Infosecurity News

  1. AI Accounts for Over Half of Cybercrime in Africa, Says Interpol

    Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling

  2. UK’s Police National Legal Database Reveals Data Breach

    The UK’s Police National Legal Database and Ask the Police service have been breached

  3. China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day

    Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure

  4. Midnight Blizzard Targets Travelers via Captive Portals

    Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens

  5. HollowFrame Loader Uses Fake Python DLL to Evade Defender

    New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions

  6. Korea’s Largest Telco KT Fined $38m After Femtocell Campaign

    Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise

  7. Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked

    A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug

  8. Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits

    A Chinese-speaking threat actor has been using DeepSeek’s AI models to orchestrate cyber-attacks targeting Asian organizations

  9. AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks

    AWS has linked North Korea to the axios campaign to other attacks on npm libraries

  10. Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

    Anthropic has revealed that Claude AI models compromised third-party organizations

  11. Cryptominer Abuses Linux PAM to Hide From SOC Analysts

    Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts

  12. AiTM Phishing Becomes Top Initial Access Threat to Law Firms

    AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats

  13. AI and Automation Fall Short of Sysadmin Expectations

    Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago

  14. Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

    Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure

  15. Google Releases Patches for 370 Vulnerabilities in Chrome 151

    The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws

  16. NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices

    The UK’s National Cyber Security Centre wants network device makers to improve forensic observability

  17. LogoKit Phishing Kit Screenshots Victim Sites in Real Time

    LogoKit now builds per-victim phishing pages using live screenshots of the target's real website

  18. Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack

    TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging

  19. The Average Cost of a Data Breach Rises to $5 Million

    IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.99m – and AI-backed attacks have played a role

  20. Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild, Research Shows

    For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said

What’s Hot on Infosecurity Magazine?