Infosecurity Magazine - Latest News and Information
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Technology Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
Infosecurity Magazine

Infosecurity Magazine

Publication
2 followers

Award-winning publication dedicated to information security strategy and insights for security professionals.

Recent Posts

Microsoft Fixes Three Zero-Days on Busy Patch Tuesday
News•Jan 14, 2026

Microsoft Fixes Three Zero-Days on Busy Patch Tuesday

Microsoft released its latest Patch Tuesday update, fixing 114 CVEs including three critical zero‑day bugs. The zero‑days are CVE‑2026‑20805 (information disclosure in Desktop Window Manager), CVE‑2026‑21265 (secure‑boot certificate bypass), and CVE‑2023‑31096 (elevation of privilege in legacy Agere modem drivers). The bulletin contains 57 elevation‑of‑privilege, 22 remote‑code‑execution, and 22 information‑disclosure flaws, with eight classified as critical. Administrators must act quickly to mitigate both software and firmware‑related risks.

By Infosecurity Magazine
Parliament Asks Security Pros to Shape Cyber Security and Resilience Bill
News•Jan 13, 2026

Parliament Asks Security Pros to Shape Cyber Security and Resilience Bill

The UK Parliament’s Public Bill Committee has opened a consultation for the Cyber Security and Resilience Bill (CSRB), the successor to the 2018 NIS Regulations and a NIS2‑style overhaul for critical infrastructure. After its second reading, the bill now enters...

By Infosecurity Magazine
Global Magecart Campaign Targets Six Card Networks
News•Jan 13, 2026

Global Magecart Campaign Targets Six Card Networks

Security firm Silent Push uncovered a long‑running Magecart skimming operation that has been active since 2022. The campaign injects malicious JavaScript into e‑commerce sites, targeting six major payment networks – American Express, Diners Club, Discover, JCB, Mastercard and UnionPay. Victims see a...

By Infosecurity Magazine
World Economic Forum: Cyber-Fraud Overtakes Ransomware as Business Leaders' Top Cyber-Security Concern
News•Jan 12, 2026

World Economic Forum: Cyber-Fraud Overtakes Ransomware as Business Leaders' Top Cyber-Security Concern

The World Economic Forum’s Global Cybersecurity Outlook for 2026 reveals that phishing attacks have eclipsed ransomware as the chief concern for business leaders. Seventy‑seven percent of respondents reported a rise in cyber‑enabled fraud, and 73 percent said they or a...

By Infosecurity Magazine
Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrested
News•Jan 9, 2026

Europol Leads Global Crackdown on Black Axe Cybercrime Gang, 34 Arrested

Europol coordinated a multi‑national operation that led to the arrest of 34 members of the Black Axe cyber‑crime gang across Spain and Germany. Spanish police detained suspects in Seville, Madrid, Málaga and Barcelona, while German authorities assisted in the raids....

By Infosecurity Magazine
World Economic Forum: Deepfake Face-Swapping Tools Are Creating Critical Security Risks
News•Jan 9, 2026

World Economic Forum: Deepfake Face-Swapping Tools Are Creating Critical Security Risks

The World Economic Forum’s Cybercrime Atlas report warns that advanced deep‑fake face‑swapping tools are now capable of bypassing know‑your‑customer (KYC) and remote verification processes. Researchers examined 17 commercial face‑swap applications and eight camera‑injection tools, finding that low‑latency, high‑fidelity swaps can...

By Infosecurity Magazine
AI-Powered Truman Show Operation Industrializes Investment Fraud
News•Jan 9, 2026

AI-Powered Truman Show Operation Industrializes Investment Fraud

Security firm Check Point uncovered an AI‑driven investment fraud that stages a "Truman Show"‑style reality for victims. The operation uses unsolicited SMS and ads to lure targets into WhatsApp groups populated by AI‑generated experts and fake members who showcase fabricated...

