Topic: information security
-
Credential Theft Surges: 1.7B Logins Stolen in Six Months
Infostealer malware stole "1.7 billion credentials" in the first half of 2026, marking a major escalation as attackers prioritize harvesting valid logins over phishing or brute force. Malware-as-a-service operations have enabled lower-skilled actors to deploy infostealers at scale, targeting br...
Read More » -
Debunking the Air Gap Myth and Other OT Security Realities
Attackers no longer target data theft but aim to take control of industrial operations, making traditional defenses like the air gap largely obsolete. The air gap is a myth because modern industrial networks are routinely bridged by maintenance laptops, vendor connections, and remote access, crea...
Read More » -
Kodak confirms data breach linked to ShinyHunters extortion
Kodak is investigating a security breach by the ShinyHunters extortion group, which accessed some corporate data, and is working with external cybersecurity specialists to assess the scope. The attack did not affect Kodak's core manufacturing operations or customer-facing systems, and no financia...
Read More » -
Half of Polymarket’s high-risk military bets now pay off
A study by the Anti-Corruption Data Collective found that high-risk bets on Polymarket regarding military and defense actions succeed 52% of the time, far exceeding the platform's overall 14% win rate, raising concerns about insider trading with classified information. The findings come amid the ...
Read More » -
NIST to prioritize only high-risk CVEs amid NVD backlog
NIST is shifting the National Vulnerability Database (NVD) to a risk-based model, prioritizing analysis of only the most critical vulnerabilities due to an overwhelming surge in CVE submissions. Under this new framework, detailed enrichment like severity scores and remediation guidance will be re...
Read More » -
Big Tech Nears Critical AI Security Threshold
The security of global digital infrastructure is threatened by quantum computers, which can break current cryptographic algorithms like RSA and ECC, necessitating a transition to new quantum-resistant standards. A historical breach in 2010, where the Flame malware exploited the weak MD5 hash func...
Read More » -
McGraw-Hill Data Breach Confirmed After Extortion Threat
A cybercriminal group breached McGraw Hill by exploiting a misconfiguration in its Salesforce environment, highlighting the threat of third-party software vulnerabilities. The company confirmed the breach did not compromise student-facing platforms or sensitive student data; only internal corpora...
Read More » -
FBI warns about foreign mobile apps in new PSA
The FBI has issued a warning about potential risks from downloading certain foreign mobile apps, specifically highlighting those developed by companies based in China. Authorities express concern that these apps could allow foreign governments to access sensitive user data, threatening national s...
Read More » -
iPhone 18 Pro May Drop Apple's Signature Finish
Apple's upcoming iPhone 18 Pro models will reportedly omit the signature Pro-exclusive gold finish, marking a significant departure from a long-standing design tradition. The change, sourced from supply chain reports, suggests Apple may be reevaluating its aesthetic strategy to align with new con...
Read More » -
DeepLoad Malware Uses AI Code to Evade Security
A sophisticated malware campaign is actively targeting enterprise credentials, using AI-generated code to adapt and evade traditional signature-based security detection. The campaign, attributed to a well-resourced group, focuses on stealing login information to enable further network intrusion, ...
Read More » -
Apple iPhones and iPads Cleared for Classified Government Data
Apple iPhones and iPads running iOS/iPadOS 26 have received official NATO certification to handle classified government data, marking the first time a mainstream consumer product meets such stringent security standards out of the box. This certification, built on a prior German government evaluat...
Read More » -
Coupang CEO Resigns Amid Police Raid Over Data Breach
Coupang's CEO resigned after a massive data breach affecting 33.7 million users, far more than initially reported, and publicly accepted responsibility for the incident and its handling. South Korean police raided Coupang's headquarters and are investigating a former employee, while U.S.-based pa...
Read More » -
Why Martech Needs Quality Management to Succeed
Martech practitioners are essential for integrating quality management processes like QA and UAT, bridging marketing and IT to ensure projects meet business needs and avoid significant risks. Quality assurance focuses on technical system integrity, while user acceptance testing evaluates the cust...
Read More » -
Pentagon report: Pete Hegseth violated military policies
A Pentagon investigation found former Defense Secretary Pete Hegseth violated DoD protocols by using a personal messaging app to discuss sensitive military information, risking its compromise. The inquiry, hampered by the app's auto-delete function, stemmed from a group chat that inadvertently in...
Read More » -
Asahi Cyber-Attack: 1.5 Million Customers' Data Breached
The Asahi Group suffered a major cybersecurity breach in September 2025, compromising personal data of nearly two million individuals, including names, addresses, and contact details, but not credit card information. The ransomware attack by the Qilin group caused significant operational disrupti...
Read More » -
Asahi Data Breach Exposes 1.5 Million Customers
Asahi Group Holdings confirmed a September cyberattack affected about 1.9 million individuals, exposing personal details like names, addresses, and contact information, but no financial data was compromised. The Qilin ransomware group claimed responsibility, releasing stolen data samples after th...
Read More » -
Achieve SOC 2 & ISO 27001 Backup Compliance
SOC 2 and ISO 27001 require a systematic approach to data backup, treating it as verifiable proof of operational integrity and security commitments, not just disaster recovery. SOC 2 is a U.S. audit framework focused on five Trust Services Criteria, with security as mandatory, while ISO 27001 is ...
Read More » -
Can Anthropic's AI Safety Plan Stop a Nuclear Threat?
Anthropic is collaborating with US government agencies to prevent its AI chatbot Claude from assisting with nuclear weapons development by implementing safeguards against sensitive information disclosure. The partnership uses Amazon's secure cloud infrastructure for rigorous testing and developme...
Read More » -
Australian Clinical Labs Fined for Medlab Pathology Data Breach
Australian Clinical Labs was fined $5.8 million for a 2022 data breach affecting over 223,000 people, marking the first civil penalties issued under the Privacy Act 1988. The penalties were imposed for failing to protect personal information, assess the breach promptly, and report it to the Commi...
Read More » -
Warp Agentic: The Top Development Tool of 2025
Warp Agentic is a leading 2025 development tool that boosts productivity through integrated code generation, debugging, and project management features. It enhances team collaboration with real-time shared workspaces and reduces delays from communication and version control issues. The platform o...
Read More »