Chinese-Speaking Cybercrime Group Hijacks IIS Servers for SEO Fraud Information Security Magazine 2 months ago Cisco Talos has identified a Chinese-speaking cybercrime group that targets high-value Internet Information Services (IIS) for SEO fraud
Hackers Target Unpatched Flaws in Oracle E-Business Suite Information Security Magazine 2 months ago Patches for the targeted vulnerabilities were released in Oracle’s July 2025 security update
WestJet Data Breach Impacts 1.2 Million Customers Information Security Magazine 2 months ago WestJet revealed that customer personal details and membership data were stolen in the June 2025 attack
US Government Shutdown to Slash Federal Cybersecurity Staff Information Security Magazine 2 months 1 week ago The US government shutdown is estimated to result in around 65% of CISA staff being furloughed, with fears that threat actors will exploit critical security gaps
Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member Information Security Magazine 2 months 1 week ago The initial investigation shows early signs of links with the FIN11 and Clop cyber extortion groups
Confucius Shifts from Document Stealers to Python Backdoors Information Security Magazine 2 months 1 week ago The Confucius cyber-espionage group has shifted its tactics from document-focused stealers to Python-based backdoors like AnonDoor
Free VPN Apps Found Riddled With Security Flaws Information Security Magazine 2 months 1 week ago A new study by Zimperium has revealed serious risks in free VPN apps, exposing users to privacy threats and security flaws
Expired US Cyber Law Puts Data Sharing and Threat Response at Risk Information Security Magazine 2 months 1 week ago Experts argued that the lapse of the Cybersecurity Information Sharing Act could have far-reaching consequences in US national cyber defenses
Forrester: Agentic AI-Powered Breach Will Happen in 2026 Information Security Magazine 2 months 1 week ago Forrester predicts agentic AI will be responsible for a major data breach in 2026
Phishing Dominates EU-Wide Intrusions, says ENISA Information Security Magazine 2 months 1 week ago ENISA reveals phishing and vulnerability exploitation accounted for majority of intrusions in past year
Broadcom Issues Patches for VMware NSX and vCenter Security Flaws Information Security Magazine 2 months 1 week ago Broadcom has released security patches for critical flaws affecting several VMware products
Shortcut-based Credential Lures Deliver DLL Implants Information Security Magazine 2 months 1 week ago A new campaign has been observed using malicious Windows shortcuts in credential-themed ZIP files to deploy PowerShell script
AI Tops Cybersecurity Investment Priorities, PwC Finds Information Security Magazine 2 months 1 week ago PwC found that AI security has become a top investment priority in cyber budgets over the next 12 months, ahead of cloud and network security
New China-Aligned Hackers Hit State and Telecom Sectors Information Security Magazine 2 months 1 week ago Phantom Taurus is the latest formally identified cyber-espionage group aligned with Chinese state interest
Campaign Warns Solicitors and House Buyers of Payment Diversion Fraud Information Security Magazine 2 months 1 week ago The NCA warns that house buyers could face losses of over £80,000 from a type of BEC called payment diversion fraud
ICO: Imgur’s UK Decision Won’t Prevent Regulatory Fine Information Security Magazine 2 months 1 week ago Image-sharing platform Imgur has blocked its services within the UK, following a regulatory notice from the ICO
Smishing Campaigns Exploit Cellular Routers to Target Belgium Information Security Magazine 2 months 1 week ago New smishing attacks exploit Milesight routers to send phishing texts targeting Belgian users
New Android RAT Klopatra Targets Financial Data Information Security Magazine 2 months 1 week ago New Android RAT Klopatra is targeting financial institutions using advanced evasion techniques
US Cuts Federal Funding for MS-ISAC Cybersecurity Program Information Security Magazine 2 months 1 week ago The Trump administration wants CISA to transition to a “new model” for supporting local government agencies’ cyber strategy
Gemini Trifecta Highlights Dangers of Indirect Prompt Injection Information Security Magazine 2 months 1 week ago Tenable researchers have discovered three vulnerabilities in Google’s Gemini GenAI tool