Infosecurity News

NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

Fake Codex Download Uses Google Sites to Deliver macOS Malware
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure

Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs

North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks

New Agent Tesla Malware Variant Boosts Evasion Capabilities
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed

Cybersecurity Job Ads Requiring AI Skills Double
An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI

NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan

Def Con Attendees Targeted by Persistent Phishing Campaign
Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con

Exclusive: Linux Foundation's Akrites to Go Live in September
The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections

OpenAI Tightens AI Safeguards Following Hugging Face Incident
OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter

ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts
The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations

UK Fraud Cases Hit Record High in 2026
Cifas data finds account takeover and identity fraud are driving a surge in fraud cases



