Infosecurity News

UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy

OpenAI Agent Hacks Australian Medicare Portal
Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026

Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows

Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
SANS Institute report claims data rather than skills is now the main hurdle for threat hunters

Hundreds of Leaked GitHub App Keys Still Authenticate
GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access

Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying

Ransomware Attacks Reach Record High for 2026
A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees

EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents

North Korean Attackers Hit 30,000 Devices and Steal $10.7m
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets

AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure

Network Segmentation Failures Are Expanding the Corporate Attack Surface
Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks

AI Drives Surge in Bot and API Threats
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats

CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect

Google Hit with €403m GDPR Fine Over Location Data Practices
The Irish DPC found that Google users were unaware that their location was being used to influence them with ads

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic

Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance

ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
A breach at image-sharing service Gyazo on September 11 affected over 23 million customers

Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages



