Infosecurity Magazine

Infosecurity Magazine

Publication
4 followers

Award-winning publication dedicated to information security strategy and insights for security professionals.

Cost of Insider Incidents Surges 20% to Nearly $20m
NewsFeb 24, 2026

Cost of Insider Incidents Surges 20% to Nearly $20m

The DTEX Cost of Insider Risks 2026 report, based on 8,750 security practitioners, finds average insider‑related losses of $19.5 million per organization, with employee negligence—largely driven by shadow AI—accounting for 53% of that cost. Negligence losses rose 17% year‑on‑year, pushing total...

By Infosecurity Magazine
Multifaceted Phishing Scheme Deceives Bitpanda Customers
NewsFeb 24, 2026

Multifaceted Phishing Scheme Deceives Bitpanda Customers

Cybersecurity firm Cofense uncovered a sophisticated phishing campaign that impersonates cryptocurrency broker Bitpanda. The fake site replicates Bitpanda’s login and adds a counterfeit multi‑factor authentication flow to harvest credentials, names, phone numbers, addresses, and birth dates. Attackers host the clone...

By Infosecurity Magazine
Shai-Hulud-Like Worm Targets Developers via Npm and AI Tools
NewsFeb 23, 2026

Shai-Hulud-Like Worm Targets Developers via Npm and AI Tools

Security researchers have uncovered a supply‑chain worm, dubbed SANDWORM_MODE, spreading through at least 19 malicious npm packages that employ typosquatting. The malware not only steals developer and CI credentials but also injects rogue servers into AI coding assistants such as...

By Infosecurity Magazine
Dramatic Escalation in Frequency and Power of DDoS Attacks
NewsFeb 20, 2026

Dramatic Escalation in Frequency and Power of DDoS Attacks

The Radware 2026 Global Threat Analysis Report reveals a 168% jump in DDoS attacks in 2025 versus 2024, with customers averaging 139 attempted incidents per day. Technology, telecommunications and financial services bore the brunt, the tech sector alone accounting for...

By Infosecurity Magazine
Remcos RAT Expands Real-Time Surveillance Capabilities
NewsFeb 19, 2026

Remcos RAT Expands Real-Time Surveillance Capabilities

A newly observed Remcos RAT variant now streams webcam footage and transmits keystrokes in real time, shifting from local data storage to direct, encrypted communication with attacker‑controlled servers. The malware decrypts its configuration only at runtime, loads critical Windows APIs...

By Infosecurity Magazine
Industrial-Scale Fake Coretax Apps Drive $2m Fraud in Indonesia
NewsFeb 19, 2026

Industrial-Scale Fake Coretax Apps Drive $2m Fraud in Indonesia

Group‑IB uncovered a sophisticated fraud campaign that spoofed Indonesia’s Coretax tax platform by distributing counterfeit Android apps. The scheme combined phishing websites, WhatsApp impersonation of tax officers, and voice‑phishing calls to install RATs such as Gigabud.RAT and MMRat, leading to...

By Infosecurity Magazine
Industrial Control System Vulnerabilities Hit Record Highs
NewsFeb 19, 2026

Industrial Control System Vulnerabilities Hit Record Highs

Forescout’s 2026 report shows industrial control system (ICS) advisories surpassed 500 in 2025, the highest level since tracking began. The 2,155 CVEs tied to those advisories pushed average CVSS scores above 8.0, reflecting increasingly critical flaws. Manufacturing and energy assets...

By Infosecurity Magazine
Starkiller: New ‘Commercial-Grade’ Phishing Kit Bypasses MFA
NewsFeb 19, 2026

Starkiller: New ‘Commercial-Grade’ Phishing Kit Bypasses MFA

A new phishing kit called Starkiller has emerged on the dark web as a commercial‑grade, subscription‑based service. It proxies live login pages through attacker‑controlled infrastructure, eliminating static HTML templates and allowing real‑time credential capture. By routing authentication traffic through the...

By Infosecurity Magazine
Cryptojacking Campaign Exploits Driver to Boost Monero Mining
NewsFeb 18, 2026

Cryptojacking Campaign Exploits Driver to Boost Monero Mining

Security firm Trellix uncovered a new cryptojacking operation that spreads through pirated software installers and installs a customized XMRig miner. The malware uses a controller named Explorer.exe for persistence and a signed driver (WinRing0x64.sys, CVE‑2020‑14979) to gain kernel access, boosting...

