Infosecurity News

  1. Financial Brands Targeted in Global Mobile Banking Malware Surge

    Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices

  2. FCA Updates Cyber Incident and Third-Party Reporting Rules

    The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer

  3. AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January

    Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says

  4. UK: Regulation Drives Cyber Spending for Critical Infrastructure Orgs

    35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs

  5. New Ubuntu Flaw Enables Local Attackers to Gain Root Access

    CVE-2026-3888 Ubuntu snap flaw lets local users escalate to root via timing-based exploit

  6. Crypto Scam "ShieldGuard" Dismantled After Malware Discovery

    ShieldGuard Chrome extension posed as a crypto security tool but stole wallets and drained user data

  7. AI-Enabled Adversaries Compress Time-to-Exploit Following Vulnerability Disclosure

    Rapid7 says median time from publication to CISA KEV inclusion dropped to five days

  8. Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats

    The Vidar 2.0 infostealers is deployed through fake free game cheats on GitHub and Reddit

  9. AI Issues Will Drive Half of Incident Response Efforts by 2028, Says Gartner

    Gartner has urged security teams to get involved in AI projects from the start to avoid costly incident response

  10. Android OS-Level Attack Bypasses Mobile Payment Security

    Android’s LSPosed-based attack hijacks payment apps via runtime manipulation and SIM-binding bypass

  11. 'CursorJack’ Attack Path Exposes Code Execution Risk in AI Development Environment

    CursorJack shows how malicious MCP deeplinks in Cursor IDE can trigger user-approved code execution

  12. Surge in Nation State Attacks on UK Firms Amid Cyber Warfare Fears

    Armis reveals that “mutually assured disruption” is no longer preventing state-backed attacks

  13. Average Number of Daily API Attacks Up 113% Annually

    Akamai says 87% of organizations suffered an API-related security incident last year

  14. UK Cyber Monitoring Centre Sets Its Sights on US Expansion One Year After Launch

    The US Cyber Monitoring Center should be operational in 2027, said the UK CMC leadership

  15. Researchers Warn of Global Surge in Fake Shipment Tracking Scams

    Some of these campaigns are linked to Darcula, a Chinese-language phishing-as-a-service platform

  16. CrackArmor Flaws Expose Linux Systems to Privilege Escalation

    CrackArmor AppArmor flaws let local Linux users gain root, break containers and enable DoS attacks

  17. Security Flaw in AWS Bedrock Code Interpreter Raises Alarms

    DNS-based attack in AWS Bedrock AgentCore lets AI sandboxes exfiltrate cloud data

  18. FBI Calls for Help to Track Steam Malware Campaign

    The FBI wants to hear from gamers who have downloaded Steam titles containing malware

  19. UK: Companies House Web Glitch Exposes Corporate Details to Fraudsters

    An issue with the Companies House website has put the personal and corporate information of millions at risk

  20. Interpol's 'Operation Synergia III' Nets 94 Arrests in Major Cybercrime Sweep

    A new law enforcement operation against phishing and ransomware operators led to the takedown of 45,000 malicious IP addresses

What’s Hot on Infosecurity Magazine?