Infosecurity News

  1. Bloody Wolf Threat Actor Expands Activity Across Central Asia

    A new Bloody Wolf campaign exploits legitimate remote-administration software for cyber-attacks on government targets in Central Asia

  2. Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack

    Almost two million people may have seen their personal data exposed following a large-scale cyberattack that hit Asahi in September 2025

  3. OpenAI Warns of Mixpanel Data Breach Impacting API Users

    The breach may have exposed OpenAI API customers’ data

  4. Fraud Fears But No Breach Spike Expected This Festive Season

    Analysis of ICO records shows no surge in breaches during Q4 2024 with no seasonal spike in reported incidents

  5. Scattered Lapsus$ Hunters Take Aim At Zendesk Users

    New phishing domains point to a campaign from the notorious Scattered Lapsus$ Hunters collective

  6. Key Provisions of the UK Cyber Resilience Bill Revealed

    Shona Lester, head of the Cyber Security and Resilience Bill team within the UK government, outlined some of the provisions that should be included in the future law

  7. Cyber-Attack Disrupts OnSolve CodeRED Emergency Notification System

    A cyber-attack claimed to be the resposibility of INC Ransom group and targeting the OnSolve CodeRED platform has disrupted emergency notification and exposed user data across the US

  8. UK Report Proposes Liability For Software Provider Insecurity

    A new report from the UK Business and Trade Committee has called for accountability of software providers for cyber flaws amid rising attack costs

  9. FBI Warns of $262M Losses from Account Takeover Fraud in 2025

    The FBI reports over $262m in losses from account takeover schemes since January 2025, as cybercriminals impersonate financial institutions to steal data and funds

  10. Gainsight Cyber-Attack Affects More Salesforce Customers

    The CEO of the customer support platform said “a handful of customers” saw their data exposed after the breach

  11. HashJack Indirect Prompt Injection Weaponizes Websites

    A new vulnerability dubbed “HashJack” could enable attackers to booby trap websites when they interact with AI browsers

  12. London Councils Hit By Serious Cyber “Incidents”

    At least three London local authorities are dealing with a major cybersecurity incident

  13. Smishing Triad Impersonation Campaigns Expand Globally

    A cluster of fraudulent domains impersonating Egyptian providers have been identified linked to Smishing Triad operations

  14. New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

    A new macOS malware chain using staged scripts and a Go-based backdoor has been attributed to FlexibleFerret, designed to steal credentials and maintain system access

  15. AI and Deepfake-Powered Fraud Skyrockets Amid Identity Fraud Stagnation

    In its latest annual identity fraud report, Sumsub observed a “sophistication shift” in global fraud trends

  16. Mounting Cyber-Threats Prompt Calls For Economic Security Bill

    MPs in the UK want a new economic security regime to tackle cyber and related threats

  17. New Shai-Hulud Worm Spells Trouble For npm Users

    A new version of the Shai-Hulud worm has infected hundreds of npm packages and caused disruption to global CI/CD workflows

  18. Flaws Expose Risks in Fluent Bit Logging Agent

    Critical flaws in Fluent Bit threaten telemetry across platforms according to an advisory published by Oligo Security researchers

  19. Russian-linked Malware Campaign Hides in Blender 3D Files

    Morphisec has observed a new operation embedding StealC V2 malware in Blender project files, targeting users via 3D assets and launching a multi-stage infection chain

  20. CISA Urges Patch of Actively Exploited Flaw in Oracle Identity Manager

    The US cybersecurity agency has added the critical flaw to its Known Exploited Vulnerabilities list

What’s Hot on Infosecurity Magazine?