Infosecurity News

  1. Eternidade Stealer Trojan Fuels Aggressive Brazil Cybercrime

    Trustwave SpiderLabs has observed new banking Trojan Eternidade Stealer targeting Brazil using WhatsApp for propagation and data theft

  2. PlushDaemon Hackers Unleash New Malware in China-Aligned Spy Campaigns

    The cyber espionage group uses a previously undocumented network implant to drop two downloaders, LittleDaemon and DaemonLogistics, which deliver a backdoor

  3. China-Linked Operation “WrtHug” Hijacks Thousands of ASUS Routers

    SecurityScorecard has revealed a new Chinese campaign targeting thousands of ASUS routers globally

  4. Half of Ransomware Access Due to Hijacked VPN Credentials

    Beazley Security data finds the top cause of initial access for ransomware in Q3 was compromised VPN credentials

  5. CISA 2015 Receives Extension, Offering Brief Relief for Cyber Information Sharing

    One US cybersecurity leader described the short-term extension of the Cybersecurity Information Sharing Act as a “temporary patch” and called for a long-term solution

  6. New npm Malware Campaign Redirects Victims to Crypto Sites

    A new malware campaign has been observed built on seven npm packages and using cloaking techniques and fake CAPTCHAs, operated by threat actor dino_reborn

  7. AI-Enhanced Tuoni Framework Targets Major US Real Estate Firm

    A major US real estate firm has been targeted with an advanced intrusion attempt using Tuoni C2, combining social engineering, steganography and in-memory attacks

  8. DoorDash Confirms Data Breach Exposing Customer Personal Information

    DoorDash has confirmed an October 2025 data breach that exposed customer names, phone numbers, addresses and email details

  9. GenAI and Deepfakes Drive Digital Forgeries and Biometric Fraud

    Entrust says AI is helping fraudsters open new accounts and bypass biometric checks

  10. Half a Million Stolen FTSE 100 Credentials Found on Criminal Sites

    Socura finds 460,000 compromised credentials belonging to FTSE 100 company employees

  11. Kraken Uses Benchmarking to Enhance Ransomware Attacks

    Cisco Talos has observed overlaps between Kraken and the earlier HelloKitty cartel through attack tactics using SMB flaws for big-game hunting and double extortion

  12. Europol Leads Takedown of Thousands of Extremist Gaming Links

    Europol’s Referral Action Day removed extremist links across gaming and gaming-adjacent platforms, targeting radical content

  13. Cyber Readiness Stalls Despite Confidence in Incident Response

    New Immersive report finds cyber resilience and decision making are flatlining

  14. US: Five Plead Guilty in North Korean IT Worker Fraud Scheme

    The five defendants allegedly assisted North Korean hackers with obtaining remote IT employment with US companies

  15. Cyber-Attack Costs Carmaker JLR $258m in Q2

    Carmaker JLR has posted $639m Q2 losses and a one-off $258m hit after a major ransomware attack

  16. Chinese Hackers Automate Cyber-Attacks With AI-Powered Claude Code

    Anthropic’s Claude Code AI assistant performed 80% to 90% of the tasks involved in a recent cyber-attack campaign, said Anthropic researchers

  17. Akira Ransomware Haul Surpasses $244M in Illicit Proceeds

    Akira ransomware has extorted $244M since September 2025, with some attacks exfiltrating data in just two hours, a joint cybersecurity advisory warns

  18. Google Files Lawsuit to Dismantle 'Lighthouse' Smishing Kit

    Google filed a civil lawsuit against 25 individuals accused of ties to a Chinese cyber collective known as the ‘Smishing Triad’

  19. “IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages

    A new npm worm dubbed “IndonesianFoods” has doubled the number of known malicious packages

  20. CISO Pay Increases 7% As Budget Growth Slows

    An IANS study finds CISO compensation rose 6.7% on average in 2025 while budget growth halved compared to 2024

What’s Hot on Infosecurity Magazine?