Hacked Another Company

    Hugging Face recently disclosed a security breach. OpenAI has now said that it was its AI models which broke containment and hacked Hugging Face themselves

  6. Ubuntu snap-confine Vulnerability Enables Local Root Access

    New Ubuntu snap-confine race condition lets local users escalate to root on default installs

  7. Google Makes CodeMender Available as Managed AI Security Agent

    CodeMender actively builds and runs exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable

  8. Russian Hacker Turns Jailbroken Claude Into Pentest Platform

    Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models

  9. A New Ransomware Threat Actor Emerges Every Week, Warns Report

    Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented

  10. FBI Warns of Deepfake Videos Impersonating IC3 Leadership

    FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites

  11. US Hospital Finance Software Provider Craneware Reports Data Theft

    Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft

  12. Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

    In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans

  13. Cruciferra Crypter Uses Process Ghosting to Evade Detection

    Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors

  14. JadePuffer Returns With Ransomware Designed to Wipe AI Models

    JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts

  15. Researchers Build WordPress Exploit Using OpenAI's GPT

    A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain

  16. New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

    Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel

  17. Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders

    Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders

  18. Government Agencies Falling Victim to Ransomware Daily, Warns Study

    Government organizations are targeted by attackers who know agencies cannot afford disruption to public services

  19. 23andMe Faces New Security Mandates in $18m Data Breach Settlement

    23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements

  20. CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

    US government agencies have until July 19 to patch two critical Fortinet vulnerabilities

What’s Hot on Infosecurity Magazine?