Infosecurity News

  1. Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

    A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages

  2. Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

    More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services

  3. Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations

    Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities

  4. Manchester Airports Group Hit by Cyber Incident

    Customer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorized third party

  5. Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns

    The FBI advisory set out QTFY’s distributed hacking ecosystem, allowing it to exploit vulnerabilities at scale and obfuscate its activities

  6. CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

    CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild

  7. Boston Scientific Reveals Global Disruption After Cyber Incident

    MedTech giant Boston Scientific has revealed IT outages following a cyber incident

  8. OpenAI: Hugging Face Incident a “Warning Shot” to the World

    OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach

  9. Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel

    Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool

  10. Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects

    Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries

  11. Four in Five AI Tools Run with No IT Oversight, New Research Finds

    Reco report reveals growing shadow AI problem and surge in vulnerability disclosures

  12. Average Cyber Insurance Losses Increase Despite Fewer Claims

    Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US

  13. Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

    This new open standard offers hardware-attested runtime and compliance evidence for AI agents

  14. DDoS Attack Hits Norwegian Government Services

    A coordinated DDoS campaign has caused disruption among Norwegian government services

  15. ZeroTokens Phishing Platform Steers Attacks in Real Time

    ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands

  16. Fake Recruiter Scams Target Corporate Credentials on Mobile

    RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials

  17. Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

    Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

  18. Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

    A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

  19. ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

    ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems

  20. US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

    The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute

What’s Hot on Infosecurity Magazine?