By Infosecurity Magazine
Over-Privileged AI Drives 4.5 Times Higher Incident Rates
NewsFeb 17, 2026

Over-Privileged AI Drives 4.5 Times Higher Incident Rates

Teleport’s 2026 State of AI in Enterprise Infrastructure Security report reveals that AI workloads with excessive access rights suffer a 4.5‑times higher incident rate than those governed by least‑privilege controls. Seventy percent of surveyed security leaders say AI systems enjoy...

By Infosecurity Magazine
OysterLoader Evolves With New C2 Infrastructure and Obfuscation
NewsFeb 16, 2026

OysterLoader Evolves With New C2 Infrastructure and Obfuscation

OysterLoader, a C++‑based multi‑stage malware loader also known as Broomstick and CleanUp, has been updated through early 2026 with enhanced command‑and‑control infrastructure and obfuscation techniques. The loader now employs a three‑step HTTP/HTTPS handshake, custom Base64 alphabets, and a modified LZMA...

By Infosecurity Magazine
Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft
NewsFeb 16, 2026

Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft

Operation DoppelBrand, attributed to the financially motivated GS7 group, launched a large‑scale phishing campaign against Fortune 500 financial and technology firms between December 2025 and January 2026. The attackers registered over 150 look‑alike domains, used automated SSL certificates and rotating registrars, and cloned...

By Infosecurity Magazine
Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third
NewsFeb 13, 2026

Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third

The Munich Security Index 2026 released at the MSC shows G7 nations rank cyber‑attacks as their top security risk for the second consecutive year. Disinformation campaigns sit in third place, while economic crises occupy the second slot. In contrast, the...

By Infosecurity Magazine
World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks
NewsFeb 12, 2026

World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks

World Leaks, a high‑profile extortion group, has introduced a new Rust‑written malware called RustyRocket, according to Accenture research. The tool provides stealthy persistence on both Windows and Linux systems, using heavily obfuscated, multi‑layered encrypted tunnels to exfiltrate data and proxy...

By Infosecurity Magazine
AI Skills Represent Dangerous New Attack Surface, Says TrendAI
NewsFeb 12, 2026

AI Skills Represent Dangerous New Attack Surface, Says TrendAI

TrendAI, the new business unit of Trend Micro, warns that AI skills—executable artifacts that blend human‑readable text with LLM instructions—represent a dangerous attack surface. These skills, used in products like Anthropic’s Agent Skills, OpenAI’s GPT Actions, and Microsoft’s Copilot Plugins, can...

By Infosecurity Magazine
“Digital Parasite” Warning as Attackers Favor Stealth for Extortion
NewsFeb 10, 2026

“Digital Parasite” Warning as Attackers Favor Stealth for Extortion

Picus Security’s Red Report 2026, based on analysis of over 1.1 million malicious files and 15.5 million actions, shows threat actors now favor stealthy persistence and silent data exfiltration for extortion. Process injection remains the top technique for the third consecutive year, accounting...

By Infosecurity Magazine
NCSC Issues Warning Over “Severe” Cyber-Attacks Targeting Critical National Infrastructure
NewsFeb 10, 2026

NCSC Issues Warning Over “Severe” Cyber-Attacks Targeting Critical National Infrastructure

The UK National Cyber Security Centre (NCSC) has issued an urgent alert to critical national infrastructure (CNI) providers, warning of "severe" cyber‑attacks that could disrupt essential services. The warning follows a coordinated malware strike on Poland’s energy grid in December,...

By Infosecurity Magazine
VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code
NewsFeb 9, 2026

VoidLink Malware Exhibits Multi-Cloud Capabilities and AI Code

Ontinue’s February 9 report details VoidLink, a Linux‑based command‑and‑control framework that can infiltrate enterprise and multi‑cloud environments. The implant adapts to AWS, Azure, GCP, Alibaba and Tencent clouds, harvesting credentials, escaping containers and employing kernel‑level stealth via eBPF or loadable modules....

By Infosecurity Magazine
Social Media Platforms Earn Billions From Scam Ads
NewsFeb 9, 2026

Social Media Platforms Earn Billions From Scam Ads

European social media platforms earned nearly £3.8bn ($5.2bn) from scam ads in 2025, driven by almost one trillion impressions across eleven markets. Scam‑related posts represented about 10% of the 993bn ad views, inflating platform revenue while undermining user trust. Juniper...

