Police Urge Passkey Use After Surge in Cybercrime Profits Information Security Magazine 5 hours 1 minute ago Report Fraud says cybercrime revenue stemming from account takeover increased 417% annually
Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds Information Security Magazine 5 hours 46 minutes ago An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims
ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes Information Security Magazine 23 hours 46 minutes ago ClingSTUN exploits known IoT flaws and abuses public STUN servers to keep proxy access to devices
New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic Information Security Magazine 1 day ago Rapid7 has uncovered new BPFDoor, BPF Rekoobe and AVERAT malware variants targeting telecom and network-edge appliances in South Korea and Taiwan
Citrix NetScaler Targeted Via New Zero Day Information Security Magazine 1 day ago The memory buffer vulnerability can result in denial of service to customers, with CISA warning it poses “significant risks” to the federal government
Google Suspends Open-Source Bug Bounty Due to AI Vulnerability Reports Information Security Magazine 1 day 3 hours ago Google has paused its Open Source Vulnerability Rewards Program due to a flood of AI submissions
More UK Schools Are Recovering Faster from Cyber Incidents Information Security Magazine 1 day 4 hours ago Ofqual study finds growing number of UK schools are bouncing back “immediately” from cyber-attacks
Frontline Education Breach Impacts K-12 School District Staff Information Security Magazine 1 day 5 hours ago A breach at school software provider Frontline Education has exposed employee data
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes Information Security Magazine 4 days ago Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
Police Target KillSec Ransomware Group with Arrests and Seizures Information Security Magazine 4 days 4 hours ago Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure Information Security Magazine 4 days 5 hours ago The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation Information Security Magazine 4 days 23 hours ago Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders Information Security Magazine 5 days ago TA419 posed as AI policymakers and economists to phish US AI policy experts' Microsoft 365 accounts
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer Information Security Magazine 5 days ago CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds Information Security Magazine 5 days 4 hours ago PwC finds global security leaders are most concerned about attacks on AI systems
MI5 Warns Over 100 Academics Helped China's Espionage Plans Information Security Magazine 5 days 6 hours ago MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says Information Security Magazine 6 days ago AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord Information Security Magazine 6 days 1 hour ago Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight
AI Boosts SOC Analyst Capacity but Limits Skill Development Information Security Magazine 6 days 2 hours ago Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer
Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware Information Security Magazine 6 days 2 hours ago Cybersecurity researchers at Huntress identify campaign to deliver potent trojan which targets users searching for ChatGPT via Google