Infosecurity News

  1. Urban VPN Proxy Accused of Harvesting AI Chat Conversations

    The browser extension Urban VPN Proxy has been reportedly collecting users’ AI chat conversations

  2. JumpCloud Windows Agent Flaw Enables Local Privilege Escalation

    A flaw in JumpCloud Remote Assist for Windows has exposed managed endpoints to local privilege escalation and denial-of-service attacks

  3. Amazon Warns Russian GRU Hackers Target Western Firms via Edge Devices

    Amazon researchers believe this campaign is part of a bigger operation spearheaded by Russia’s military intelligence service, the GRU

  4. Millions of Car Owners Hit By Credit700 Data Breach

    US financial services firm Credit700 has revealed a major data breach impacting 5.8 million people

  5. Phishing Messages and Social Scams Flood Users Ahead of Christmas

    Check Point has detected thousands of phishing emails in the past fortnight, offering fake promotions and special deals

  6. Third Defendant Pleads Guilty in Fantasy Sports Betting Hack Case

    A Minnesota man has pleaded guilty to a credential stuffing scheme that compromised over 60,000 accounts

  7. Russian Phishing Campaign Delivers Phantom Stealer Via ISO Files

    A new phishing campaign has been identified, delivering the Phantom information-stealing malware via an ISO attachment

  8. Asahi to Launch Cybersecurity Overhaul After Crippling Cyber-Attack

    Asahi Group’s CEO said he is considering creating a dedicated cyber unit following the ransomware attack that crippled the company

  9. Top 25 Most Dangerous Software Weaknesses of 2025 Revealed

    MITRE has released its Top 25 CWE list for 2025, compiled from software and hardware flaws behind almost 40,000 CVEs

  10. NCSC Playbook Embeds Cyber Essentials in Supply Chains

    The UK’s National Cyber Security Centre has called on businesses to apply Cyber Essentials to suppliers

  11. NCSC Plugs Gap in Cyber-Deception Guidance

    The National Cyber Security Centre has released new learnings from a cyber deception pilot

  12. ICO Fines LastPass £1.2m After 2022 Breach

    The UK’s data protection regulator has fined password manager provider LastPass £1.2m after 2022 data breach

  13. South Korean Police Raid Coupang Over Data Breach as CEO Resigns

    The Coupang South Korean unit's response will be spearheaded by an executive based in the US

  14. OpenAI Enhances Defensive Models to Mitigate Cyber-Threats

    OpenAI has reported a surge in performance as GPT-5.1-Codex-Max reaching 76% in capability assessments, and warned of upcoming cyber-risks

  15. Malware Discovered in 19 Visual Studio Code Extensions

    A new campaign involving 19 malicious Visual Studio Code extensions used a legitimate npm package to embed malware in dependency folders

  16. Scam-Busting FCA Firm Checker Tool Given Cautious Welcome

    Experts say a new Firm Checker tool from the FCA won’t move the dial on fraud but is a step in the right direction

  17. Google Releases Critical Chrome Security Update to Address Three Zero-Days

    Google has released a Chrome security update to fix three zero-day vulnerabilities, including a high-severity flaw with an active exploit

  18. “Cyber Tax” Warning as Two-Fifths of SMBs Raise Prices After Breach

    New ITRC research finds 81% of US small businesses suffered a data or security breach in the past year

  19. ClickFix Social Engineering Sparks Rise of CastleLoader Attacks

    A new malware campaign has been identified using a Python-based delivery system to deploy CastleLoader malware

  20. Pro-Russia Hackers Target US Critical Infrastructure in New Wave

    Pro-Russia hacktivist groups have been observed exploiting exposed virtual network computing connections to breach OT systems

What’s Hot on Infosecurity Magazine?