Infosecurity News

  1. Cryptominer Abuses Linux PAM to Hide From SOC Analysts

    Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

  2. AiTM Phishing Becomes Top Initial Access Threat to Law Firms

    AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats

  3. AI and Automation Fall Short of Sysadmin Expectations

    Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago

  4. Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

    Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure

  5. Google Releases Patches for 370 Vulnerabilities in Chrome 151

    The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws

  6. NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices

    The UK’s National Cyber Security Centre wants network device makers to improve forensic observability

  7. LogoKit Phishing Kit Screenshots Victim Sites in Real Time

    LogoKit now builds per-victim phishing pages using live screenshots of the target's real website

  8. Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

    TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging

  9. The Average Cost of a Data Breach Rises to $5 Million

    IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role

  10. Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows

    For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said

  11. Researchers Warn of AI-Enhanced Phone Fraud Ecosystem

    AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns

  12. NCSC Publishes Guidance to Aid Incident Response and Recovery

    The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery

  13. Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard

    Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it

  14. AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched

    AI-assisted research uncovered Linux kernel use-after-free allowing root escalation

  15. Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

    Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise

  16. Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats

    Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model

  17. Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach

    Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack

  18. NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names

    NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”

  19. New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

    CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage

  20. SourTrade Malvertising Campaign Secretly Builds Malware in the Browser

    Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims

What’s Hot on Infosecurity Magazine?