CISA Updates Insider Threat Guide With New Mitigation Advice Information Security Magazine 6 days 21 hours ago CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
MantaxOtax Android Malware Combines Ransomware With Spyware Information Security Magazine 6 days 22 hours ago MantaxOtax Android malware combines ransomware with extensive spyware capabilities
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors Information Security Magazine 6 days 23 hours ago The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Anthropic Reveals Yet Another Cybersecurity Incident Information Security Magazine 1 week ago Anthropic has found a fourth case of its model accessing third-party systems without authorization
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee Information Security Magazine 1 week ago The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls Information Security Magazine 1 week ago The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Gigabud Uses Android App Cloning to Evade Fraud Detection Information Security Magazine 1 week ago Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
ClickFix Moves into the Browser to Steal Cryptocurrency Information Security Magazine 1 week ago ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers Information Security Magazine 1 week ago SpyCloud claims non-human identities are the most likely route into the enterprise
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026 Information Security Magazine 1 week 1 day ago The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
SAP Patches Maximum Severity “Overpass” Flaw Information Security Magazine 1 week 1 day ago Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
France Establishes New Government-Focused Cyber Incident Response Unit Information Security Magazine 1 week 1 day ago After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability
Grindr Settles UK Data Privacy Claims for £26m Information Security Magazine 1 week 1 day ago Grindr settled UK claims over alleged unlawful processing of sensitive user data
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns Information Security Magazine 1 week 1 day ago Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
THost9 Android RAT Pairs Packed Loader With ADB Worm Information Security Magazine 1 week 2 days ago THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials Information Security Magazine 1 week 2 days ago CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365
Trezor Supply Chain Breach Now Impacts 81,000 Customers Information Security Magazine 1 week 2 days ago Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought
NCSC Warns Shadow AI Creates New Security Risks Information Security Magazine 1 week 2 days ago NCSC warns unapproved AI tools can expose corporate data and create new security risks
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability Information Security Magazine 1 week 2 days ago The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused Information Security Magazine 1 week 2 days ago The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans