China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders Information Security Magazine 6 days 7 hours ago TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer Information Security Magazine 6 days 7 hours ago CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds Information Security Magazine 6 days 11 hours ago PwC finds global security leaders are most concerned about attacks on AI systems
MI5 Warns Over 100 Academics Helped China's Espionage Plans Information Security Magazine 6 days 13 hours ago MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says Information Security Magazine 1 week ago AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord Information Security Magazine 1 week ago Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight
AI Boosts SOC Analyst Capacity but Limits Skill Development Information Security Magazine 1 week ago Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware Information Security Magazine 1 week ago Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google
Apple Patches CoreGraphics Zero Day Exploited in Attacks Information Security Magazine 1 week ago Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine
RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model Information Security Magazine 1 week 1 day ago RatHat's C2 panel now builds malware and ranks victims with AI across nearly 100 deployments
Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials Information Security Magazine 1 week 1 day ago AWS AgentCore SDK flaws could let attackers run commands in AI sandboxes and reach AWS credentials
Microsoft Warns NeedyMantis Malware Enables Persistent Network Access Information Security Magazine 1 week 1 day ago Microsoft Threat Intelligence warns that NeedyMantis threat actor from China has targeted organizations across a range of industries
Japanese Railway Operators Hit with Weekend Cyber Attacks Information Security Magazine 1 week 1 day ago Tokyo Metro and Keio have revealed separate cyber-attacks
Kiteworks Urges Customers to Restart Systems After Shutdown Notice Information Security Magazine 1 week 1 day ago Kiteworks has lifted a temporary shutdown recommendation which was issued on the back of federal intelligence
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach Information Security Magazine 1 week 2 days ago Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
NVIDIA Launches Open Platform to Secure Autonomous AI Agents Information Security Magazine 1 week 2 days ago NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns Information Security Magazine 1 week 2 days ago A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat
MCP Is Creating Major Governance Gaps, Researchers Warn Information Security Magazine 1 week 2 days ago Ox Security found security shortcomings in analysis of over 15,000 MCP servers
Citrix Patches Critical Zero Days Under Active Exploitation Information Security Magazine 1 week 2 days ago Citrix has confirmed exploitation of two critical zero-day RCE bugs
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk Information Security Magazine 1 week 5 days ago The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration