Anthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizations
Tag: www.infosecurity-magazine.com
Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
NCSC Publishes Guidance to Aid Incident Response and Recovery
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”
AI and Automation Fall Short of Sysadmin Expectations
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
CREST’s new AI standards are optional add-on requirements for cybersecurity service providers wishing to demonstrate responsible AI usage
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate…
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
NCSC Calls on Vendors to Embed ‘Forensic Observability’ in Network Devices
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Impersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target’s real website
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging