Infosecurity News

  1. Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

    Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort

  2. ICO Reprimands Criminal Records Office After 2023 Breach

    The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach

  3. WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam

    New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call

  4. Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

    Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

  5. Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

    Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

  6. NIST Seeks Public Input on AI-Ready NVD Modernization

    The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research

  7. Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL

    The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country

  8. Microsoft Fixes 400 Flaws on August Patch Tuesday

    Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday

  9. Six npm Packages Read C2 Addresses From Ethereum Wallet

    Six npm packages queried an Ethereum wallet to locate C2 infrastructure

  10. Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification

    Cursor fixed a pre-trust code execution path in three days then closed the report as informative

  11. Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks

    Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week also

  12. OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber

    Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models

  13. Logistics Giant Ceva Suffers Data Breach Impacting European Clients

    Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius

  14. OpenAI Pauses Some Development of Astra Model on Security Concerns

    OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns

  15. Only Half of UK Manufacturers Have a Cyber Incident Response Plan

    Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents

  16. Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

    Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data

  17. WordPress Plugins Compromised Without a Single File Change

    Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files

  18. “Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls

    Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports

  19. Go-Based macOS Malware Steals Crypto and Secrets

    A macOS malware variant has been detected stealing crypto, passwords and more

  20. US Sanctions Iranian $6bn Crypto “Exchange” Shelbit

    TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange

What’s Hot on Infosecurity Magazine?