Infosecurity News

  1. TrickMo Variant Routes Android Trojan Traffic Through TON

    ThreatFabric finds new TrickMo Android banking trojan variant routing C2 through The Open Network

  2. Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities

    Two new high-severity vulnerabilities, dubbed ’Dirty Frag’ when chained, have been found in the Linux kernel, affecting most Linux distributions

  3. Fake Claude Code Page Pushes PowerShell Stealer at Devs

    Ontinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2

  4. Hackers Observed Using AI to Develop Zero-Day for the First Time

    Google Threat Intelligence Group details how cybercriminals attempted to launch a campaign based around an AI-developed Zero-Day targeting open-source software

  5. US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates

    The same extension applies to security updates shipped to US-based users of foreign-made drones

  6. ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign

    ShinyHunters has escalated its Canvas extortion campaign, defacing hundreds of school login pages and threatening to leak stolen data unless institutions negotiate

  7. Zara Data Breach Impacts Nearly 200,000 Customers

    ShinyHunters gets away with emails and other data on 200,000 Zara customers

  8. Police Shut Relaunched Crimenetwork Dark Web Marketplace

    Spanish police have arrested the suspected administrator of German dark web marketplace Crimenetwork

  9. Australian Cyber Security Centre Issues Alert Over ClickFix Attacks

    ACSC warns over a campaign targeting organizations which uses ClickFix to deliver Vidar infostealer malware

  10. PCPJack Campaign Boots TeamPCP Off Compromised Machines

    SentinelOne believes the PCPJack campaign may be the brainchild of a former TeamPCP member

  11. Legacy Security Tools Failing Data Protection, Capital One Software Report Finds

    Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible without rethinking data security

  12. Cline Kanban Flaw Lets Websites Hijack AI Coding Agents

    Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack

  13. OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos

    Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers

  14. Fake Claude AI Site Drops Beagle Backdoor on Windows Users

    Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading

  15. Daemon Tools Developer Confirms Software Was Trojanized

    A China-linked threat actor backdoored a version of Daemon Tools to infect thousands

  16. Researchers Spot Uptick in Use of Vercel for Phishing Campaigns

    Cofense has warned of a “significant” increase in phishing campaigns abusing Vercel platform

  17. CloudZ Malware Abuses Phone Link to Steal SMS OTPs

    Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs

  18. CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack

    CISA’s CI Fortify initiative aim for critical infrastructure operators to build isolation & recovery

  19. Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign

    Rapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attack

  20. One in Eight Workers Has Sold Their Corporate Logins

    Cifas says that 13% of employees admit selling company credentials to a former colleague

What’s Hot on Infosecurity Magazine?