Infosecurity News

  1. ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

    The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act

  2. SafePal Data Breach Hits Tens of Thousands of Customers

    Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach

  3. Infostealers Harvest 1.7 Billion Credentials in Six Months

    Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026

  4. Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

    Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents

  5. New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

    Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

  6. Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

    AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data

  7. Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations

    Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation

  8. Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities

    CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data

  9. Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone

    Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028

  10. vCenter Flaw Exploited Just Five Days After Disclosure

    Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it

  11. Trump Authorizes Private Sector Participation in Offensive Cyber Operations

    The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risks

  12. Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

    Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort

  13. ICO Reprimands Criminal Records Office After 2023 Breach

    The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach

  14. WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

    New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call

  15. Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

    Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

  16. Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

    Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

  17. NIST Seeks Public Input on AI-Ready NVD Modernization

    The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research

  18. Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL

    The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country

  19. Microsoft Fixes 400 Flaws on August Patch Tuesday

    Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday

  20. Six npm Packages Read C2 Addresses From Ethereum Wallet

    Six npm packages queried an Ethereum wallet to locate C2 infrastructure

What’s Hot on Infosecurity Magazine?