Infosecurity News

  1. JadePuffer Returns With Ransomware Designed to Wipe AI Models

    JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts

  2. Researchers Build WordPress Exploit Using OpenAI's GPT

    A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain

  3. New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

    Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel

  4. Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders

    Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders

  5. Government Agencies Falling Victim to Ransomware Daily, Warns Study

    Government organizations are targeted by attackers who know agencies cannot afford disruption to public services

  6. 23andMe Faces New Security Mandates in $18m Data Breach Settlement

    23andMe has agreed to an $18m settlement with 42 US attorneys general over its 2023 data breach, including enhanced data protection requirements

  7. CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities

    US government agencies have until July 19 to patch two critical Fortinet vulnerabilities

  8. The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat

    Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape

  9. Phishing Campaign Hides Lua Loader as TrueType Font File

    Global phishing campaign disguised a Lua loader as a font file to deploy RATs and infostealers

  10. Modular macOS Stealer Uses Kill Loops to Force Password Entry

    New ClickLock macOS stealer locked victims out of their own system until they surrendered a password

  11. Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim

    Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers

  12. "Selfish Bravado" Behind TfL Cyber-Attack, Judge Says as Pair Jailed

    The perpetrators of the 2024 TfL cyber-attack have been jailed for five and a half years each after pleading guilty to Computer Misuse Act offences

  13. SANS Warns of AI Governance Gap as Use by Security Teams Surges

    SANS Institute says governance programs are still nascent even as AI failures and threats grow

  14. US Launches Gold Eagle to Coordinate AI-Driven Vulnerability Management

    The White House announced Gold Eagle to help accelerate the discovery, prioritization and patching of flaws found by AI

  15. Phishing Campaign Abuses eCards to Deploy RMM Tools

    Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims

  16. Eleven Vulnerable UEFI Shims Enable Secure Boot Bypass

    Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine

  17. Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks

    Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware

  18. Progress Restores ShareFile Storage Zones Access After Security Warning

    Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat

  19. Microsoft Patches 570 CVEs in Record Patch Tuesday

    Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discovery and increasing patch volumes

  20. Government Updates UK’s National Risk Register with Cyber Warnings

    The UK government is warning of the potential impact of catastrophic cyber-attacks

What’s Hot on Infosecurity Magazine?