Infosecurity Magazine (RSS)
infosec-magazine · C · active
https://www.infosecurity-magazine.com/rss/news/
Industry news (added 2026-05-08). Feed returned 5 dated items 2026-05-07/08. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://www.infosecurity-magazine.com/rss/news/ 5 (listing) then webfetch the per-article URL for the body. AVOID: Nothing to avoid; RSS and article WebFetch both work.. | 2026-07-05 admiralty audit: C, reputable trade press, mostly re-reporting with some original interviews; corroborate before acting. MEDIUM->C, stays active.
Cited in 23 entries
Citation cadence
Citation days per ISO week (18 weeks of coverage span, total 18).
- Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network2026-09-03
- Unisoc T612 modem (and other devices on shared Unisoc modem firmware): a single answered video call can escalate from modem-level RCE to full Android kernel access via an ARM Memory Protection Unit isolation bypass; no CVE, no patch, vendor unresponsive2026-08-28
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector2026-08-28
- Beacon CRM tells around 1,500 UK charities to assume everything they stored was taken, a compromised access key, exfiltrated backups, and encryption its experts think the attacker could undo2026-08-08
- Talos analyses threat actors' own AI coding-assistant prompt logs: guardrails fell to unverified permission claims, and the operator's skill (not model access) decided what got built2026-08-05
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C22026-07-21
- Cruciferra: a crypter-as-a-service using kernel-aware process ghosting and BYOVD EDR termination, tied to China-nexus TA49222026-07-21
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records2026-07-11
- GodDamn ransomware (Beast/Monster rebrand) blinds EDR with 'PoisonX', a malicious kernel driver Microsoft signed2026-07-11
- GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant2026-07-11
- 'Friendly Fire': prompt injection hijacks AI coding agents' defensive auto-review into remote code execution2026-07-11
- JADEPUFFER, Sysdig documents an autonomous, LLM-driven ransomware operation entering via Langflow CVE-2025-32482026-07-04
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2026-06-29
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid2026-06-27
- macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst2026-06-26
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access2026-06-19
- 15 malicious JetBrains Marketplace plugins exfiltrate AI provider API keys on "Apply"2026-06-18
- Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm2026-06-02
- ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset2026-05-30
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed2026-05-08