By Infosecurity Magazine
US Agencies Told to Scrap End of Support Edge Devices
NewsFeb 9, 2026

US Agencies Told to Scrap End of Support Edge Devices

CISA issued a directive requiring all federal agencies to retire edge devices that have reached end‑of‑support within the next 12 months. The rule targets routers, switches, firewalls, and IoT endpoints that are no longer receiving vendor patches. Agencies must inventory,...

By Infosecurity Magazine
Smartphones Now Involved in Nearly Every Police Investigation
NewsFeb 5, 2026

Smartphones Now Involved in Nearly Every Police Investigation

A new Cellebrite report shows digital evidence, especially from smartphones, now underpins almost every police investigation. Ninety‑five percent of law‑enforcement practitioners consider it essential, and 97% identify smartphones as the top source, up from 73% in 2024. Consequently, 62% of...

By Infosecurity Magazine
AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+
NewsFeb 5, 2026

AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+

Pindrop’s 2025 report reveals a 1,210% surge in AI‑enabled voice and virtual‑meeting fraud, dwarfing the 195% rise in traditional scams. Synthetic voice bots and deepfake executives are now bypassing contact‑center IVRs and infiltrating remote interviews, financial transactions, and other trust‑based...

By Infosecurity Magazine
Global SystemBC Botnet Found Active Across 10,000 Infected Systems
NewsFeb 4, 2026

Global SystemBC Botnet Found Active Across 10,000 Infected Systems

Silent Push has identified more than 10,000 active SystemBC infections across data‑centre and government servers in the US, Europe and Asia. The multi‑platform proxy malware turns compromised hosts into SOCKS5 relays, a technique frequently observed before ransomware campaigns. A previously unknown...

By Infosecurity Magazine
New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure
NewsFeb 4, 2026

New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure

Group‑IB uncovered new technical markers that expand the ShadowSyndicate cybercrime infrastructure, adding two fresh SSH fingerprints and revealing server‑transfer tactics that link dozens of servers to a single operator. The cluster consistently reuses OpenSSH keys and hosts on the same...

By Infosecurity Magazine
AI Drives Doubling of Phishing Attacks in a Year
NewsFeb 4, 2026

AI Drives Doubling of Phishing Attacks in a Year

Cofense reports that phishing attacks doubled in 2025, with security filters catching one malicious email every 19 seconds, up from one every 42 seconds in 2024. The surge is driven by AI, which threat actors now use as a core...

By Infosecurity Magazine
SQL Injection Flaw Affects 40,000 WordPress Sites
NewsFeb 3, 2026

SQL Injection Flaw Affects 40,000 WordPress Sites

A SQL injection vulnerability (CVE‑2025‑67987) was found in the Quiz and Survey Master (QSM) WordPress plugin affecting versions up to 10.3.1. The flaw allowed any logged‑in user with Subscriber‑level access to inject arbitrary SQL via the `_is_linking_` REST API parameter,...

By Infosecurity Magazine
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask Gordon
NewsFeb 3, 2026

DockerDash Exposes AI Supply Chain Weakness In Docker's Ask Gordon

A critical security flaw named DockerDash was disclosed in Docker's Ask Gordon AI assistant, allowing unverified Docker image metadata to become executable instructions. The vulnerability, identified by Noma Labs, enables remote code execution in cloud and CLI environments and data...

By Infosecurity Magazine
Researchers Warn of New “Vect” RaaS Variant
NewsFeb 3, 2026

Researchers Warn of New “Vect” RaaS Variant

Researchers have identified a new ransomware‑as‑a‑service (RaaS) group called Vect, which has already hit organizations in Brazil and South Africa. The group markets a custom‑built C++ ransomware that uses ChaCha20‑Poly1305 encryption, claiming speeds 2.5 times faster than AES‑256‑GCM. Vect advertises...

By Infosecurity Magazine
Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks
NewsFeb 2, 2026

Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks

Russian‑linked group Fancy Bear leveraged the high‑severity CVE‑2026‑21509 Office flaw days after Microsoft disclosed it, targeting Ukrainian ministries and EU bodies. The malicious Word document triggered a WebDAV call that installed a DLL via COM hijacking, ultimately launching the Covenant...

