Infosecurity News

  1. Wikimedia Says Rogue AI Agents Abused its Platforms

    Wikimedia says OpenAI agents performed unauthorized actions on its platforms, including edits to wikis

  2. Q3 2026 Sets New Record for Ransomware Attacks

    Comparitech observed 2627 claimed ransomware attacks in Q3, with critical sectors like finance, technology, education and healthcare experiencing significant increases

  3. UK and Allies Warn of Cyber Threat from China’s Integrity Technology Group

    The UK, US and allies have issued an alert detailing malicious activity linked to China’s Integrity Technology Group

  4. AI Training Critical as Governance Challenges Grow

    As AI adoption accelerates, ISACA is expanding its certification portfolio with a governance-focused credential designed to help professionals manage AI securely

  5. Major AI Firms Pledge Data Protection Changes Following UK Privacy Watchdog Push

    Ten leading AI firms have committed to make data protection improvements following a call for evidence by the UK’s Information Commissioner's Office

  6. Attackers Hijack Three ccTLDs to Obtain Google Certificates

    Attackers compromised .gh, .sl and .as registries to obtain unauthorized HTTPS certificates

  7. ASOS Confirms Data Breach Linked to Stolen Employee Credentials

    The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers

  8. Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware

    Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024

  9. Chinese Hacker Deployed AI in Campaign Against South Korean Banks

    CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms

  10. Critical Flaw in Multiple Atlassian Products Exploited in the Wild

    A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck

  11. Europol and US Spending Watchdog Sound the Alarm Over Quantum Threats

    Europol and US Government Accountability Office urge faster transition to post-quantum cryptography

  12. FBI and Secret Service Warn of FortiBleed Lockout Threat

    The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted

  13. OT Coalition Urges CISA to Mandate Federal OT Security

    OTCC urged CISA to mandate baseline security requirements for federal operational technology

  14. Attackers Hide AI Prompt Injections Inside Phishing Emails

    Barracuda finds phishing emails designed to manipulate both human users and AI assistants

  15. Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading

    A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged in gaming-item trading

  16. Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns

    A Yubico survey identified a significant gap between awareness and adoption of secure methods of authentication in enterprises

  17. Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One

    Ethical hackers have already found 32 zero days in various products at Pwn2Own Ireland

  18. Danish CPR Breach Highlights Challenge of Supply Chain Risk

    A breach of 8.8 million citizens on the Danish Central Register of Persons (CPR) occurred via third-party access

  19. ClickFix Attack Hides VBScript Payload in Browser Cache

    ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit

  20. Nikkei Discloses Two Employee Cloud Account Compromises

    Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails

What’s Hot on Infosecurity Magazine?