Infosecurity News

  1. “Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls

    Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports

  2. Go-Based macOS Malware Steals Crypto and Secrets

    A macOS malware variant has been detected stealing crypto, passwords and more

  3. US Sanctions Iranian $6bn Crypto “Exchange” Shelbit

    TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange

  4. Healthcare and Victim Support Charities Affected by Beacon Cyber Incident

    Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor

  5. Google Links Redact Extortion Group to BlackFile Rebrand

    BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns

  6. Ransomware Surges in July After Q2 Lull

    Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

  7. Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

    Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database

  8. TeamPCP Traced Back to 2020 Cryptojacking Operation

    Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020

  9. Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident

    One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI systems

  10. Violent Physical Crypto Thefts Surge to $30m in Losses

    So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis

  11. Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign

    A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims

  12. NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing

    The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)

  13. Fake Open VSX Extensions Harvest Private Repo and CI Data

    77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity

  14. Paperclip AI Flaws Let Unauthenticated Attackers Run Commands

    3 Paperclip flaws exposed data & allowed unauthenticated command execution in two deployment modes

  15. Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents

    Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list

  16. ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs

    A new npm worm has compromised packages with over two billion monthly installs

  17. Frontier Models Engage in Unsanctioned Behavior During Testing

    Anthropic and OpenAI models attacked “real people and organizations” during AI Security Institute tests

  18. Fake Bank of America Phishing Scam Installs Remote Access Malware

    Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems

  19. WhatsApp Scam Hijacks Accounts via Linked Devices Feature

    WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords

  20. Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions

    Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims

What’s Hot on Infosecurity Magazine?