Infosecurity News

  1. UK Leads the Way with £15m AI Alignment Project

    The UK’s AI Security Institute has announced a new AI misalignment research program

  2. Android Malware Targets Banking Users Through Discord Channels

    The DoubleTrouble Android banking Trojan has evolved, using Discord for delivery and introducing several new features

  3. CISA Unveils Eviction Strategies Tool to Aid Incident Response

    CISA has launched a new tool to streamline cyber incident response and aid in adversary eviction

  4. Ransomware Attacks Escalate to Physical Threats Against Executives

    Semperis found that executives were physically threatened in 40% of ransomware incidents, in a bid to pressure victims to pay demands

  5. Cybercriminals ‘Spooked’ After Scattered Spider Arrests

    The arrest of members of the Scattered Spider cyber-attack group have temporarily halted new intrusions, however, similar threat actors continue to pose risks

  6. FunkSec Ransomware Victims Can Now Recover Files with Free Decryptor

    Avast researchers shared a step-by-step guide to decrypt files for victims of FunkSec ransomware

  7. Passwordless Future Years Away Despite Microsoft Authenticator Move

    Experts argue that password managers are still useful despite Microsoft Authenticator ditching its capabilities

  8. Over 200 Malicious Open Source Packages Traced to Lazarus Campaign

    North Korea’s Lazarus Group has been blamed for a cyber-espionage campaign using open source packages

  9. Hafnium Tied to Advanced Chinese Surveillance Tools

    A SentinelLabs report has revealed patents linked to firms aiding China's cyber-espionage operations, exposing new capabilities

  10. Hidden Backdoor Found in ATM Network via Raspberry Pi

    A covert ATM attack used a Raspberry Pi to breach bank systems, employing stealthy malware and anti-forensics techniques

  11. Google to Publicly Report New Vulnerabilities Within One Week of Vendor Disclosure

    Google’s Project Zero team will provide limited details of new vulnerabilities early following discovery, in a bid to speed up end users’ patching

  12. Third of Exploited Vulnerabilities Weaponized Within a Day of Disclosure

    32.1% of vulnerabilities listed in VulnCheck’s Known Exploited Vulnerabilities catalog were weaponized before being detected or within the following day

  13. Data Breach Costs Fall for First Time in Five Years

    IBM found that the global average cost of a data breach has fallen by 9% compared to 2024, driven by improved detection and containment

  14. US Tops Hit List as 396 SharePoint Systems Compromised Globally

    A total of 396 compromised Microsoft SharePoint systems have been identified globally, affecting 145 organizations across 41 countries in the wake of the ToolShell zero-day vulnerability

  15. OWASP Launches Agentic AI Security Guidance

    The comprehensive guidance focuses on technical recommendations for securing agentic AI applications, from development to deployment

  16. French Telco Orange Hit by Cyber-Attack

    Some of Orange’s professional and consumer services may be disrupted for a few days because of the cyber incident

  17. Critical Authentication Flaw Identified in Base44 Vibe Coding Platform

    Flaw in Base44 allowed unauthorized access to private apps, bypassing authentication systems

  18. Auto-Color Backdoor Malware Exploits SAP Vulnerability

    Backdoor malware Auto-Color targets Linux systems, exploiting SAP NetWeaver flaw CVE-2025-31324

  19. CISA Warns of Exploited Critical Vulnerabilities in Cisco Identity Services Engine

    Hackers are actively exploiting two critical flaws in Cisco Identity Services Engine, said the US Cybersecurity and Infrastructure Security Agency

  20. FBI Seizes $2.4m in Crypto from Chaos Ransomware Gang

    The federal government has applied for forfeiture of the funds, which were seized by FBI Dallas in April 2025

What’s Hot on Infosecurity Magazine?