CISA Updates Insider Threat Guide With New Mitigation Advice Information Security Magazine 1 day 5 hours ago CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
MantaxOtax Android Malware Combines Ransomware With Spyware Information Security Magazine 1 day 6 hours ago MantaxOtax Android malware combines ransomware with extensive spyware capabilities
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors Information Security Magazine 1 day 6 hours ago The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Anthropic Reveals Yet Another Cybersecurity Incident Information Security Magazine 1 day 10 hours ago Anthropic has found a fourth case of its model accessing third-party systems without authorization
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee Information Security Magazine 1 day 11 hours ago The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls Information Security Magazine 2 days 4 hours ago The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Gigabud Uses Android App Cloning to Evade Fraud Detection Information Security Magazine 2 days 4 hours ago Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
ClickFix Moves into the Browser to Steal Cryptocurrency Information Security Magazine 2 days 5 hours ago ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers Information Security Magazine 2 days 6 hours ago SpyCloud claims non-human identities are the most likely route into the enterprise
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026 Information Security Magazine 2 days 9 hours ago The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
SAP Patches Maximum Severity “Overpass” Flaw Information Security Magazine 2 days 10 hours ago Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
France Establishes New Government-Focused Cyber Incident Response Unit Information Security Magazine 3 days 4 hours ago After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability
Grindr Settles UK Data Privacy Claims for £26m Information Security Magazine 3 days 6 hours ago Grindr settled UK claims over alleged unlawful processing of sensitive user data
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns Information Security Magazine 3 days 6 hours ago Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
THost9 Android RAT Pairs Packed Loader With ADB Worm Information Security Magazine 3 days 7 hours ago THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials Information Security Magazine 3 days 9 hours ago CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365
Trezor Supply Chain Breach Now Impacts 81,000 Customers Information Security Magazine 3 days 9 hours ago Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought
NCSC Warns Shadow AI Creates New Security Risks Information Security Magazine 4 days 5 hours ago NCSC warns unapproved AI tools can expose corporate data and create new security risks
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability Information Security Magazine 4 days 6 hours ago The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused Information Security Magazine 4 days 7 hours ago The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans