Handala Group Tied to Iranian Hack‑and‑Leak Operations, FBI Reveals Information Security Magazine 2 months ago The FBI has warned that Iranian hacking group Handala has been targeting opponents of the regime since 2023
Most Cybersecurity Staff Don’t Know How Fast They Could Stop a Cyber-Attack on AI Systems Information Security Magazine 2 months ago ISACA survey found that confusion over responsibility and lack of understanding around AI cyber-attacks makes containing them difficult
Tycoon2FA Phishing Service Resumes Activity Post-Takedown Information Security Magazine 2 months ago Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA
High-Tech Sector Overtakes Finance as Top Target for Cyber-Attacks, Mandiant Reports Information Security Magazine 2 months ago High tech was the most frequently targeted industry in Mandiant investigations in 2025, overtaking financial services which led in 2023 and 2024
Trivy Supply Chain Attack Expands With New Compromised Docker Images Information Security Magazine 2 months ago New Trivy Docker images 0.69.5 and 0.69.6 compromised with TeamPCP infostealer, impacting CI/CD scans
CISA Orders US Government to Patch Maximum Severity Cisco Flaw Information Security Magazine 2 months ago CISA added CVE-2026-20131 to its KEV catalog as it is being used in ransomware campaigns
Operation Alice Takes Down 370,000+ Dark Web Sites Information Security Magazine 2 months ago German-led policing effort against fraud operation disrupts countless CSAM and cybercrime sites
Hackers Exploit Critical Langflow Bug in Just 20 Hours Information Security Magazine 2 months ago Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day
NCA Boss Warns That Teens Are Being “Radicalized” Into Cybercrime Online Information Security Magazine 2 months ago The National Crime Agency’s director general warns that technology is rapidly reshaping crime
Ransomware Affiliate Exposes Details of 'The Gentlemen' Operation Information Security Magazine 2 months 1 week ago Hastalamuerte leaks The Gentlemen RaaS ops: FortiGate exploits, BYOVD evasion, Qilin split tactics
Financial Brands Targeted in Global Mobile Banking Malware Surge Information Security Magazine 2 months 1 week ago Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices
FCA Updates Cyber Incident and Third-Party Reporting Rules Information Security Magazine 2 months 1 week ago The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer
AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January Information Security Magazine 2 months 1 week ago Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says
UK: Regulation Drives Cyber Spending for Critical Infrastructure Orgs Information Security Magazine 2 months 1 week ago 35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs
New Ubuntu Flaw Enables Local Attackers to Gain Root Access Information Security Magazine 2 months 1 week ago CVE-2026-3888 Ubuntu snap flaw lets local users escalate to root via timing-based exploit
Crypto Scam "ShieldGuard" Dismantled After Malware Discovery Information Security Magazine 2 months 1 week ago ShieldGuard Chrome extension posed as a crypto security tool but stole wallets and drained user data
AI-Enabled Adversaries Compress Time-to-Exploit Following Vulnerability Disclosure Information Security Magazine 2 months 1 week ago Rapid7 says median time from publication to CISA KEV inclusion dropped to five days
Vidar Stealer 2.0 Exploits GitHub, Reddit to Deliver Malware via Fake Game Cheats Information Security Magazine 2 months 1 week ago The Vidar 2.0 infostealers is deployed through fake free game cheats on GitHub and Reddit
AI Issues Will Drive Half of Incident Response Efforts by 2028, Says Gartner Information Security Magazine 2 months 1 week ago Gartner has urged security teams to get involved in AI projects from the start to avoid costly incident response
Android OS-Level Attack Bypasses Mobile Payment Security Information Security Magazine 2 months 1 week ago Android’s LSPosed-based attack hijacks payment apps via runtime manipulation and SIM-binding bypass