News
Entertainment
Science & Technology
Sport
Business & Money
Life
Culture & Art
Hobbies
8 | Follower
Infosecurity Magazine - Information Security & IT Security
02.09.2025
A software supply chain attack targeting Nx marks the first known case where attackers have leveraged developer AI assistants, according to StepSecurity
Silver Fox APT abuses Microsoft-signed drivers to kill antivirus and deploy ValleyRAT remote-access backdoor
Adversaries targeting the Salesloft Drift application integration with Salesforce have also compromised Google Workspace accounts
The credit rating giant revealed that the breach, which occurred on July 28, was caused by unauthorized access to a third-party application
Zscaler has emerged as the latest corporate victim of a supply chain attack targeting Salesforce data
The campaign shows APT29’s intentions to “cast a wider net in their intelligence collection efforts,” said Amazon
Pennsylvania’s Attorney General confirmed the OAG had refused to pay a ransom demand to the attackers after files were encrypted
Recorded Future highlighted the vast capabilities of state actors to rapidly weaponize newly disclosed vulnerabilities for geopolitical purposes
WhatsApp has fixed a zero-day vulnerability linked to a sophisticated cyber-attack
A vulnerability in the WordPress Paid Memberships Subscription plugin could lead to unauthenticated SQL injection on affected sites
Fake IT support lures are being used to trick employees into installing remote‑access tools via Microsoft Teams
Pyongyang-backed hacking group APT37 leveraged an internal South Korean intelligence briefing in a spear phishing campaign
28.08.2025
CISA has launched a new Software Acquisition Guide Web Tool to enhance security in software procurement
Citrix customers are urged to patch their vulnerable NetScaler appliances, but “patching alone won’t cut it,” experts said
While still in development, PromptLock is described as the “first known AI-powered ransomware” by ESET researchers
Microsoft observed Storm-0501 pivot to the victim’s cloud environment to exfiltrate data rapidly and prevent the victim’s recovery
A series of cyber-attacks against government organizations in Central Asia and Asia- Pacific has been linked to the ShadowSilk threat cluster
EU security agency ENISA is being handed €36m to operate the EU Cybersecurity Reserve
The Office of the Governor of Nevada revealed that the incident has shut down in-person State services, while government phone lines and websites are offli
Google is warning of a new credential theft campaign targeting Salesforce customers via Salesloft Drift
27.08.2025
A global phishing campaign has been identified using personalized emails and fake websites to deliver malware via UpCrypter
All previously scheduled mobility trips across Maryland for this week will be honored, said the state’s transportation administration
Abnormal AI said the campaign, which lures victims into downloading legitimate RMM software, marks a major evolution in phishing tactics
A new version of the Hook Android banking Trojan features 107 remote commands, including ransomware overlays
A new CIISec poll finds the majority of industry professionals would prefer more rigorous cybersecurity laws
26.08.2025
The US Cybersecurity and Infrastructure Security Agency is planning to launch an update to a 2021 guideline for SBOM requirements
A Chinese developer has been sentenced to four years in prison after being found to deploy malicious code in his employer’s network, including a “kill swit
Data I/O has revealed operational disruption following a ransomware breach that forced it to take some systems offline
A variant of the Atomic macOS Stealer (AMOS) targets macOS users via fake support sites in malvertising campaign
25.08.2025
Noah Urban, linked with the Scattered Spider cybercriminal gang, will also pay $13m in restitution to victims
Operation Serengeti 2.0 operators helped recover $97.4m stolen by cybercriminals
A 22-year-old Oregon man has been charged with administering the Rapper Bot DDoS-for-hire Botnet
Indiana-based pharmaceutical research company Inotiv has confirmed it suffered a ransomware attack, disrupting operations and compromising data
Darktrace observed a coordinated campaign on customer SaaS accounts, all of which involved logins from IP addresses linked to VPS providers
Russian state-backed hackers are exploiting a seven-year-old Cisco Smart Install vulnerability (CVE-2018-0171) in end-of-life devices
Guardio reveals a new AI take on ClickFix dubbed “PromptFix”
Colt customers can request a list of filenames posted on the dark web via a dedicated call center
NIST has released new guidelines examining the pros and cons of detection methods for face morphing
Microsoft has set out a roadmap to complete transition to PQC in all its products and services by 2033, with roll out beginning by 2029
Orange Belgium revealed that a threat actor has compromised 850,000 customer accounts, with SIM card numbers among the data accessed