Infosecurity News

  1. Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT researchers find two zero-days in TP-Link cameras

  2. Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

    A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program

  3. NCSC and Allies Warn of Iranian Spyware Campaign

    The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents

  4. Most Fraudulent Hires Receive Credentials Before Detection

    A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations

  5. Most Firms Unable to Recover Quickly from Ransomware

    Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours

  6. Black Axe Members Extradited to US Over Internet Fraud Claims

    Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims

  7. AI the Top Priority for New Spend as Cyber Budgets Flatline

    IANS finds AI is dominating net-new budgets even as overall funding for the function is flat

  8. Microsoft Releases Emergency Patch to Fix RDS Vulnerability

    Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday

  9. Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

    Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service

  10. Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

    A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds

  11. Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

    MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military

  12. Revolut Confirms Data Breach Through Fake Government Requests

    An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data

  13. Hackers Exploit Maximum Severity Flaw in GitLab

    CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

  14. OpenAI Agent Swarm Hacks RubyGems Package Manager

    Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems

  15. Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

    KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails

  16. Most Organizations Skip Permissions Reviews Before Deploying AI Tools

    A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so

  17. CISA Updates Insider Threat Guide With New Mitigation Advice

    CISA has updated its insider threat guide with new advice on remote work, AI and risk detection

  18. MantaxOtax Android Malware Combines Ransomware With Spyware

    MantaxOtax Android malware combines ransomware with extensive spyware capabilities

  19. FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

    The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors

  20. Anthropic Reveals Yet Another Cybersecurity Incident

    Anthropic has found a fourth case of its model accessing third-party systems without authorization

What’s Hot on Infosecurity Magazine?