Infosecurity News

  1. Average Cyber Insurance Losses Increase Despite Fewer Claims

    Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US

  2. Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

    This new open standard offers hardware-attested runtime and compliance evidence for AI agents

  3. DDoS Attack Hits Norwegian Government Services

    A coordinated DDoS campaign has caused disruption among Norwegian government services

  4. ZeroTokens Phishing Platform Steers Attacks in Real Time

    ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands

  5. Fake Recruiter Scams Target Corporate Credentials on Mobile

    RecruitTrap campaigns use mobile-optimized phishing pages to target enterprise credentials

  6. Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

    Australian officials are urging TeamCity customers to patch an actively exploited critical flaw, which follows a similar warning from the US government

  7. Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

    A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July

  8. ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

    ReliaQuest has detailed a social engineering attack linked to ShinyHunters, denying reports that the threat actor successfully compromised its systems

  9. US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

    The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute

  10. New Guidance Helps Businesses Verify Quantum-Safe Hardware Claims

    TCG has released new guidance to help proving that trusted platform modules genuinely meet essential quantum-safe requirements

  11. NIST Warns of Unique Security Risks in Multi-Cloud Environments

    NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

  12. Fake Codex Download Uses Google Sites to Deliver macOS Malware

    Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users

  13. Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

    Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

  14. Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

    Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure

  15. Researchers Uncover Thousands of Leaked AWS Keys

    Truffle Security says it found over 9000 publicly accessible and active AWS key pairs

  16. North Korean Hackers Tied to Rust Supply Chain Attack

    Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks

  17. New Agent Tesla Malware Variant Boosts Evasion Capabilities

    An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed

  18. Cybersecurity Job Ads Requiring AI Skills Double

    An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI

  19. NCSC Urges Stronger Controls for Agentic AI Systems

    NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents

  20. US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate

    Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

What’s Hot on Infosecurity Magazine?