CISA Unveils Election Security Plan Ahead of 2026 Midterms Information Security Magazine 1 week 5 days ago The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices Information Security Magazine 1 week 5 days ago The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials
Researchers Identify AliExpress Phishing Domains Before Registration Information Security Magazine 1 week 5 days ago EfficientIP says it flagged AliExpress phishing domains before they were registered
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims Information Security Magazine 1 week 6 days ago Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims
CISA Charts New "Quality Era" for Global CVE Program Information Security Magazine 1 week 6 days ago CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit Information Security Magazine 1 week 6 days ago Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy
OpenAI Agent Hacks Australian Medicare Portal Information Security Magazine 1 week 6 days ago Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
Over 75% of Organizations Experience Microsoft 365 Governance Issues Information Security Magazine 1 week 6 days ago ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds Information Security Magazine 1 week 6 days ago SANS Institute report claims data rather than skills is now the main hurdle for threat hunters
Hundreds of Leaked GitHub App Keys Still Authenticate Information Security Magazine 2 weeks ago GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods Information Security Magazine 2 weeks ago Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Ransomware Attacks Reach Record High for 2026 Information Security Magazine 2 weeks ago A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day Information Security Magazine 2 weeks ago Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response Information Security Magazine 2 weeks ago The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents
North Korean Attackers Hit 30,000 Devices and Steal $10.7m Information Security Magazine 2 weeks 1 day ago WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds Information Security Magazine 2 weeks 1 day ago A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure
Network Segmentation Failures Are Expanding the Corporate Attack Surface Information Security Magazine 2 weeks 1 day ago Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks
AI Drives Surge in Bot and API Threats Information Security Magazine 2 weeks 1 day ago Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns Information Security Magazine 2 weeks 1 day ago Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
Google Hit with €403m GDPR Fine Over Location Data Practices Information Security Magazine 2 weeks 2 days ago The Irish DPC found that Google users were unaware that their location was being used to influence them with ads