Infosecurity News

  1. AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks

    AWS has linked North Korea to the axios campaign to other attacks on npm libraries

  2. Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

    Anthropic has revealed that Claude AI models compromised third-party organizations

  3. Cryptominer Abuses Linux PAM to Hide From SOC Analysts

    Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

  4. AiTM Phishing Becomes Top Initial Access Threat to Law Firms

    AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats

  5. AI and Automation Fall Short of Sysadmin Expectations

    Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago

  6. Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

    Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure

  7. Google Releases Patches for 370 Vulnerabilities in Chrome 151

    The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws

  8. NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices

    The UK’s National Cyber Security Centre wants network device makers to improve forensic observability

  9. LogoKit Phishing Kit Screenshots Victim Sites in Real Time

    LogoKit now builds per-victim phishing pages using live screenshots of the target's real website

  10. Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

    TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging

  11. The Average Cost of a Data Breach Rises to $5 Million

    IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role

  12. Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows

    For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said

  13. Researchers Warn of AI-Enhanced Phone Fraud Ecosystem

    AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns

  14. NCSC Publishes Guidance to Aid Incident Response and Recovery

    The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery

  15. Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard

    Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it

  16. AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched

    AI-assisted research uncovered Linux kernel use-after-free allowing root escalation

  17. Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

    Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise

  18. Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats

    Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model

  19. Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach

    Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack

  20. NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names

    NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”

What’s Hot on Infosecurity Magazine?