Infosecurity News

  1. FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    ESET said FamousSparrow has replaced SparrowDoor with SparroWocky

  2. CISA Urges Critical Infrastructure to Plant Decoys Inside Networks

    CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks

  3. New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

    Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities

  4. Cyber Essentials Has Record Year but Takeup Remains Low

    New government figures reveal a 20% annual increase in certifications

  5. Cisco Warns of Active Exploitation of Critical ISE Flaw

    Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation

  6. AI Agent Carries Out Multi-Stage Data Theft Attack

    Spanish data protection agency AEPD reveals the country’s first AI-powered data breach

  7. PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

  8. CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

    CISA and NIST issued final guidance to help protect cloud identity tokens and assertions

  9. Cyber-Attacks Cost Organizations $52,000 on Average

    Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000

  10. Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT researchers find two zero-days in TP-Link cameras

  11. Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

    A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program

  12. NCSC and Allies Warn of Iranian Spyware Campaign

    The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents

  13. Most Fraudulent Hires Receive Credentials Before Detection

    A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations

  14. Most Firms Unable to Recover Quickly from Ransomware

    Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours

  15. Black Axe Members Extradited to US Over Internet Fraud Claims

    Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims

  16. AI the Top Priority for New Spend as Cyber Budgets Flatline

    IANS finds AI is dominating net-new budgets even as overall funding for the function is flat

  17. Microsoft Releases Emergency Patch to Fix RDS Vulnerability

    Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday

  18. Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

    Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service

  19. Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

    A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds

  20. Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

    MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military

What’s Hot on Infosecurity Magazine?