Infosecurity News

  1. Hundreds of Leaked GitHub App Keys Still Authenticate

    GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access

  2. Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods

    Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying

  3. Ransomware Attacks Reach Record High for 2026

    A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data

  4. ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

    Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees

  5. EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response

    The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents

  6. North Korean Attackers Hit 30,000 Devices and Steal $10.7m

    WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets

  7. AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds

    A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure

  8. Network Segmentation Failures Are Expanding the Corporate Attack Surface

    Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks

  9. AI Drives Surge in Bot and API Threats

    Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats

  10. CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

    Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect

  11. Google Hit with €403m GDPR Fine Over Location Data Practices

    The Irish DPC found that Google users were unaware that their location was being used to influence them with ads

  12. New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

    Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic

  13. Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

    CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance

  14. ShinyHunters Claim Hack of Rival Ransomware Gang Clop

    ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data

  15. Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

    A breach at image-sharing service Gyazo on September 11 affected over 23 million customers

  16. Revolut Customers Targeted with New Wave of Phishing Attacks

    Following a major data breach, Revolut customers are being sent convincing phishing messages

  17. New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

    Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks

  18. CISA Upgrades Vulnerability Reporting Platform with More Automation

    The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT

  19. Manufacturing Accounts for 22% of all Ransomware Victims

    Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026

  20. FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    ESET said FamousSparrow has replaced SparrowDoor with SparroWocky

What’s Hot on Infosecurity Magazine?