Infosecurity News

  1. Most Organizations Now Use AI Agents for Sensitive Security Tasks

    Semperis study finds 74% of organizations believe AI will increase attacks on identity infrastructure

  2. ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks

    The Information Commissioner’s Office has released new guidance on how to mitigate the risk of AI-powered attacks

  3. Canvas Owner Reaches Agreement With Cybercriminals After Ransomware Attack

    Instructure says it reached an agreement with ShinyHunters over the Canvas breach data

  4. Avada Builder Flaws Expose One Million WordPress Sites

    Avada Builder flaws allowed file read and SQL injection on one million WordPress sites

  5. Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers

    Survey of cybersecurity leaders suggests that majority would strongly consider paying cybercriminals, if that’s what it took to help restore encrypted systems

  6. Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks

    The G7 Cybersecurity Working Group releases new SBOM for AI guidance, outlining seven key data clusters to boost transparency and security across AI supply chains

  7. UK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security Firms

    UK cybersecurity sector reaches £14.7bn in revenue, driven by rapid growth in AI security firms, increased investment and rising employment across the industry

  8. Microsoft Fixes 17 Critical Flaws in May Patch Tuesday

    Microsoft has patched 120 vulnerabilities in this month’s security update round

  9. OpenAI Launches 'Daybreak' to Help Build Secure By Design Software

    With Daybreak, OpenAI wants its frontier AI models to be used to deploy secure by design software from the ground up

  10. Mini Shai-Hulud Hits TanStack npm Packages

    Mini Shai-Hulud compromises TanStack npm packages and spreads across PyPI

  11. End‑to‑End Encrypted RCS Messaging Arrives Across iPhone and Android

    Apple begins rolling out end-to-end encrypted RCS messaging between iPhone and Android in iOS 26.5

  12. Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence

    Exploitation of open-source tools allows attackers to maintain persistent access after initial social engineering, warn ReliaQuest researchers

  13. Malicious Hugging Face Repository Typosquats OpenAI

    HiddenLayer reveals infostealer malware in a Hugging Face repository

  14. South Staffordshire Water Fined £1m After Data Breach

    The ICO has fined South Staffordshire Water nearly £1m for a series of data protection failings

  15. TrickMo Variant Routes Android Trojan Traffic Through TON

    ThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open Network

  16. Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities

    Two new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributions

  17. Fake Claude Code Page Pushes PowerShell Stealer at Devs

    Ontinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2

  18. Hackers Observed Using AI to Develop Zero-Day for the First Time

    Google Threat Intelligence Group details how cybercriminals attempted to launch a campaign based around an AI-developed Zero-Day targeting open-source software

  19. US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates

    The same extension applies to security updates shipped to US-based users of foreign-made drones

  20. ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign

    ShinyHunters has escalated its Canvas extortion campaign, defacing hundreds of school login pages and threatening to leak stolen data unless institutions negotiate

What’s Hot on Infosecurity Magazine?