Infosecurity News

Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list

ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
A new npm worm has compromised packages with over two billion monthly installs

Frontier Models Engage in Unsanctioned Behavior During Testing
Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests

Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems

WhatsApp Scam Hijacks Accounts via Linked Devices Feature
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims

Cloud and SaaS Environments Now Top Targets for Attackers
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks

AI Accounts for Over Half of Cybercrime in Africa, Says Interpol
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling

UK’s Police National Legal Database Reveals Data Breach
The UK’s Police National Legal Database and Ask the Police service have been breached

China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure

Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens

HollowFrame Loader Uses Fake Python DLL to Evade Defender
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions

Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise

Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations

AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Anthropic has revealed that Claude AI models compromised third-party organizations

Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats

AI and Automation Fall Short of Sysadmin Expectations
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago



