Doubloon Dredger Abuses Notion to Harvest Authentication Tokens Information Security Magazine 3 weeks 2 days ago Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant Information Security Magazine 3 weeks 2 days ago Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure
Researchers Uncover Thousands of Leaked AWS Keys Information Security Magazine 3 weeks 2 days ago Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
North Korean Hackers Tied to Rust Supply Chain Attack Information Security Magazine 3 weeks 5 days ago Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks
New Agent Tesla Malware Variant Boosts Evasion Capabilities Information Security Magazine 3 weeks 5 days ago An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed
Cybersecurity Job Ads Requiring AI Skills Double Information Security Magazine 3 weeks 5 days ago An analysis by the AI Workforce Consortium found that technical cybersecurity jobs are becoming more strategic due to the influence of AI
JFrog Artifactory Flaws Enable Software Supply Chain Attacks Information Security Magazine 3 weeks 6 days ago Two Artifactory flaws allowed attackers to poison package metadata across software repositories
NCSC Urges Stronger Controls for Agentic AI Systems Information Security Magazine 3 weeks 6 days ago NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents
US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate Information Security Magazine 3 weeks 6 days ago Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs Information Security Magazine 3 weeks 6 days ago A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps Information Security Magazine 3 weeks 6 days ago Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan
Def Con Attendees Targeted by Persistent Phishing Campaign Information Security Magazine 3 weeks 6 days ago Huntress researcher explains how they were targeted by an elaborate and persistent phishing scam following Def Con
Exclusive: Linux Foundation's Akrites to Go Live in September Information Security Magazine 4 weeks ago The Linux Foundation's Akrites initiative will become operational in September, when it will begin accepting AI-powered vulnerability reports for open-source projects
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra Information Security Magazine 4 weeks ago eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra
Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign Information Security Magazine 4 weeks ago Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections
OpenAI Tightens AI Safeguards Following Hugging Face Incident Information Security Magazine 4 weeks ago OpenAI is strengthening safeguards for its most advanced AI models, citing growing risks as frontier systems gain more powerful cyber capabilities
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware Information Security Magazine 4 weeks ago The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter
ICO Urges Police to Improve Data Governance in Facial Recognition Rollouts Information Security Magazine 4 weeks ago The UK’s privacy watchdog has called on police using facial recognition to follow its recommendations
UK Fraud Cases Hit Record High in 2026 Information Security Magazine 4 weeks ago Cifas data finds account takeover and identity fraud are driving a surge in fraud cases
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed Information Security Magazine 4 weeks 1 day ago The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher