Infosecurity News

  1. Android Devices Targeted By KONNI APT in Find Hub Exploitation

    A new cyber-attack has been observed exploiting Google Find Hub to remotely wipe Android devices, linked to North Korean APTs

  2. Qilin Ransomware Activity Surges as Attacks Target Small Businesses

    Qilin group ransomware incidents have surged in SMBs, exploiting security gaps and collaborating with Scattered Spider threat group

  3. Hackers Exploit Critical Flaw in Gladinet's Triofox File Sharing Product

    Threat actors were exploiting vulnerable versions of Triofox after a patched version was released, said Google Cloud researchers

  4. CISA Adds Zero-Day Bug Used in Spyware Attacks to KEV

    CISA has demanded federal agencies patch a zero-day vulnerability affecting Samsung devices used in LandFall spyware attacks

  5. Quantum Route Redirect Phishing Kit Democratizes Cyber-Attacks

    KnowBe4 claims the new Quantum Route Redirect kit is supercharging phishing attacks on Microsoft365 users

  6. 65% of Leading AI Companies Found With Verified Secrets Leaks

    A new study has revealed 65% of top AI firms have leaked sensitive data on GitHub, risking $400bn in assets

  7. China-Aligned UTA0388 Uses AI Tools in Global Phishing Campaigns

    Volexity has linked spear phishing operations to China-aligned UTA0388 in new campaigns using advanced tactics and LLMs

  8. New NCA Campaign Warns Men Off Crypto Investment Scams

    The UK’s National Crime Agency is warning men under 45 that crypto dreams can soon become a scam nightmare

  9. NCSC Set to Retire Web Check and Mail Check Tools

    The UK’s National Cyber Security Centre has urged users of its Web Check and Mail Check services to find alternatives

  10. Russian Hacking Group Sandworm Deploys New Wiper Malware in Ukraine

    Sandworm deployed data wipers against Ukrainian governmental entities and companies in the energy, logistics and grain sectors

  11. “I Paid Twice” Phishing Campaign Targets Booking.com

    Experts have uncovered large-scale phishing exploiting Booking.com, Airbnb and Expedia accounts, targeting hotels and customers

  12. Multi-Turn Attacks Expose Weaknesses in Open-Weight LLM Models

    A new Cisco report exposed large language models to multi-turn adversarial attacks with 90% success rates

  13. Hacktivist-Driven DDoS Dominates Attacks on Public Sector

    ENISA report reveals DDoS accounted for 60% of public sector security incidents last year

  14. AI-Enabled Malware Now Actively Deployed, Says Google

    Google warns of “just-in-time AI” malware using LLMs to evade detection and generate malicious code on-demand

  15. Google Forecasts Rise of Cyber-Physical Attacks Targeting Europe in 2026

    Europe will likely face a combination of heightened cyber-physical attacks and information operations coming from nation-state groups in 2026

  16. Operation Chargeback Uncovers €300m Fraud Scheme in 193 Countries

    Operation “Chargeback” has dismantled global fraud networks misusing stolen card data from more than 4.3 million victims

  17. UNK_SmudgedSerpent Targets Academics With Political Lures

    A previously unknown cyber actor UNK_SmudgedSerpent has been observed targeting academics with phishing and malware, merging techniques from Iranian groups

  18. Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection

    Three of Anthropic’s Claude Desktop extensions were vulnerable to command injection – flaws that have now been fixed

  19. SMS Fraud Losses Set to Decline 11% in 2026

    Juniper Research predicts a $9bn drop in losses to SMS fraud next year

  20. Hundreds of Malware-Laden Apps Downloaded 42 Million Times From Google Play

    Zscaler estimates 239 malicious Android apps made it onto the official Play store over the past year

What’s Hot on Infosecurity Magazine?