Infosecurity News

  1. Hidden Backdoor Found in ATM Network via Raspberry Pi

    A covert ATM attack used a Raspberry Pi to breach bank systems, employing stealthy malware and anti-forensics techniques

  2. Google to Publicly Report New Vulnerabilities Within One Week of Vendor Disclosure

    Google’s Project Zero team will provide limited details of new vulnerabilities early following discovery, in a bid to speed up end users’ patching

  3. Third of Exploited Vulnerabilities Weaponized Within a Day of Disclosure

    32.1% of vulnerabilities listed in VulnCheck’s Known Exploited Vulnerabilities catalog were weaponized before being detected or within the following day

  4. Data Breach Costs Fall for First Time in Five Years

    IBM found that the global average cost of a data breach has fallen by 9% compared to 2024, driven by improved detection and containment

  5. US Tops Hit List as 396 SharePoint Systems Compromised Globally

    A total of 396 compromised Microsoft SharePoint systems have been identified globally, affecting 145 organizations across 41 countries in the wake of the ToolShell zero-day vulnerability

  6. OWASP Launches Agentic AI Security Guidance

    The comprehensive guidance focuses on technical recommendations for securing agentic AI applications, from development to deployment

  7. French Telco Orange Hit by Cyber-Attack

    Some of Orange’s professional and consumer services may be disrupted for a few days because of the cyber incident

  8. Critical Authentication Flaw Identified in Base44 Vibe Coding Platform

    Flaw in Base44 allowed unauthorized access to private apps, bypassing authentication systems

  9. Auto-Color Backdoor Malware Exploits SAP Vulnerability

    Backdoor malware Auto-Color targets Linux systems, exploiting SAP NetWeaver flaw CVE-2025-31324

  10. CISA Warns of Exploited Critical Vulnerabilities in Cisco Identity Services Engine

    Hackers are actively exploiting two critical flaws in Cisco Identity Services Engine, said the US Cybersecurity and Infrastructure Security Agency

  11. FBI Seizes $2.4m in Crypto from Chaos Ransomware Gang

    The federal government has applied for forfeiture of the funds, which were seized by FBI Dallas in April 2025

  12. Charity Fined After Destroying “Irreplaceable” Records

    A Scottish charity has been fined £18,000 for systematic data protection failings

  13. Pro-Ukraine Hacktivists Ground Dozens of Aeroflot Flights

    Two pro-Ukraine hacktivists have claimed responsibility for a destructive attack on Aeroflot

  14. Critical Flaws in WordPress Plugin Leave 10,000 Sites Vulnerable

    10,000 WordPress sites vulnerable to takeover due to critical flaws in HT Contact Form Widget plugin

  15. New Scattered Spider Tactics Target VMware vSphere Environments

    Scattered Spider has targeted VMware vSphere environments, exploiting retail, airline and insurance sectors

  16. Third-Party Breach Impacts Majority of Allianz Life US Customers

    Insurance firm Allianz Life said that a threat actor accessed personally identifiable information of the majority of its 1.4 million US customers

  17. Naval Group Denies Hack Claims, Alleges "Reputational Attack"

    Despite claims by a hacker, French defense company Naval Group has detected no intrusions into its IT environments at the time of writing

  18. US Woman Gets Eight Years for Part in $17m North Korean Scheme

    Arizonan woman sentenced to 102 months for operating laptop farm for North Korean IT workers

  19. Dating App Breach Exposes Images of 13,000 Women

    Dating app Tea has been compromised by a hacker, resulting in the exposure of 13,000 selfies

  20. BlackSuit Ransomware Group’s Dark Web Sites Seized in Operation Checkmate

    The US and partners from nine countries have taken down part of the ransomware group’s infrastructure

What’s hot on Infosecurity Magazine?