Infosecurity News

Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds

NASA Ground Control Software Flaw Enables Unauthenticated Commands
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume

Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit

UK Legal Regulator Raises AI Misuse Concerns
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
UNISOC modem flaw enabled kernel-level code execution through video calls

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act

SafePal Data Breach Hits Tens of Thousands of Customers
Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach

Infostealers Harvest 1.7 Billion Credentials in Six Months
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026

Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data

Researchers Link 'Jewelbug' Chinese APT to Hack-for-Hire Operations
Threat intelligence researchers from Broadcom revealed that a known Chinese APT group may be linked to a lucrative crypto fraud operation

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
CRM provider Beacon has revealed that a compromised AWS access key was the likely root cause of the breach of 1500 UK charities’ data

Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone
Google Cloud has set a 2027 deadline to mitigate store-now-decrypt-later risks as part of its post-quantum cryptography roadmap, with wider migration goals extending through 2028

vCenter Flaw Exploited Just Five Days After Disclosure
Attackers exploited a critical-severity vCenter flaw five days after Broadcom disclosed it

Trump Authorizes Private Sector Participation in Offensive Cyber Operations
The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attribution risks

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort

ICO Reprimands Criminal Records Office After 2023 Breach
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach



