Infosecurity News

  1. New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

    Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic

  2. Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

    CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance

  3. ShinyHunters Claim Hack of Rival Ransomware Gang Clop

    ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data

  4. Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

    A breach at image-sharing service Gyazo on September 11 affected over 23 million customers

  5. Revolut Customers Targeted with New Wave of Phishing Attacks

    Following a major data breach, Revolut customers are being sent convincing phishing messages

  6. New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

    Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks

  7. CISA Upgrades Vulnerability Reporting Platform with More Automation

    The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT

  8. Manufacturing Accounts for 22% of all Ransomware Victims

    Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026

  9. FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    ESET said FamousSparrow has replaced SparrowDoor with SparroWocky

  10. CISA Urges Critical Infrastructure to Plant Decoys Inside Networks

    CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks

  11. New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

    Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities

  12. Cyber Essentials Has Record Year but Takeup Remains Low

    New government figures reveal a 20% annual increase in certifications

  13. Cisco Warns of Active Exploitation of Critical ISE Flaw

    Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation

  14. AI Agent Carries Out Multi-Stage Data Theft Attack

    Spanish data protection agency AEPD reveals the country’s first AI-powered data breach

  15. PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

  16. CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

    CISA and NIST issued final guidance to help protect cloud identity tokens and assertions

  17. Cyber-Attacks Cost Organizations $52,000 on Average

    Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000

  18. Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT researchers find two zero-days in TP-Link cameras

  19. Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

    A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program

  20. NCSC and Allies Warn of Iranian Spyware Campaign

    The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents

What’s Hot on Infosecurity Magazine?