Infosecurity News

  1. React.js Hit by Maximum-Severity 'React2Shell' Vulnerability

    A critical RCE flaw in React.js, dubbed React2Shell (CVE-2025-55182), has been disclosed with a maximum CVSS score of 10.0, posing severe risks for server-side implementations

  2. China-Linked Warp Panda Targets North American Firms in Espionage Campaign

    CrowdStrike warned that Warp Panda, a China-linked cyber-espionage group, is targeting US organizations to steal sensitive data and support Beijing’s strategic interests

  3. Louvre to Bolster Its Security, Issues €57m Public Tender

    The French museum is planning to revamp its safety and security systems following a high-profile burglary in October

  4. Predator Spyware Maker Intellexa Evades Sanctions, New Victims Identified

    Data leaks have shed a new light on Intellexa’s flagship spyware infrastructure and attack vectors

  5. CISA and International Partners Issue Guidance for Secure AI in Infrastructure

    Cybersecurity agencies have issued guidance for securely integrating AI into OT systems

  6. Cyber Agencies Push for Digital Trust Amid AI Era with New Provenance Report

    UK’s NCSC and Canada’s CCCS release a joint report on content provenance, urging organizations to strengthen digital trust and combat AI-driven misinformation

  7. New GhostFrame Phishing Framework Hits Over One Million Attacks

    The GhostFrame phishing framework, using stealthy iframes, was linked to over 1 million attacks

  8. Skills Shortages Trump Headcount as Critical Cyber Challenge

    ISC2 report reveals 59% of global organizations have critical or significant skills shortages

  9. Post Office Escapes £1m Fine After Postmaster Data Breach

    The Information Commissioner’s Office has chosen only to reprimand the Post Office after a 2024 breach

  10. French NGO Reporters Without Borders Targeted by Star Blizzard

    A fresh wave of spear-phishing linked to the Russia-based Star Blizzard group has been detected by Sekoia

  11. UK's Cyber Service for Telcos Blocks One Billion Malicious Site Attempts

    A new cyber defense service has prevented almost one billion early-stage cyber-attacks in the past year, British Security Minister claims

  12. Yearn Finance yETH Pool Hit by $9M Exploit

    A critical vulnerability in Yearn Finance's yETH pool allowed an attacker to steal around $9m

  13. UK Ransomware Payment Ban to Come with Exemptions, Security Minster Say

    The UK government’s proposed ransomware payment ban for public sector and critical infrastructure will come with national security exemptions

  14. Disinformation and Cyber-Threats Among Top Global Exec Concerns

    A new WEF report reveals that AI-powered threats like disinformation are among executives’ biggest concerns

  15. Pall Mall Process to Define Responsible Commercial Cyber Intrusion

    The Pall Mall Process begins outreach to define guidelines for private commercial intrusion industry

  16. Critical PickleScan Vulnerabilities Expose AI Model Supply Chains

    3 critical zero-day flaws in PickleScan, affecting Python and PyTorch, allowed undetected attacks

  17. ShadyPanda's Seven-Year Campaign Infects 4.3M Chrome and Edge Users

    Infected 4.3 million Chrome and Edge users via extensions; ShadyPanda exploited browser marketplaces

  18. Google Releases Patches for Android Zero-Day Flaws Exploited in the Wild

    Google said it found indications that two newly identified vulnerabilities affecting Android “may be under limited, targeted exploitation”

  19. ICO Set to Check If Mobile Games Comply with Children’s Code

    The UK Information Commissioner’s Office has launched an investigation into the mobile gaming sector

  20. Most Companies Fear State-Sponsored Cyber-Attacks and Want More Government Help

    New IO study claims 88% of US and UK firms are concerned about state-sponsored cyber-attacks

What’s Hot on Infosecurity Magazine?