Wiper Attack on Polish Power Grid Linked to Russia’s Sandworm Information Security Magazine 2 months ago A destructive cyber attack targeting Poland’s energy sector has been linked to Russian APT group Sandworm
NHS Issues Open Letter Demanding Improved Cybersecurity Standards from Suppliers Information Security Magazine 2 months 1 week ago Open letter by NHS technology leaders outlines plans to identify risks to software supply chain security across health and social care system
Under Armour Investigates Data Breach After 72 Million Records Allegedly Exposed Information Security Magazine 2 months 1 week ago Under Armour said there is no evidence at this point to suggest the incident affected systems used to process payments or store customer passwords
Critical Appsmith Flaw Enables Account Takeovers Information Security Magazine 2 months 1 week ago Critical vulnerability in Appsmith allows account takeover via flawed password reset process
RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites Information Security Magazine 2 months 1 week ago Security flaw in RealHomes CRM plugin allowed file uploads; patches released for 30,000+ sites
Zero-Day Exploits Surge, Nearly 30% of Flaws Attacked Before Disclosure Information Security Magazine 2 months 1 week ago VulnCheck analysts found that vulnerabilities exploited before being publicly disclosed rose from 23.6% in 2024 to 28.96% in 2025
LastPass Warns of Phishing Campaign Attempting to Steal Master Passwords Information Security Magazine 2 months 1 week ago Phoney email alerts suggest users need to backup their LastPass accounts within 24 hours. LastPass says it would never require this action from users
UK Executives Warn They May Not Survive a Major Cyber-Attack, Vodafone Survey Finds Information Security Magazine 2 months 1 week ago UK Executives Warn They May Not Survive a Major Cyber-Attack, Vodafone Survey Finds
Over 160,000 Companies Notify Regulators of GDPR Breaches Information Security Magazine 2 months 1 week ago DLA Piper finds 22% increase in breached firms notifying European GDPR regulators
Phishing and Spoofed Sites Remain Primary Entry Points For Olympics Information Security Magazine 2 months 1 week ago Cyber risks for the Milano-Cortina 2026 Winter Games include phishing and spoofed websites as key threat vectors
Peruvian Loan Scam Harvests Cards and PINs via Fake Applications Information Security Magazine 2 months 1 week ago Loan phishing operation in Peru is stealing card info by impersonating financial institutions
VoidLink Linux Malware Was Built Using an AI Agent, Researchers Reveal Information Security Magazine 2 months 1 week ago Sophisticated malware previously thought to be the work of a well-resourced cyber-crime group was built by one person - with the aid of AI tools
EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act Information Security Magazine 2 months 1 week ago The EU’s Cybersecurity Act 2.0 will aim to address some of the challenges of the current CSA, including the slow rollout of certification schemes
Experts Welcome Global Cybersecurity Vulnerability Enumeration Launch Information Security Magazine 2 months 1 week ago A new service, the Global Cybersecurity Vulnerability Enumeration (GCVE), offers an alternative to the US-led CVE
Report Fraud Promises to Streamline Fight Against Economic Crime Information Security Magazine 2 months 1 week ago City of London Police has launched the UK’s national Report Fraud service
Risk of AI Model Collapse to Drive Zero Trust Data Governance, Gartner Says Information Security Magazine 2 months 1 week ago Gartner predicts 50% of organizations will adopt zero trust data governance by 2028
Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps Information Security Magazine 2 months 1 week ago 2 security vulnerabilities in the Chainlit framework expose risks from web flaws in AI applications
Prompt Injection Bugs Found in Official Anthropic Git MCP Server Information Security Magazine 2 months 1 week ago Three vulnerabilities in Anthropic's Git server for the MCP can be exploited via prompt injection
Cyber Risks Among CEOs’ Top Worries Amid Weak Short Term Growth Outlook Information Security Magazine 2 months 1 week ago PwC’s 29th Global CEO Survey shows cyber risk rising to the top of CEO concerns as confidence in short term business growth weakens
LinkedIn Phishing Campaign Exploits Open-Source Pen Testing Tool to Compromise Business Execs Information Security Magazine 2 months 1 week ago Cybersecurity Researchers at ReliaQuest warn of an ongoing campaign delivered to “high-value individuals” via LinkedIn messages