Topic: information security

  • Credential Theft Surges: 1.7B Logins Stolen in Six Months

    Credential Theft Surges: 1.7B Logins Stolen in Six Months

    Infostealer malware stole "1.7 billion credentials" in the first half of 2026, marking a major escalation as attackers prioritize harvesting valid logins over phishing or brute force. Malware-as-a-service operations have enabled lower-skilled actors to deploy infostealers at scale, targeting br...

    Read More »
  • Debunking the Air Gap Myth and Other OT Security Realities

    Debunking the Air Gap Myth and Other OT Security Realities

    Attackers no longer target data theft but aim to take control of industrial operations, making traditional defenses like the air gap largely obsolete. The air gap is a myth because modern industrial networks are routinely bridged by maintenance laptops, vendor connections, and remote access, crea...

    Read More »
  • Kodak confirms data breach linked to ShinyHunters extortion

    Kodak confirms data breach linked to ShinyHunters extortion

    Kodak is investigating a security breach by the ShinyHunters extortion group, which accessed some corporate data, and is working with external cybersecurity specialists to assess the scope. The attack did not affect Kodak's core manufacturing operations or customer-facing systems, and no financia...

    Read More »
  • Half of Polymarket’s high-risk military bets now pay off

    Half of Polymarket’s high-risk military bets now pay off

    A study by the Anti-Corruption Data Collective found that high-risk bets on Polymarket regarding military and defense actions succeed 52% of the time, far exceeding the platform's overall 14% win rate, raising concerns about insider trading with classified information. The findings come amid the ...

    Read More »
  • NIST to prioritize only high-risk CVEs amid NVD backlog

    NIST to prioritize only high-risk CVEs amid NVD backlog

    NIST is shifting the National Vulnerability Database (NVD) to a risk-based model, prioritizing analysis of only the most critical vulnerabilities due to an overwhelming surge in CVE submissions. Under this new framework, detailed enrichment like severity scores and remediation guidance will be re...

    Read More »
  • Big Tech Nears Critical AI Security Threshold

    Big Tech Nears Critical AI Security Threshold

    The security of global digital infrastructure is threatened by quantum computers, which can break current cryptographic algorithms like RSA and ECC, necessitating a transition to new quantum-resistant standards. A historical breach in 2010, where the Flame malware exploited the weak MD5 hash func...

    Read More »
  • McGraw-Hill Data Breach Confirmed After Extortion Threat

    McGraw-Hill Data Breach Confirmed After Extortion Threat

    A cybercriminal group breached McGraw Hill by exploiting a misconfiguration in its Salesforce environment, highlighting the threat of third-party software vulnerabilities. The company confirmed the breach did not compromise student-facing platforms or sensitive student data; only internal corpora...

    Read More »
  • FBI warns about foreign mobile apps in new PSA

    FBI warns about foreign mobile apps in new PSA

    The FBI has issued a warning about potential risks from downloading certain foreign mobile apps, specifically highlighting those developed by companies based in China. Authorities express concern that these apps could allow foreign governments to access sensitive user data, threatening national s...

    Read More »
  • iPhone 18 Pro May Drop Apple's Signature Finish

    iPhone 18 Pro May Drop Apple's Signature Finish

    Apple's upcoming iPhone 18 Pro models will reportedly omit the signature Pro-exclusive gold finish, marking a significant departure from a long-standing design tradition. The change, sourced from supply chain reports, suggests Apple may be reevaluating its aesthetic strategy to align with new con...

    Read More »
  • DeepLoad Malware Uses AI Code to Evade Security

    DeepLoad Malware Uses AI Code to Evade Security

    A sophisticated malware campaign is actively targeting enterprise credentials, using AI-generated code to adapt and evade traditional signature-based security detection. The campaign, attributed to a well-resourced group, focuses on stealing login information to enable further network intrusion, ...

    Read More »
  • Apple iPhones and iPads Cleared for Classified Government Data

    Apple iPhones and iPads Cleared for Classified Government Data

    Apple iPhones and iPads running iOS/iPadOS 26 have received official NATO certification to handle classified government data, marking the first time a mainstream consumer product meets such stringent security standards out of the box. This certification, built on a prior German government evaluat...

    Read More »
  • Coupang CEO Resigns Amid Police Raid Over Data Breach

    Coupang CEO Resigns Amid Police Raid Over Data Breach

    Coupang's CEO resigned after a massive data breach affecting 33.7 million users, far more than initially reported, and publicly accepted responsibility for the incident and its handling. South Korean police raided Coupang's headquarters and are investigating a former employee, while U.S.-based pa...

    Read More »
  • Why Martech Needs Quality Management to Succeed

    Why Martech Needs Quality Management to Succeed

    Martech practitioners are essential for integrating quality management processes like QA and UAT, bridging marketing and IT to ensure projects meet business needs and avoid significant risks. Quality assurance focuses on technical system integrity, while user acceptance testing evaluates the cust...

    Read More »
  • Pentagon report: Pete Hegseth violated military policies

    Pentagon report: Pete Hegseth violated military policies

    A Pentagon investigation found former Defense Secretary Pete Hegseth violated DoD protocols by using a personal messaging app to discuss sensitive military information, risking its compromise. The inquiry, hampered by the app's auto-delete function, stemmed from a group chat that inadvertently in...

    Read More »
  • Asahi Cyber-Attack: 1.5 Million Customers' Data Breached

    Asahi Cyber-Attack: 1.5 Million Customers' Data Breached

    The Asahi Group suffered a major cybersecurity breach in September 2025, compromising personal data of nearly two million individuals, including names, addresses, and contact details, but not credit card information. The ransomware attack by the Qilin group caused significant operational disrupti...

    Read More »
  • Asahi Data Breach Exposes 1.5 Million Customers

    Asahi Data Breach Exposes 1.5 Million Customers

    Asahi Group Holdings confirmed a September cyberattack affected about 1.9 million individuals, exposing personal details like names, addresses, and contact information, but no financial data was compromised. The Qilin ransomware group claimed responsibility, releasing stolen data samples after th...

    Read More »
  • Achieve SOC 2 & ISO 27001 Backup Compliance

    Achieve SOC 2 & ISO 27001 Backup Compliance

    SOC 2 and ISO 27001 require a systematic approach to data backup, treating it as verifiable proof of operational integrity and security commitments, not just disaster recovery. SOC 2 is a U.S. audit framework focused on five Trust Services Criteria, with security as mandatory, while ISO 27001 is ...

    Read More »
  • Can Anthropic's AI Safety Plan Stop a Nuclear Threat?

    Can Anthropic's AI Safety Plan Stop a Nuclear Threat?

    Anthropic is collaborating with US government agencies to prevent its AI chatbot Claude from assisting with nuclear weapons development by implementing safeguards against sensitive information disclosure. The partnership uses Amazon's secure cloud infrastructure for rigorous testing and developme...

    Read More »
  • Australian Clinical Labs Fined for Medlab Pathology Data Breach

    Australian Clinical Labs Fined for Medlab Pathology Data Breach

    Australian Clinical Labs was fined $5.8 million for a 2022 data breach affecting over 223,000 people, marking the first civil penalties issued under the Privacy Act 1988. The penalties were imposed for failing to protect personal information, assess the breach promptly, and report it to the Commi...

    Read More »
  • Warp Agentic: The Top Development Tool of 2025

    Warp Agentic: The Top Development Tool of 2025

    Warp Agentic is a leading 2025 development tool that boosts productivity through integrated code generation, debugging, and project management features. It enhances team collaboration with real-time shared workspaces and reduces delays from communication and version control issues. The platform o...

    Read More »