By Infosecurity Magazine
New Zero-Click Attack Lets ChatGPT User Steal Data
News•Jan 8, 2026

New Zero-Click Attack Lets ChatGPT User Steal Data

Researchers at Radware disclosed a new prompt‑injection method called ZombieAgent that lets ChatGPT exfiltrate data from integrated services such as Gmail, Outlook, Google Drive, and GitHub. The technique sidesteps OpenAI’s recent URL‑modification guardrails by using pre‑built static URLs, leaking information...

By Infosecurity Magazine
China-Linked UAT-7290 Targets Telecom Networks in South Asia
News•Jan 8, 2026

China-Linked UAT-7290 Targets Telecom Networks in South Asia

Cisco Talos has identified a long‑running cyber‑espionage campaign, designated UAT‑7290, targeting high‑value telecommunications infrastructure across South Asia since at least 2022. The group compromises public‑facing edge devices using one‑day vulnerabilities and SSH brute‑force techniques, deploying a suite of Linux‑based tools...

By Infosecurity Magazine
Fifth of Breaches Take Two Weeks to Recover From
News•Jan 8, 2026

Fifth of Breaches Take Two Weeks to Recover From

A new Absolute Security report, based on a poll of 750 CISOs in the US and UK, finds that endpoint disruptions from cyber‑attacks often require 3‑6 days to remediate, with 19% taking up to two weeks. The average cost to...

By Infosecurity Magazine
US To Leave Global Forum on Cyber Expertise
News•Jan 8, 2026

US To Leave Global Forum on Cyber Expertise

The Trump administration signed an executive order on Jan. 7 withdrawing the United States from 66 international bodies, including the Global Forum on Cyber Expertise (GFCE) and the European Centre of Excellence for Countering Hybrid Threats (Hybrid CoE). Both organizations coordinate...

By Infosecurity Magazine
Versatile Malware Loader Pkr_mtsi Delivers Diverse Payloads
News•Jan 7, 2026

Versatile Malware Loader Pkr_mtsi Delivers Diverse Payloads

ReversingLabs identified a Windows packer named pkr_mtsi that serves as a versatile malware loader in large‑scale malvertising and SEO‑poisoning campaigns. First seen in April 2025, it disguises fake installers for popular tools like PuTTY, Rufus and Microsoft Teams, then delivers...

By Infosecurity Magazine
Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud
News•Jan 7, 2026

Ghost Tap Malware Fuels Surge in Remote NFC Payment Fraud

Group‑IB uncovered a new Android malware family, dubbed Ghost Tap, that enables criminals to perform unauthorized tap‑to‑pay transactions by remotely relaying NFC card data. Over 54 malicious APKs, disguised as legitimate finance apps, are sold on Chinese‑language Telegram channels where...

By Infosecurity Magazine
High-Severity Flaw in Open WebUI Affects AI Connections
News•Jan 6, 2026

High-Severity Flaw in Open WebUI Affects AI Connections

A high‑severity vulnerability (CVE‑2025‑64496) was found in Open WebUI versions 0.6.34 and earlier when the Direct Connections feature is enabled. The flaw lets a malicious AI endpoint send crafted server‑sent events that execute JavaScript in the user’s browser, stealing localStorage tokens and...

By Infosecurity Magazine
Jaguar Land Rover's Q3 Sales Crash Amid Cyber-Attack Fallout
News•Jan 6, 2026

Jaguar Land Rover's Q3 Sales Crash Amid Cyber-Attack Fallout

Jaguar Land Rover reported a sharp sales decline in Q3 2025 after a late‑August cyber‑attack crippled its factories. Retail volumes fell 25.1% year‑on‑year to 79,600 vehicles, while wholesale shipments plunged 43% to 59,200 units. Production stoppages in September and lingering...

By Infosecurity Magazine
VVS Stealer Uses Advanced Obfuscation to Target Discord Users
News•Jan 5, 2026

VVS Stealer Uses Advanced Obfuscation to Target Discord Users

The VVS stealer, a Python‑based malware family distributed as a PyInstaller package, employs Pyarmor obfuscation to evade detection and specifically harvest Discord tokens and browser credentials. It injects malicious JavaScript into the Discord client, extracts data from Chromium‑based and Firefox...

By Infosecurity Magazine

Page 3 of 3

← Prev123