Infosecurity News

Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging

The Average Cost of a Data Breach Rises to $5 Million
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role

Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said

Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns

NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it

AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation

Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise

Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model

Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack

NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims

Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against

Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign

ChatGPT Among Top 10 Most Impersonated Brands in Phishing Attacks, Says Check Point
OpenAI’s chatbot tool ChatGPT ranked among the top 10 most impersonated brands in phishing attacks for the first time

Ransomware Attacks Targeting Universities on the Rise
Comparitech’s analysis of incidents in the first half of 2026 finds that the emergence of The Gentlemen ransomware has resulted in surge in attacks against higher education

Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite

Microsoft Copilot Deployments Delayed Over Security Concerns
CoreView research finds that security leadership is concerned about AI Assistant exposing confidential data

Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
US government agencies have warned that Iranian cyber actors are targeting US-based Siemens and Schneider industrial equipment



