Infosecurity News

  1. macOS Backdoor Uses Prompt Injection to Evade AI Triage

    SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools

  2. KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

    Customers of the affected Japanese email services are “strongly advised” to change their email passwords

  3. Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

    An NCC Group report warns state-backed hackers are attempting to hide activity by posing as ransomware groups and deploying commercially available malware

  4. AI Is Making Attacks Cheaper, Faster and More Covert, Says ReliaQuest

    New ReliaQuest study reveals the six ways AI is practically being used in attacks today

  5. UK Museums Face Cybersecurity Risks, MPs Warn

    Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber

  6. Lookalike npm Package Hides a Multi-Stage Windows RAT

    JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT

  7. OpenAI Expands Daybreak to Help Defenders Patch Flaws

    OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws

  8. Trump Issues Executive Order to Fast-Track Post-Quantum Migration

    All US federal agencies will have to complete their post-quantum cryptography transition by 2031, according to a new Trump Executive Order

  9. GTA 6 Scams Emerge as Pre-Orders Open

    Cybercriminals launch fake GTA 6 pre-order sites offering early access for crypto payments

  10. Scattered Spider Teens Convicted of TfL Cyber-Attack

    Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plot

  11. Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats

    The Five Eyes Alliance has published a rare call to action for organizations facing AI threats

  12. GentleKiller Framework Disables Victims' Security Software

    ESET details GentleKiller, the EDR-killer framework the Gentlemen ransomware gang gives affiliates

  13. Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips

    Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices

  14. Microsoft Attributes Mastra AI Supply Chain Attack to North Korea

    North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers

  15. Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens

    At least four cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integration

  16. UK Information Commissioner Resigns After Workplace Investigation

    The UK’s data protection regulator the information commissioner has resigned after his position became “untenable”

  17. NCSC Urges Fortinet Customers to Tackle FortiBleed Fallout

    The NCSC has released guidance for Fortinet customers impacted by the FortiBleed threat campaign

  18. AWS Unveils 'Continuum,' an AI-Powered Vulnerability Management Platform

    Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities

  19. Operation Endgame Disrupts Malware Network Linked to Major Ransomware Gang

    SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers

  20. Confidence Lacks in Threat Detection Across Non-Email Channels like Slack and Teams

    Half of cybersecurity leaders lack confidence in detecting threats on Slack, Teams and other non-email platforms, despite growing attacker focus

What’s Hot on Infosecurity Magazine?