Infosecurity News

  1. Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds

    Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data security

  2. Cline Kanban Flaw Lets Websites Hijack AI Coding Agents

    Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack

  3. OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos

    Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers

  4. Fake Claude AI Site Drops Beagle Backdoor on Windows Users

    Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading

  5. Daemon Tools Developer Confirms Software Was Trojanized

    A China-linked threat actor backdoored a version of Daemon Tools to infect thousands

  6. Researchers Spot Uptick in Use of Vercel for Phishing Campaigns

    Cofense has warned of a “significant” increase in phishing campaigns abusing Vercel platform

  7. CloudZ Malware Abuses Phone Link to Steal SMS OTPs

    Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs

  8. CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack

    CISA’s CI Fortify initiative aim for critical infrastructure operators to build isolation & recovery

  9. Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign

    Rapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attack

  10. One in Eight Workers Has Sold Their Corporate Logins

    Cifas says that 13% of employees admit selling company credentials to a former colleague

  11. Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails

    Microsoft researchers warn of a large-scale phishing campaign using fake compliance emails to steal credentials, targeting 35,000 users across 13,000 organizations worldwide

  12. North Korean APT Targets Yanbian Gamers via Trojanized Platform

    ESET warns that North Korean hackers compromised a Yanbian gaming site in a supply‑chain attack, trojanizing Windows and Android software to spy on users

  13. Fake SSA Emails Drive Venomous#Helper Phishing Campaign

    Venomous#Helper attackers impersonate the US Social Security Administration to deploy signed RMM software and maintain persistent access across US networks

  14. AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk

    ISACA report warns that while AI has become the norm, many organizations are yet to formally apply safety or security policies around its use

  15. NCSC Warns of an AI-Fuelled “Vulnerability Patch Wave”

    The UK's National Cyber Security Centre is urging organizations to prepare for glut of new software updates

  16. Trellix Reveals Unauthorized Access to Source Code

    Security vendor Trellix has suffered a breach involving unauthorized access

  17. Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says

    Team Cymru’s Stephen Campbell warned that small US defense contractors are not well prepared to face cyber intrusions through edge devices

  18. OpenAI To Extend Cyber Program to Government Agencies

    OpenAI announced its intention to expand the Trusted Access for Cyber program for cyber defenders at the federal, state and local government levels

  19. Anthropic Rolls Out Claude Security for AI Vulnerability Scanning

    Claude Security enters public beta, giving enterprises AI driven code scanning with no API integration or custom agents required

  20. Two American Cybersecurity Workers Jailed for BlackCat Ransomware Attacks

    The cybersecurity workers used their knowledge and skills to conduct ransomware attacks for notorious gang, rather than protect victims against them

What’s Hot on Infosecurity Magazine?