Infosec stories
Businesses face a fresh wave of identity theft-driven extortion as Helix is linked to BlackFile and ShinyHunters through shared infrastructure.
Asia-Pacific security teams can now keep regulated data in Singapore as Conifers expands its CognitiveSOC platform across the region.
Breaches are hitting lenders harder as AI adoption speeds up, with 98 per cent of affected firms saying the impact was material.
The cybersecurity company is tightening financial control and customer support as it expands internationally and seeks to protect recurring revenue.
A live fraud campaign targeting Mexican banks, fintechs and crypto services exposed how criminals are using generative AI to draft malware.
Malicious AI skills are helping criminals steal data and run malware, while QR-code phishing climbed 146% in the latest ESET report.
Security teams now see autonomous AI as a bigger internal danger, even as most say it is boosting productivity, a survey found.
Reduced staffing and delegated approvals during annual leave are giving fraudsters more chances to slip through corporate checks, Everywhen says.
Security teams could cut alert overload as Google ties exposed assets to live attacker activity, helping prioritise the riskiest flaws first.
Firms with manually rotated ADFS certificates could still be exposed, as attackers may recover live signing keys and forge SAML logins.
Users now have more local routing choices as ExpressVPN widens its app-selectable network to 214 locations in 113 countries.
Sensitive physics and engineering research at US and Canadian universities may have been exposed after hackers used Roundcube flaws to enter mail servers.
Vendor consolidation among managed service providers is pushing WatchGuard to sharpen its platform strategy as it appoints a new product chief.
The real risk is growing backlogs and patching delays, as AI speeds up exploit development faster than security teams can respond.
Healthcare providers face added pressure to secure AI systems and patient data as Rubrik joins a coalition of nearly 3,000 members.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
Security teams may be able to cut false alarms as Picus says its new platform proves whether a vulnerability can actually be exploited.
It targets defence and government teams needing to handle sensitive data in disconnected environments without direct internet access.
UK firms face mounting attack costs as NCC Group joins a government-backed push to put cyber risk on board agendas and across supply chains.
Staff confidence masks weak cyber readiness in the public sector, where more than a quarter report no effective training in a year or ever.