Cifas data finds account takeover and identity fraud are driving a surge in fraud cases
Category: www.infosecurity-magazine.com
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities
Enterprise software creation has accelerated as vulnerability levels rise, Sonatype finds
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers
Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to…
Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit
UK Legal Regulator Raises AI Misuse Concerns
Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks
UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
UNISOC modem flaw enabled kernel-level code execution through video calls
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Critical User Profile Builder flaw let unauthenticated attackers access administrator accounts
ETSI Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act
The European Telecommunications Standards Institute has launched an approval process for standards vendors will have to meet under the Cyber Resilience Act
SafePal Data Breach Hits Tens of Thousands of Customers
Nearly 40,000 customers of hardware wallet provider SafePal have been impacted by a data breach
Infostealers Harvest 1.7 Billion Credentials in Six Months
Flashpoint data reveals infostealers were responsible for taking 1.7 billion credentials in the first half of 2026
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
ICO Reprimands Criminal Records Office After 2023 Breach
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via…
WindRelay Malware Pairs With SpyNote RAT in Live-Call Scam
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
AmnesiaStealer contains novel functions, including the attackers gaining remote control over the victim’s browser to steal cookie data