Infosecurity News

Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
The IBM subsidiary has also announced its Lightwell Clearinghouse is now available to all customers

Critical Medical Devices Unable to Support PQC Transition
Forescout found that just 6% of Internet of Medical Things (IoMT) and 16% of medical OT are capable of supporting post quantum cryptography

ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
ASOS customers have received a seemingly legitimate push notifications claiming the retailer’s IT systems have been breached through a Snowflake breach

Police Urge Passkey Use After Surge in Cybercrime Profits
Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually

Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims

ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices

New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan

Citrix NetScaler Targeted Via New Zero Day
The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government

Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports
Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions

More UK Schools Are Recovering Faster from Cyber Incidents
Ofqual study finds growing number of UK schools are bouncing back “immediately” from cyber-attacks

Frontline Education Breach Impacts K-12 School District Staff
A breach at school software provider Frontline Education has exposed employee data

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks

Police Target KillSec Ransomware Group with Arrests and Seizures
Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects

Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges

China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts

CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor

AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
PwC finds global security leaders are most concerned about attacks on AI systems

MI5 Warns Over 100 Academics Helped China's Espionage Plans
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute

AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise



