Infosecurity News

  1. AI Surge Drives Record 1205% Increase in API Vulnerabilities

    AI-related API vulnerabilities surged 1,205% in 2024, with 99% tied to API flaws, according to a new report by Wallarm

  2. Nation-State Hackers Abuse Gemini AI Tool

    Google highlighted significant abuse of its Gemini LLM tool by nation state actors to support malicious activities, including research and malware development

  3. New Hellcat Ransomware Gang Employs Humiliation Tactics

    Cato Networks highlighted how the recently emerged HellCat ransomware group is using novel psychological tactics to court attention and pressurize victims

  4. Threat Actors Exploit Government Websites for Phishing

    Cybercriminals exploit government websites using open redirects and phishing tactics, bypassing secure email gateway protections

  5. Chinese GenAI Startup DeepSeek Sparks Global Privacy Debate

    Government agencies and privacy watchdogs have started investigating the Chinese AI chatbot provider over data privacy concerns

  6. Breakout Time Accelerates 22% as Cyber-Attacks Speed Up

    ReliaQuest warns threat actor innovation and infostealer activity helped to accelerate breakout time by 22% in 2024

  7. Scores of Critical UK Government IT Systems Have Major Security Holes

    The National Audit Office warns of major gaps in cyber resilience across UK government departments

  8. ENGlobal Cyber-Attack Exposes Sensitive Data

    Energy contractor ENGlobal reported that sensitive personal data was stolen by threat actors, with the incident disrupting operations for six weeks

  9. Lynx Ransomware Group Unveiled with Sophisticated Affiliate Program

    Group-IB researchers have exposed the highly organized affiliate platform and sophisticated operations of the Lynx Ransomware-as-a-Service group

  10. 58% of Ransomware Victims Forced to Shut Down Operations

    A Ponemon Institute survey highlighted the growing impact of ransomware attacks on victims’ revenue and reputation

  11. API Supply Chain Attacks Put Millions of Airline Users at Risk

    An API supply-chain attack affecting a popular online travel booking service put millions of airline users at risk

  12. Mega Data Breaches Push US Victim Count to 1.7 Billion

    The number of data breach victims increased 312% annually to exceed 1.7 billion in 2024, according to the ITRC 2024 Annual Data Breach Report

  13. EU Sanctions Three Russians For 2020 Cyber-Attack on Estonia

    The three Russian hackers are believed to be part of Unit 29155 of the GRU, also known as Cadet Blizzard, Ember Bear and Ruinous Ursa

  14. British Vishing-as-a-Service Trio Sentenced

    Three men have been sentenced after pleading guilty to running an account hijacking service for fraudsters

  15. Hidden Text Salting Disrupts Brand Name Detection Systems

    A new phishing tactic has been identified by Cisco Talos, using hidden text salting to evade email security measures

  16. SaaS Breaches Skyrocket 300% as Traditional Defenses Fall Short

    Obsidian found that threat actors are focusing on SaaS applications to steal sensitive data, with most organizations' security measures not set up to deal with these attacks

  17. New Phishing Campaign Targets Mobile Devices with Malicious PDFs

    A novel phishing campaign identified by Zimperium targets mobile users with malicious PDFs, impersonating USPS to steal credentials

  18. CISOs Boost Crisis Simulation Budgets Amid High-Profile Cyber-Attacks

    74% of CISOs plan to increase their cyber crisis simulation budgets in 2025

  19. Subaru Bug Enabled Remote Vehicle Tracking and Hijacking

    A now-patched vulnerability could have enabled threat actors to remotely control Subaru cars

  20. Change Healthcare Breach Almost Doubles in Size to 190 Million Victims

    Change Healthcare has claimed 190 million customers were affected by a mega-breach last year

What’s Hot on Infosecurity Magazine?