Infosecurity News

  1. ICS Operators Warned of AI-Driven Attacks on Siemens PLCs

    A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs

  2. Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

    Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan

  3. Def Con Attendees Targeted by Persistent Phishing Campaign

    Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con

  4. Exclusive: Linux Foundation's Akrites to Go Live in September

    The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects

  5. MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

    eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra

  6. Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

    Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections

  7. OpenAI Tightens AI Safeguards Following Hugging Face Incident

    OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities

  8. Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware

    The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter

  9. ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts

    The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations

  10. UK Fraud Cases Hit Record High in 2026

    Cifas data finds account takeover and identity fraud are driving a surge in fraud cases

  11. Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

    The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

  12. Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

    Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds

  13. NASA Ground Control Software Flaw Enables Unauthenticated Commands

    Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

  14. Cyber Incident Disrupts Student Services at UT San Antonio

    UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume

  15. Three-quarters of Ransomware Attacks Target Mid-Market Firms

    Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit

  16. UK Legal Regulator Raises AI Misuse Concerns

    Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks

  17. UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

    UNISOC modem flaw enabled kernel-level code execution through video calls

  18. WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

    Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts

  19. ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

    The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act

  20. SafePal Data Breach Hits Tens of Thousands of Customers

    Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach

What’s Hot on Infosecurity Magazine?