Infosecurity News

  1. Critical Flaw in Multiple Atlassian Products Exploited in the Wild

    A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck

  2. Europol and US GAO Sound the Alarm Over Quantum Threats

    Europol and US Government Accountability Office urge faster transition to post-quantum cryptography

  3. FBI and Secret Service Warn of FortiBleed Lockout Threat

    The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted

  4. OT Coalition Urges CISA to Mandate Federal OT Security

    OTCC urged CISA to mandate baseline security requirements for federal operational technology

  5. Attackers Hide AI Prompt Injections Inside Phishing Emails

    Barracuda finds phishing emails designed to manipulate both human users and AI assistants

  6. Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading

    A Group-IB researcher has found the Telegram account linked to the unauthorized ASOS customer notification previously engaged in gaming-item trading

  7. Half of Cybersecurity Pros Still Rely on Passwords Despite Security Concerns

    A Yubico survey identified a significant gap between awareness and adoption of secure methods of authentication in enterprises

  8. Pwn2Own Hackers Find 32 Zero-Day Vulnerabilities on Day One

    Ethical hackers have already found 32 zero days in various products at Pwn2Own Ireland

  9. Danish CPR Breach Highlights Challenge of Supply Chain Risk

    A breach of 8.8 million citizens on the Danish Central Register of Persons (CPR) occurred via third-party access

  10. ClickFix Attack Hides VBScript Payload in Browser Cache

    ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit

  11. Nikkei Discloses Two Employee Cloud Account Compromises

    Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails

  12. Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities

    The IBM subsidiary has also announced its Lightwell Clearinghouse is now available to all customers

  13. Critical Medical Devices Unable to Support PQC Transition

    Forescout found that just 6% of Internet of Medical Things (IoMT) and 16% of medical OT are capable of supporting post quantum cryptography

  14. ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise

    ASOS customers have received a seemingly legitimate push notifications claiming the retailer’s IT systems have been breached through a Snowflake breach

  15. Police Urge Passkey Use After Surge in Cybercrime Profits

    Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually

  16. Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds

    An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims

  17. ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes

    ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices

  18. New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic

    Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan

  19. Citrix NetScaler Targeted Via New Zero Day

    The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government

  20. Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports

    Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions

What’s Hot on Infosecurity Magazine?