Infosecurity News

Russian Hacker Turns Jailbroken Claude Into Pentest Platform
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models

A New Ransomware Threat Actor Emerges Every Week, Warns Report
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented

FBI Warns of Deepfake Videos Impersonating IC3 Leadership
FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites

US Hospital Finance Software Provider Craneware Reports Data Theft
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans

Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra crypter used process ghosting and 90 custom ciphers to hide payloads for multiple actors

JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts

Researchers Build WordPress Exploit Using OpenAI's GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel

Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders

Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services

23andMe Faces New Security Mandates in $18m Data Breach Settlement
23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements

CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities

The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape

Phishing Campaign Hides Lua Loader as TrueType Font File
Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers

Modular macOS Stealer Uses Kill Loops to Force Password Entry
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password

Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers

"Selfish Bravado" Behind TfL Cyber-Attack, Judge Says as Pair Jailed
The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences

SANS Warns of AI Governance Gap as Use by Security Teams Surges
SANS Institute says governance programs are still nascent even as AI failures and threats grow

US Launches Gold Eagle to Coordinate AI-Driven Vulnerability Management
The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI



