Infosecurity News

  1. CrushFTP Vulnerability Exploited Following Disclosure Issues

    A critical authentication bypass flaw in CrushFTP is under active exploitation following a mishandled disclosure process

  2. Amateur Hacker Leverages Russian Bulletproof Hosting Server to Spread Malware

    The cybercriminal uses the service of Proton66, an infamous Russian-based bulletproof hosting provider, to deploy malware

  3. Sensitive Data Breached in Highline Schools Ransomware Incident

    Highline Public Schools revealed that sensitive personal, financial and medical data was accessed by ransomware attackers during the September 2024 incident

  4. Over Half of Attacks on Electricity and Water Firms Are Destructive

    Semperis claims 62% of water and electricity providers were hit by cyber-attacks in the past year

  5. Nearly 600 Phishing Domains Emerge Following Bybit Heist

    BforeAI researchers discover 596 suspicious Bybit-themed domains designed to defraud visitors

  6. Stripe API Skimming Campaign Unveils New Techniques for Theft

    A novel skimming attack has been observed by Jscramber, using the Stripe API to steal payment information by injecting malicious scripts into pages

  7. Royal Mail Investigates Data Breach Affecting Supplier

    A cyber threat actor has claimed to have leaked 144GB of data from Royal Mail users

  8. Gray Bots Surge as Generative AI Scraper Activity Increases

    Gray bots surge as generative AI scraper activity increases, impacting web applications with millions of requests daily

  9. Bybit Heist Fuels Record Crypto-Theft Surge, Says CertiK

    Hackers stole $1.67bn of cryptocurrencies in the first quarter of 2025, a 303% increase

  10. North Korea's Fake IT Worker Scheme Sets Sights on Europe

    Google has found a significant increase in North Korean actors attempting to gain employment as IT workers in European companies, leading to data theft and extortion

  11. Steam Surges to Top of Most Spoofed Brands List in Q1

    Gaming community Steam appeared most often in phishing emails and texts detected by Guardio in Q1 2025

  12. ICO Apologizes After Data Protection Response Snafu

    The UK’s data protection regulator says it is overwhelmed with complaints from the public

  13. WP Ultimate CSV Importer Flaws Expose 20,000 Websites to Attacks

    WP Ultimate CSV Importer flaws expose 20,000 websites to attacks enabling attackers to achieve full site compromise

  14. Ukraine Blames Russia for Railway Hack, Labels It "Act of Terrorism"

    The CERT-UA investigation concluded that the attack’s techniques were “characteristic of Russian intelligence services”

  15. New Phishing Attack Combines Vishing and DLL Sideloading Techniques

    A new attack targeting Microsoft Teams users used vishing, remote access tools and DLL sideloading to deploy a JavaScript backdoor

  16. Google to Switch on E2EE for All Gmail Users

    Google is set to roll out end-to-end encryption for all Gmail users, boosting security, compliance and data sovereignty efforts

  17. Cybercriminals Expand Use of Lookalike Domains in Email Attacks

    BlueVoyant found that the use of lookalike domains in email-based attacks is allowing actors to extend the types of individuals and organizations being targeted

  18. Cyber Security and Resilience Bill Will Apply to 1000 UK Firms

    A thousand UK service providers will be expected to comply with the forthcoming Cyber Security and Resilience Bill

  19. New Malware Variant RESURGE Exploits Ivanti Vulnerability

    CISA recommends immediate action to address malware variant RESURGE exploiting Ivanti vulnerability CVE-2025-0282

  20. ClickFake Interview Campaign by Lazarus Targets Crypto Job Seekers

    New “ClickFake Interview” campaign attributed to the Lazarus Group targets crypto professionals with fake job offers

What’s hot on Infosecurity Magazine?