Infosecurity News

  1. MantaxOtax Android Malware Combines Ransomware With Spyware

    MantaxOtax Android malware combines ransomware with extensive spyware capabilities

  2. FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

    The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors

  3. Anthropic Reveals Yet Another Cybersecurity Incident

    Anthropic has found a fourth case of its model accessing third-party systems without authorization

  4. OFAC Sanctions Chinese Scam Platform Xinbi Guarantee

    The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee

  5. Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

    The hacking tool, built using a combination of AI models, is effective against Android and iOS devices

  6. Gigabud Uses Android App Cloning to Evade Fraud Detection

    Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud

  7. ClickFix Moves into the Browser to Steal Cryptocurrency

    ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency

  8. NHIs Now the Number One Corporate Entry Point for Hackers

    SpyCloud claims non-human identities are the most likely route into the enterprise

  9. Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

    The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates

  10. SAP Patches Maximum Severity “Overpass” Flaw

    Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0

  11. France Establishes New Government-Focused Cyber Incident Response Unit

    After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability

  12. Grindr Settles UK Data Privacy Claims for £26m

    Grindr settled UK claims over alleged unlawful processing of sensitive user data

  13. AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

    Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks

  14. THost9 Android RAT Pairs Packed Loader With ADB Worm

    THost9 hides its payload and uses ADB to spread across exposed Android devices and containers

  15. BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

    CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365

  16. Trezor Supply Chain Breach Now Impacts 81,000 Customers

    Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought

  17. NCSC Warns Shadow AI Creates New Security Risks

    NCSC warns unapproved AI tools can expose corporate data and create new security risks

  18. N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

    The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself

  19. Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

    The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans

  20. North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

    Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion

What’s Hot on Infosecurity Magazine?