Infosecurity News

  1. Most Cybersecurity Staff Don’t Know How Fast They Could Stop a Cyber-Attack on AI Systems

    ISACA survey found that confusion over responsibility and lack of understanding around AI cyber-attacks makes containing them difficult

  2. Tycoon2FA Phishing Service Resumes Activity Post-Takedown

    Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA

  3. High-Tech Sector Overtakes Finance as Top Target for Cyber-Attacks, Mandiant Reports

    High tech was the most frequently targeted industry in Mandiant investigations in 2025, overtaking financial services which led in 2023 and 2024

  4. Trivy Supply Chain Attack Expands With New Compromised Docker Images

    New Trivy Docker images 0.69.5 and 0.69.6 compromised with TeamPCP infostealer, impacting CI/CD scans

  5. CISA Orders US Government to Patch Maximum Severity Cisco Flaw

    CISA added CVE-2026-20131 to its KEV catalog as it is being used in ransomware campaigns

  6. Operation Alice Takes Down 370,000+ Dark Web Sites

    German-led policing effort against fraud operation disrupts countless CSAM and cybercrime sites

  7. Hackers Exploit Critical Langflow Bug in Just 20 Hours

    Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day

  8. NCA Boss Warns That Teens Are Being “Radicalized” Into Cybercrime Online

    The National Crime Agency’s director general warns that technology is rapidly reshaping crime

  9. Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation

    Hastalamuerte leaks The Gentlemen RaaS ops: FortiGate exploits, BYOVD evasion, Qilin split tactics

  10. Financial Brands Targeted in Global Mobile Banking Malware Surge

    Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices

  11. FCA Updates Cyber Incident and Third-Party Reporting Rules

    The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer

  12. AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January

    Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says

  13. UK: Regulation Drives Cyber Spending for Critical Infrastructure Orgs

    35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs

  14. New Ubuntu Flaw Enables Local Attackers to Gain Root Access

    CVE-2026-3888 Ubuntu snap flaw lets local users escalate to root via timing-based exploit

  15. Crypto Scam "ShieldGuard" Dismantled After Malware Discovery

    ShieldGuard Chrome extension posed as a crypto security tool but stole wallets and drained user data

  16. AI-Enabled Adversaries Compress Time-to-Exploit Following Vulnerability Disclosure

    Rapid7 says median time from publication to CISA KEV inclusion dropped to five days

  17. Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats

    The Vidar 2.0 infostealers is deployed through fake free game cheats on GitHub and Reddit

  18. AI Issues Will Drive Half of Incident Response Efforts by 2028, Says Gartner

    Gartner has urged security teams to get involved in AI projects from the start to avoid costly incident response

  19. Android OS-Level Attack Bypasses Mobile Payment Security

    Android’s LSPosed-based attack hijacks payment apps via runtime manipulation and SIM-binding bypass

  20. 'CursorJack’ Attack Path Exposes Code Execution Risk in AI Development Environment

    CursorJack shows how malicious MCP deeplinks in Cursor IDE can trigger user-approved code execution

What’s Hot on Infosecurity Magazine?