Infosecurity News

  1. Google to Switch on E2EE for All Gmail Users

    Google is set to roll out end-to-end encryption for all Gmail users, boosting security, compliance and data sovereignty efforts

  2. Cybercriminals Expand Use of Lookalike Domains in Email Attacks

    BlueVoyant found that the use of lookalike domains in email-based attacks is allowing actors to extend the types of individuals and organizations being targeted

  3. Cyber Security and Resilience Bill Will Apply to 1000 UK Firms

    A thousand UK service providers will be expected to comply with the forthcoming Cyber Security and Resilience Bill

  4. New Malware Variant RESURGE Exploits Ivanti Vulnerability

    CISA recommends immediate action to address malware variant RESURGE exploiting Ivanti vulnerability CVE-2025-0282

  5. ClickFake Interview Campaign by Lazarus Targets Crypto Job Seekers

    New “ClickFake Interview” campaign attributed to the Lazarus Group targets crypto professionals with fake job offers

  6. EU Commission to Invest €1.3bn in Cybersecurity and AI

    The funding will go to several projects within the Digital Europe Programme (DIGITAL) work program for 2025 to 2027

  7. NCSC Urges Users to Patch Next.js Flaw Immediately

    The UK’s National Cyber Security Agency has called on Next.js users to patch CVE-2025-29927

  8. US Seizes $8.2m from Romance Baiting Scammers

    The DoJ has managed to recoup over $8m from scammers, stolen in romance baiting schemes

  9. Solar Power System Vulnerabilities Could Result in Blackouts

    Forescout researchers found multiple vulnerabilities in leading solar power system manufacturers, which could be exploited to cause emergencies and blackouts

  10. Nine in Ten Healthcare Organizations Use the Most Vulnerable IoT Devices

    Claroty revealed that 89% of healthcare organizations use the top 1% of riskiest Internet-of-Medical-Things (IoMT) devices

  11. Trump CISA Cuts Threaten US Election Integrity, Experts Warn

    Expert speakers discussed the impact of reported cutbacks to CISA on the ability of local officials to protect against surging cyber-attacks on US election infrastructure

  12. Morphing Meerkat PhaaS Platform Spoofs 100+ Brands

    A PhaaS platform, dubbed 'Morphing Meerkat,' uses DNS MX records to spoof over 100 brands and steal credentials, according to Infoblox Threat Intel

  13. CoffeeLoader Malware Loader Linked to SmokeLoader Operations

    Newly identified CoffeeLoader uses multiple evasion techniques and persistence mechanisms to deploy payloads and bypass endpoint security

  14. PJobRAT Malware Targets Users in Taiwan via Fake Apps

    PJobRAT malware targets Taiwan Android users, stealing data through fake messaging platforms

  15. No MFA? Expect Hefty Fines, UK’s ICO Warns

    The ICO’s Deputy Commissioner told Infosecurity that organizations that fail to implement MFA and suffer a breach can expect heavy penalties

  16. Chinese Spy Group FamousSparrow Back with a Vengeance, Targets US

    Once considered inactive, the Chinese cyber espionage group FamousSparrow has reemerged, targeting organizations across the US, Mexico and Honduras

  17. NCA Warns of Sadistic Online “Com” Networks

    The UK’s National Crime Agency is warning of a growing cyber and physical threat from homegrown teens

  18. NCSC Urges Domain Registrars to Improve Security

    The UK’s National Cyber Security Centre has released new guidance to help domain registrars enhance security

  19. SecurityScorecard Observes Surge in Third-Party Breaches

    In its 2025 Global Third-Party Breach Report, SecurityScorecard has found that 35.5% of all cyber breaches in 2024 were third-party related, up from 29% in 2023

  20. Threat Actors Abuse Trust in Cloud Collaboration Platforms

    Threat actors are exploiting cloud platforms like Adobe and Dropbox to evade email gateways and steal credentials

What’s hot on Infosecurity Magazine?