By Infosecurity Magazine
Labyrinth Chollima Evolves Into Three North Korean Hacking Groups
NewsJan 30, 2026

Labyrinth Chollima Evolves Into Three North Korean Hacking Groups

Labyrinth Chollima has split into three distinct North Korean hacking groups—Labyrinth Chollima, Golden Chollima, and Pressure Chollima—according to CrowdStrike. While Labyrinth Chollima continues espionage against defense, manufacturing and critical‑infrastructure firms, the new Golden and Pressure factions focus on cryptocurrency theft. Each group employs a unique...

By Infosecurity Magazine
New AI-Developed Malware Campaign Targets Iranian Protests
NewsJan 30, 2026

New AI-Developed Malware Campaign Targets Iranian Protests

HarfangLab uncovered the RedKitten campaign, an AI‑assisted operation delivering the SloppyMIO malware to Iranian human‑rights activists and NGOs. The attack uses shock‑value Excel files masquerading as forensic records to lure victims into enabling macros. Once activated, SloppyMIO pulls additional payloads...

By Infosecurity Magazine
National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat
NewsJan 30, 2026

National Crime Agency and NatWest Issue Joint Warning Over Invoice Fraud Threat

NatWest Bank and the UK National Crime Agency have launched a joint awareness campaign to combat invoice fraud, a cyber‑crime that siphons millions from businesses each year. The partnership highlights the scale of the threat, citing September 2025 data where...

By Infosecurity Magazine
Operation Winter SHIELD: FBI Issues Call to Arms for Organizations to Improve Cybersecurity
NewsJan 29, 2026

Operation Winter SHIELD: FBI Issues Call to Arms for Organizations to Improve Cybersecurity

The FBI has launched Operation Winter SHIELD, a cyber‑resilience campaign that outlines ten concrete actions for organizations to harden both IT and OT environments. The initiative aligns with the U.S. National Cyber Strategy and draws on recent investigations of cyber‑criminal and...

By Infosecurity Magazine
New CISA Guidance Targets Insider Threat Risks
NewsJan 29, 2026

New CISA Guidance Targets Insider Threat Risks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a new infographic aimed at helping critical‑infrastructure operators and state, local, tribal and territorial (SLTT) governments manage insider threats. The guidance outlines a four‑stage model—plan, organize, execute, maintain—and stresses building multidisciplinary...

By Infosecurity Magazine
US Data Breaches Hit Record High but Victim Numbers Decline
NewsJan 29, 2026

US Data Breaches Hit Record High but Victim Numbers Decline

The Identity Theft Resource Center recorded a record 3,332 data compromises in the United States for 2025, a 5 % rise over the previous year. Despite more incidents, victim notices fell sharply to 279 million, the lowest level since 2014, as the...

By Infosecurity Magazine
Number of Cybersecurity Pros Surges 194% in Four Years
NewsJan 29, 2026

Number of Cybersecurity Pros Surges 194% in Four Years

The UK cybersecurity workforce has exploded, rising 194% between December 2021 and June 2025 to reach 83,700 professionals. This makes cyber the fifth‑fastest‑growing occupation and the most rapidly expanding IT role, outpacing the sector’s average 9.6% growth. Despite the surge, a talent...

By Infosecurity Magazine
Critical and High Severity N8n Sandbox Flaws Allow RCE
NewsJan 28, 2026

Critical and High Severity N8n Sandbox Flaws Allow RCE

Two critical sandbox bypasses were discovered in the n8n workflow automation platform, affecting its JavaScript expression engine (CVE‑2026‑1470, CVSS 9.9) and Python Code node (CVE‑2026‑0863, CVSS 8.5). Both flaws let authenticated users escape the sandbox and execute arbitrary commands on the host...

By Infosecurity Magazine
Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign
NewsJan 28, 2026

Emojis in PureRAT’s Code Point to AI-Generated Malware Campaign

Researchers at Symantec and Carbon Black have uncovered a PureRAT trojan campaign that is being authored with artificial‑intelligence tools. The malware is distributed through phishing emails masquerading as job offers and contains code comments and emojis typical of AI‑generated scripts....

By Infosecurity Magazine
AI Security Threats Loom as Enterprise Usage Jumps 91%
NewsJan 28, 2026

AI Security Threats Loom as Enterprise Usage Jumps 91%

Zscaler’s ThreatLabz 2026 AI Security Report reveals a 91% surge in enterprise AI usage, encompassing 989.3 billion transactions across more than 3,400 applications in 2025. Despite this rapid adoption, every AI system examined harbored critical vulnerabilities, with 90% compromised within 90...

