Infosecurity News

  1. New WordPress Malware Masquerades as Plugin

    New WordPress malware disguised as a plugin gives attackers persistent access and injects malicious code enabling administrative control

  2. Phorpiex Botnet Delivers LockBit Ransomware with Automated Tactics

    A new ransomware campaign is automating LockBit deployment via the Phorpiex botnet, according to Cybereason

  3. New Gremlin Infostealer Distributed on Telegram

    Administrators of a Telegram channel named CoderSharp have been advertising Gremlin Stealer since March 2025

  4. Infostealers Harvest Over 30,000 Australian Banking Credentials

    Dvuln researchers highlighted the growing impact of infostealers on the cybercrime landscape, enabling attackers to bypass traditional defenses

  5. Zero-Day Exploitation Figure Surges 19% in Two Years

    Google claims 19% more zero-day bugs were exploited in 2024 than 2022 as threat actors focus on security products

  6. Europol Creates “Violence-as-a-Service” Taskforce

    Europol has launched a new initiative designed to combat recruitment of youngsters into violent organized crime groups

  7. Uyghur Diaspora Group Targeted with Remote Surveillance Malware

    Members of the World Uyghur Congress living in exile were targeted with a spear phishing campaign deploying surveillance malware, according to the Citizen Lab

  8. Half of Mobile Devices Run Outdated Operating Systems

    50% of mobile devices run outdated operating systems, increasing vulnerability to cyber-attacks, according to the latest report from Zimperium

  9. Researchers Note 16.7% Increase in Automated Scanning Activity

    According to the 2025 Global Threat Landscape Report from FortiGuard, threat actors are executing 36,000 scans per second

  10. ISACA Highlights Critical Lack of Quantum Threat Mitigation Strategies

    An ISACA survey found that just 5% of organizations have a defined strategy to defend against quantum-enabled threats

  11. FBI Asks for Help Tracking Chinese Salt Typhoon Actors

    The US authorities have asked the public to help them unmask China’s Salt Typhoon threat actors

  12. Government Set to Ban SIM Farms in European First

    The UK government says it will ban the possession or supply of SIM farms, in a fraud crackdown

  13. Law Enforcement Crackdowns Drive Novel Ransomware Affiliate Schemes

    Increased law enforcement pressure has forced ransomware groups like DragonForce and Anubis to move away from traditional affiliate models

  14. SAP Fixes Critical Vulnerability After Evidence of Exploitation

    A maximum severity flaw affecting SAP NetWeaver has been exploited by threat actors

  15. M&S Shuts Down Online Orders Amid Ongoing Cyber Incident

    British retailer M&S continues to tackle a cyber incident with online orders now paused for customers

  16. Security Experts Flag Chrome Extension Using AI Engine to Act Without User Input

    Researchers have found a Chrome extension that can act on the user’s behalf by using a popular AI agent orchestration protocol

  17. US Data Breach Lawsuits Total $155M Amid Cybersecurity Failures

    Panaseer's latest cybersecurity study revealed that US companies have paid $155M in data breach lawsuit settlements over just six months

  18. Popular LLMs Found to Produce Vulnerable Code by Default

    Backslash Security found that naïve prompts resulted in code vulnerable to at least four of the of the 10 most common vulnerabilities across popular LLMs

  19. ELENOR-corp Ransomware Targets Healthcare Sector

    ELENOR-corp ransomware, a new version of Mimic, is targeting healthcare organizations using advanced capabilities

  20. Blue Shield of California Data Breach Affects 4.7 Million Members

    A misconfigured tracking tool has exposed protected health information of 4.7 million Blue Shield members to Google Ads

What’s hot on Infosecurity Magazine?