Infosecurity News

  1. LNER Reveals Supply Chain Attack Compromised Customer Information

    Government-run train operator LNER has revealed details of a supplier data breach

  2. KillSec Ransomware Hits Brazilian Healthcare IT Vendor

    A ransomware attack by KillSec on Brazil software provider MedicSolution threatens healthcare, impacting providers and patients

  3. Cursor Autorun Flaw Lets Repositories Execute Code Without Consent

    A flaw in the Cursor extension allows unauthorized code execution when opening repositories in Visual Studio

  4. Adobe Releases Emergency Patch for Critical Flaw in Commerce and Magento

    The vulnerability, dubbed SessionReaper, allows customer account takeover and unauthenticated remote code execution

  5. Ransomware Payments Plummet in Education Amid Enhanced Resiliency

    Sophos found that average ransom demands and payments fell substantially in the education sector in 2025, as recovery time and costs fell

  6. Two Zero-Days Among Patch Tuesday CVEs This Month

    Microsoft has fixed over 80 vulnerabilities including two publicly disclosed zero-days in its latest Patch Tuesday release

  7. Malicious npm Code Reached 10% of Cloud Environments

    Wiz Security warns that a recently discovered supply chain attack campaign targeting npm is far from over

  8. Threat Actor Accidentally Exposes AI-Powered Operations

    A threat actor accidentally revealed their AI-powered methods by installing Huntress security software

  9. Salty2FA Phishing Kit Unveils New Level of Sophistication

    Salty2FA phishing campaign showcases advanced techniques and professionalism of cybercrime operations

  10. Open Source Community Thwarts Massive npm Supply Chain Attack

    What could have been a historic supply chain attack seems to have been averted due to the rapid response of the open source community

  11. Axios User Agent Helps Automate Phishing on “Unprecedented Scale”

    ReliaQuest warns that phishing campaigns abusing the Axios user agent have surged 241% in three months

  12. Chinese Cyber Espionage Campaign Impersonates US Congressman

    A House select committee said Chinese actors impersonated Representative John Moolenaar to steal information that could be used to influence trade talks

  13. Salesloft: GitHub Account Breach Was Ground Zero in Drift Campaign

    Salesloft has revealed that threat actors targeted customer Salesforce data after breaching its GitHub account

  14. Wealthsimple Confirms Data Breach After Supply Chain Attack

    Wealthsimple confirmed a third-party vendor data breach affecting roughly 30,000 customers

  15. MostereRAT Targets Windows Users With Stealth Tactics

    Phishing campaign unveiled MostereRAT, targeting Windows systems with advanced evasion techniques

  16. Remote Access Abuse Biggest Pre-Ransomware Indicator

    Cisco Talos found that abuse of remote services and remote access software are the most prevalent ‘pre-ransomware’ tactics deployed by threat actors

  17. Qualys, Tenable Latest Victims of Salesloft Drift Hack

    Palo Alto Networks, Cloudflare and Zscaler were also among confirmed victims of the attack

  18. GhostAction Supply Chain Attack Compromises 3000+ Secrets

    Security researchers have discovered a new malicious campaign impacting hundreds of GitHub users

  19. SAP S/4HANA Users Urged to Patch Critical Exploited Bug

    Critical SAP S/4HANA vulnerability CVE-2025-42957 is being exploited in the wild

  20. Bridgestone Confirms "Limited Cyber Incident" Impacting Facilities in North America

    Bridgestone Americas confirmed the incident but has not detailed the scope of the attack

What’s Hot on Infosecurity Magazine?