Infosec stories - Page 4
China-aligned TA416 resumes spying on EU & Mideast
Last week
#
phishing
#
email security
#
cybersecurity
China-linked TA416 returns to spying on European diplomats and later expands attacks to Middle Eastern government targets after Iran conflict.
Commvault adds structured data controls for AI risk
Last week
#
data protection
#
dr
#
hybrid cloud
Commvault adds structured database controls to Commvault Cloud after Satori deal, aiming to curb AI-era exposure across live and backup data.
Vulnetix named Australia's first global CVE authority
Last week
#
malware
#
digital transformation
#
cloud security
Vulnetix expands AI coding defences as Australia's first Global CVE Numbering Authority, opening vulnerability tools to developers nationwide.
Avocado warns on code repository supply chain attacks
Last week
#
cloud security
#
phishing
#
application security
Avocado urges Australian firms to tighten repository security as the ACSC reissues a high alert on active supply chain attacks and secrets sprawl.
Cloudflare, WatchGuard warn cloud security assumptions fail
Last week
#
firewalls
#
data protection
#
digital transformation
Cloudflare and WatchGuard urge organisations to rethink cloud defences as rising identity attacks, AI risks and quantum threats expose weak spots.
GigaOm names Check Point leader in app & API security
This month
#
firewalls
#
devops
#
hybrid cloud
GigaOm names Check Point a third-year application security leader as its WAF posts strong detection rates and low false positives.
Attackers turn trusted tools into cyber weapon
This month
#
malware
#
ransomware
#
advanced persistent threat protection
Attackers abuse trusted tools, remote support software and stolen SSO sessions to breach systems, ReliaQuest says.
ChatGPT flaw let hackers steal data via DNS queries
This month
#
firewalls
#
data protection
#
devops
ChatGPT flaw may have let attackers siphon sensitive user data via DNS queries, prompting OpenAI to issue a fix after researchers exposed the bug.
Upwind hires ex-Facebook security chief Joe Sullivan
This month
#
data protection
#
cloud security
#
socs
Upwind taps former Facebook security chief Joe Sullivan to bolster cloud and AI strategy as it eyes enterprise buyers and rapid growth.
Zscaler flags Xloader malware's tougher obfuscation
This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.
Australian firms warned over AI & cloud cyber risks
This month
#
storage
#
data protection
#
hybrid cloud
Australian firms urged to tighten cloud defences as Zscaler and Reolink warn AI agents and connected cameras are widening cyber risk.
Secure.com guide says AI helps CISOs, but judgements matter
This month
#
data protection
#
digital transformation
#
advanced persistent threat protection
Secure.com urges Chief Information Security Officers to use AI for alert triage and threat detection, but keep human judgement in the loop.
QuSecure joins NIST project on post-quantum migration
This month
#
firewalls
#
data protection
#
encryption
QuSecure has joined a NIST-backed consortium to test tools and methods that help organisations find and replace quantum-vulnerable public-key systems.
DeepLoad malware steals credentials via ClickFix campaign
This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Login problems drive consumers away from digital services
This month
#
data protection
#
digital transformation
#
mfa
Thales report finds weak login and sign-up flows are pushing users away, as trust in AI, data handling and digital services remains low.
Firms warned on ransomware amid backup & AI sprawl
This month
#
saas
#
firewalls
#
data protection
Experts warn firms must improve visibility and backup resilience as automated ransomware campaigns and hidden SaaS and AI assets widen exposure.
Bitdefender launches free attack surface assessment
This month
#
firewalls
#
network security
#
pam
Bitdefender offers free 45-day internal security check to spot over-entitled staff access as attackers increasingly abuse trusted tools.
ExpressVPN launches private AI platform with secure enclaves
This month
#
data protection
#
vpns
#
devops
ExpressVPN expands beyond VPNs with encrypted AI chats, launching ExpressAI on confidential computing enclaves after an audit by cybersecurity firm Cure53.
CrowdStrike & HCLTech launch continuous threat service
This month
#
data protection
#
hybrid cloud
#
digital transformation
CrowdStrike and HCLTech deepen cybersecurity tie-up with a service to spot, prioritise and fix threats across cloud, identity and endpoints.
SonicWall flags SMB cyber gaps as attacks rise 20.8%
This month
#
firewalls
#
vpns
#
ransomware
SonicWall says small firms are being hit hardest by basic security lapses as ransomware, bot traffic and identity theft keep climbing.