Infosecurity News

  1. UK Report Proposes Liability For Software Provider Insecurity

    A new report from the UK Business and Trade Committee has called for accountability of software providers for cyber flaws amid rising attack costs

  2. FBI Warns of $262M Losses from Account Takeover Fraud in 2025

    The FBI reports over $262m in losses from account takeover schemes since January 2025, as cybercriminals impersonate financial institutions to steal data and funds

  3. Gainsight Cyber-Attack Affect More Salesforce Customers

    The CEO of the customer support platform said “a handful of customers” saw their data exposed after the breach

  4. HashJack Indirect Prompt Injection Weaponizes Websites

    A new vulnerability dubbed “HashJack” could enable attackers to booby trap websites when they interact with AI browsers

  5. London Councils Hit By Serious Cyber “Incidents”

    At least three London local authorities are dealing with a major cybersecurity incident

  6. Smishing Triad Impersonation Campaigns Expand Globally

    A cluster of fraudulent domains impersonating Egyptian providers have been identified linked to Smishing Triad operations

  7. New FlexibleFerret Malware Chain Targets macOS With Go Backdoor

    A new macOS malware chain using staged scripts and a Go-based backdoor has been attributed to FlexibleFerret, designed to steal credentials and maintain system access

  8. AI and Deepfake-Powered Fraud Skyrockets Amid Identity Fraud Stagnation

    In its latest annual identity fraud report, Sumsub observed a “sophistication shift” in global fraud trends

  9. Mounting Cyber-Threats Prompt Calls For Economic Security Bill

    MPs in the UK want a new economic security regime to tackle cyber and related threats

  10. New Shai-Hulud Worm Spells Trouble For npm Users

    A new version of the Shai-Hulud worm has infected hundreds of npm packages and caused disruption to global CI/CD workflows

  11. Flaws Expose Risks in Fluent Bit Logging Agent

    Critical flaws in Fluent Bit threaten telemetry across platforms according to an advisory published by Oligo Security researchers

  12. Russian-linked Malware Campaign Hides in Blender 3D Files

    Morphisec has observed a new operation embedding StealC V2 malware in Blender project files, targeting users via 3D assets and launching a multi-stage infection chain

  13. CISA Urges Patch of Actively Exploited Flaw in Oracle Identity Manager

    The US cybersecurity agency has added the critical flaw to its Known Exploited Vulnerabilities list

  14. Iberia Airlines Notifies Customers of Supply Chain Data Breach

    Spanish airline Iberia has begun emailing its customers about a supplier data breach

  15. MoD Launches World’s First Military Gaming Tournament

    The International Defence Esports Games (IDEG) will help sharpen cyber and battlefield skills for allied soldiers

  16. Cybercriminals Exploit Browser Push Notifications to Deliver Malware

    Researchers at BlackFrog have uncovered Matrix Push C2, a malicious command-and-control system that abuses web browser push notifications to deliver malware

  17. New Gainsight Supply Chain Hack Could Affect Salesforce Customers

    Salesforce believes there has been unauthorized access to its customers’ data through the Gainsight app’s connection to its platform

  18. UNC2891 Money Mule Network Reveals Full Scope of ATM Fraud Operation

    A multi-year ATM fraud campaign by UNC2891 targeted two Indonesian banks, cloning cards, recruiting money mules and coordinating cash withdrawals

  19. CISA Issues New Guidance on Bulletproof Hosting Threat

    CISA launches guide to combat cybercrime via bulletproof hosting, recommending measures for ISPs

  20. Supply Chain Breaches Impact Almost All Firms Globally, BlueVoyant Reveals

    Despite a growing maturity of third-party risk management programs, supply chain attacks impacted more organizations in 2025 than in previous years

What’s Hot on Infosecurity Magazine?