Infosecurity News

  1. Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk

    The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration

  2. CISA Unveils Election Security Plan Ahead of 2026 Midterms

    The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines

  3. RemControl Banking Trojan Gives Attackers Remote Control of Android Devices

    The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials

  4. Researchers Identify AliExpress Phishing Domains Before Registration

    EfficientIP says it flagged AliExpress phishing domains before they were registered

  5. Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims

    Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims

  6. CISA Charts New "Quality Era" for Global CVE Program

    CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise

  7. UK Government Shifts to Service-Led Cyber Governance After Stinging Audit

    Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy

  8. OpenAI Agent Hacks Australian Medicare Portal

    Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026

  9. Over 75% of Organizations Experience Microsoft 365 Governance Issues

    ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows

  10. Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds

    SANS Institute report claims data rather than skills is now the main hurdle for threat hunters

  11. Hundreds of Leaked GitHub App Keys Still Authenticate

    GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access

  12. Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods

    Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying

  13. Ransomware Attacks Reach Record High for 2026

    A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data

  14. ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

    Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees

  15. EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response

    The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents

  16. North Korean Attackers Hit 30,000 Devices and Steal $10.7m

    WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets

  17. AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds

    A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure

  18. Network Segmentation Failures Are Expanding the Corporate Attack Surface

    Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks

  19. AI Drives Surge in Bot and API Threats

    Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats

  20. CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

    Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect

What’s Hot on Infosecurity Magazine?