Infosecurity News

  1. AI Boosts SOC Analyst Capacity but Limits Skill Development

    Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer

  2. Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware

    Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google

  3. Apple Patches CoreGraphics Zero Day Exploited in Attacks

    Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine

  4. RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model

    RatHat's C2 panel now builds malware and ranks victims with AI across nearly 100 deployments

  5. Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials

    AWS AgentCore SDK flaws could let attackers run commands in AI sandboxes and reach AWS credentials

  6. Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

    Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries

  7. Japanese Railway Operators Hit with Weekend Cyber Attacks

    Tokyo Metro and Keio have revealed separate cyber-attacks

  8. Kiteworks Urges Customers to Restart Systems After Shutdown Notice

    Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence

  9. Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach

    Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets

  10. NVIDIA Launches Open Platform to Secure Autonomous AI Agents

    NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents

  11. Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns

    A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat

  12. MCP Is Creating Major Governance Gaps, Researchers Warn

    Ox Security found security shortcomings in analysis of over 15,000 MCP servers

  13. Citrix Patches Critical Zero Days Under Active Exploitation

    Citrix has confirmed exploitation of two critical zero-day RCE bugs

  14. Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk

    The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration

  15. CISA Unveils Election Security Plan Ahead of 2026 Midterms

    The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines

  16. RemControl Banking Trojan Gives Attackers Remote Control of Android Devices

    The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials

  17. Researchers Identify AliExpress Phishing Domains Before Registration

    EfficientIP says it flagged AliExpress phishing domains before they were registered

  18. Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims

    Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims

  19. CISA Charts New "Quality Era" for Global CVE Program

    CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise

  20. UK Government Shifts to Service-Led Cyber Governance After Stinging Audit

    Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy

What’s Hot on Infosecurity Magazine?