Infosecurity News

  1. Notepad++ Update Hijacking Linked to Hosting Provider Compromise

    A supply chain attack on Notepad++ update process was linked to compromised hosting infrastructure

  2. Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks

    Russia-linked hacking group Fancy Bear is exploiting a brand-new vulnerability in Microsoft Office, CERT-UA says

  3. Android RAT Uses Hugging Face to Host Malware

    Bitdefender has discovered a new Android malware campaign that uses Hugging Face

  4. Former Google Engineer Found Guilty of Stealing AI Secrets

    Linwei Ding, a former Google engineer, has been found guilty of stealing trade secrets for China

  5. Labyrinth Chollima Evolves into Three North Korean Hacking Groups

    CrowdStrike assessed that two new threat actor groups have spun off from North Korean Labyrinth Chollima hackers

  6. New AI-Developed Malware Campaign Targets Iranian Protests

    The RedKitten campaign distributes lures designed to target people seeking information about missing persons or political dissidents in Iran

  7. National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat

    Cyber fraudsters targeting corporate finance departments costs businesses millions a year

  8. Google Disrupts Extensive Residential Proxy Networks

    Google has taken coordinated action against the massive IPIDEA residential proxy network, enhancing customer protections and disrupting cybercrime operations

  9. Operation Winter SHIELD: FBI Issues Call to Arms for Organizations to Improve Cybersecurity

    The FBI outlines ten actions which organizations can take to defend networks against cybercriminal and nation-state threats

  10. France Fines National Employment Agency €5m Over 2024 Data Breach

    The French data protection regulator said that France Travail’s response to a 2024 data breach violated GDPR

  11. New CISA Guidance Targets Insider Threat Risks

    CISA urges action against insider threats with publication of a new infographic offering strategies to manage risks

  12. FBI Takes Down RAMP Ransomware Forum

    The dark web forum administrator confirmed the takedown and said they had “no plans to rebuild”

  13. Ransomware Victim Numbers Rise, Despite Drop in Active Extortion Groups

    Ransomware victims surged in Q4 2025 despite fewer active extortion groups, with data leaks rising 50%, ReliaQuest researchers report

  14. US Data Breaches Hit Record High but Victim Numbers Decline

    Non-profit ITRC says the number of data breaches increased 5% annually to reach a record total in 2025

  15. Number of Cybersecurity Pros Surges 194% in Four Years

    Cybersecurity is now the fifth fastest-growing occupation in the UK, says Socura

  16. Cybersecurity Teams Embrace AI, Just Not at the Scale Marketing Suggests

    Despite the seemingly widespread adoption of AI for security operations, security leaders primarily use it for “relatively basic use cases,” said a Sumo Logic study

  17. Autonomous System Uncovers Long-Standing OpenSSL Flaws

    A recent update has fixed 12 vulnerabilities in OpenSSL, some existing in the codebase for years

  18. Critical and High Severity n8n Sandbox Flaws Allow RCE

    Two critical security flaws in n8n have exposed sandboxing vulnerabilities, enabling remote code execution for attackers

  19. Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign

    Researchers discover that PureRAT’s code now contains emojis – indicating it has been written by AI based-on comments ripped from social media.

  20. AI Security Threats Loom as Enterprise Usage Jumps 91%

    Zscaler analysts found critical vulnerabilities in 100% of enterprise AI systems, with 90% compromised in under 90 minutes

What’s Hot on Infosecurity Magazine?