By Infosecurity Magazine
Researchers Uncover 454,000+ Malicious Open Source Packages
NewsJan 28, 2026

Researchers Uncover 454,000+ Malicious Open Source Packages

Security vendor Sonatype reported that developers downloaded 9.8 trillion open‑source components in 2025, yet 454,648 of the packages were newly identified as malicious. The report describes a shift from opportunistic spam to industrialized, often state‑sponsored campaigns that use typosquatting, namespace confusion,...

By Infosecurity Magazine
Over 80% of Ethical Hackers Now Use AI
NewsJan 27, 2026

Over 80% of Ethical Hackers Now Use AI

Bugcrowd’s latest report shows that 82% of ethical hackers now rely on AI, up from 64% a year earlier. The adoption enables faster, broader assessments and higher‑quality vulnerability reports, with automation and deep code analysis cited as primary use cases....

By Infosecurity Magazine
EScan Antivirus Supply Chain Breach Delivers Signed Malware
NewsJan 26, 2026

EScan Antivirus Supply Chain Breach Delivers Signed Malware

On January 20 2026, MicroWorld Technologies’ eScan antivirus was compromised through its legitimate update infrastructure, delivering digitally signed malware to global endpoints. The multi‑stage payload installed a 64‑bit backdoor, persisted via disguised scheduled tasks, and altered hosts and registry settings to block...

By Infosecurity Magazine
CISA Releases List of Post-Quantum Cryptography Product Categories
NewsJan 26, 2026

CISA Releases List of Post-Quantum Cryptography Product Categories

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released its first list of hardware and software product categories that support or are transitioning to post‑quantum cryptography (PQC) standards. The list, compiled with the NSA, follows Executive Order 14306 and targets cloud...

By Infosecurity Magazine
Researchers Uncover “Haxor” SEO Poisoning Marketplace
NewsJan 26, 2026

Researchers Uncover “Haxor” SEO Poisoning Marketplace

Security researchers uncovered the HaxorSEO (HxSEO) marketplace, a Telegram and WhatsApp‑based service that sells over 1,000 malicious backlinks from compromised, decades‑old domains. Each listing includes trust scores such as domain authority and is priced at $6, allowing threat actors to...

By Infosecurity Magazine
Law Firm Investigates Coupang Security Failures Ahead of Class Action Deadline
NewsJan 26, 2026

Law Firm Investigates Coupang Security Failures Ahead of Class Action Deadline

US law firm Hagens Berman is urging investors to join a class action against Coupang over a massive June 2025 cyber‑attack that exposed personal data of 33.7 million customers. The breach prompted a police raid, the resignation of CEO Park Dae‑Joon,...

By Infosecurity Magazine
NHS Issues Open Letter Demanding Improved Cybersecurity Standards From Suppliers
NewsJan 23, 2026

NHS Issues Open Letter Demanding Improved Cybersecurity Standards From Suppliers

The UK National Health Service has issued an open letter to suppliers, demanding proactive cybersecurity collaboration across the health and social care system. The initiative builds on last year’s voluntary supply‑chain charter and aligns with the Cyber Security and Resilience...

By Infosecurity Magazine
Critical Appsmith Flaw Enables Account Takeovers
NewsJan 22, 2026

Critical Appsmith Flaw Enables Account Takeovers

A critical authentication flaw (CVE‑2026‑22794) was discovered in Appsmith’s low‑code platform. The vulnerability stems from the password‑reset endpoint trusting the client‑supplied Origin header, allowing attackers to craft malicious reset links and capture tokens. Exploitation enables full account takeover, including admin...

By Infosecurity Magazine
RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites
NewsJan 22, 2026

RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites

A critical vulnerability (CVE‑2025‑67968) in the RealHomes CRM plugin, bundled with a popular WordPress real‑estate theme, affected over 30,000 sites. Versions 1.0.0 and earlier allowed any logged‑in subscriber to upload arbitrary files via a CSV import endpoint, enabling potential full...

By Infosecurity Magazine
Over 160,000 Companies Notify Regulators of GDPR Breaches
NewsJan 22, 2026

Over 160,000 Companies Notify Regulators of GDPR Breaches

Over 160,000 companies reported GDPR breaches in 2025, a 22% increase year‑over‑year. Daily average notifications jumped to 443, the first time since 2018 that the figure exceeded 400. Germany, the Netherlands and Poland accounted for the highest breach counts, while...

By Infosecurity Magazine