Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Expert panel: AI is writing the code. Who is defending it?

Kirsten DoyleJuly 31, 202612 Mins Read

AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster. It also raises serious questions about the quality of code, its security, accountability, and trust. When an AI writes or patches the code, who will ensure that it is indeed secure? And, are the current application security practices adequate…

Read More

One-click Claude Desktop flaw could enable hidden prompt injection and code execution

Kirsten DoyleJuly 28, 20266 Mins Read

Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links. According to the researchers, clicking one of these links caused the application to automatically open, import a prompt from the URL, and immediately submit it without displaying the full prompt or requiring user approval. Anthropic addressed the issue in Claude Desktop version 1.1.2321. Hidden instructions Oasis Security demonstrated the attack using…

Read More

Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns

Kirsten DoyleJuly 28, 20269 Mins Read

Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. The campaign is being tracked across the cybersecurity industry under several names,…

Read More

Americans are ignoring scam calls, but phishing emails still fool many

Kirsten DoyleJuly 15, 20266 Mins Read

Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed a call from a doctor, hospital, or healthcare provider, while others report missing calls from employers, pharmacies, financial institutions, government agencies, and even family emergencies. The findings come at a time when cybercrime losses have hit a new all-time high. According to the FBI’s Internet…

Read More

Sysdig uncovers first documented agentic ransomware operation

Kirsten DoyleJuly 10, 20265 Mins Read

Security researchers at Sysdig have documented what they believe is the first documented case of an AI agent running a ransomware operation from end to end. Dubbed JADEPUFFER, the operation used a large language model (LLM) to automate an attack that began with the exploitation of an internet-facing Langflow instance and ended in destructive database extortion. Sysdig’s research describes an AI-driven campaign that adapted to failures, harvested credentials, searched for sensitive data, moved toward its intended target, and attacked a production database server. The attackers initially exploited CVE-2025-3248, a missing-authentication vulnerability in Langflow’s code validation endpoint that allows unauthenticated remote…

Read More

AI-assisted software engineering is creating a new delivery paradox

Kirsten DoyleJuly 10, 20267 Mins Read

AI can generate code faster than most software organizations can absorb it. This should be a productivity breakthrough, but it also exposes a larger problem: many of the processes surrounding software delivery still happen at human speed. A new white paper from code4thought looks at what happens when AI changes how quickly teams write software, and what software engineering produces, how organizations govern it, and where engineers add the most value. AI-Assisted Software Engineering: The New Delivery Paradox pulls from six in-depth conversations covering security, product engineering, academic research, regulated industry, retail banking, and AI assurance. The expert contributors do…

Read More

Klue supply chain breach exposes Salesforce data at several security firms

Kirsten DoyleJune 24, 20266 Mins Read

A supply chain attack targeting Klue, a competitive intelligence platform, has lead to the theft of Salesforce data from multiple entities, including several cybersecurity vendors. Klue disclosed that threat actors had gained unauthorized access to part of its integration infrastructure in June after compromising a legacy credential linked to a backend system. “Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce,” Klue said. According to incident investigations published by Huntress and other…

Read More

AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

Kirsten DoyleJune 19, 20265 Mins Read

AI-powered attacks are the biggest cybersecurity concern among security professionals. Forty-one percent identified AI-powered attacks at scale as their biggest security concern, nearly double the number citing supply chain risk (21%) or unknown threats (21%). AI-driven threats and what security professionals are doing about them is also the top concern for nearly one in three boards (32%). These were some of the findings of new research conducted by Filigran during Infosecurity Europe 2026.  A new phase of threat-informed defence The survey of 168 cybersecurity professionals across various industry sectors, suggest that organisations are entering a new phase of threat-informed defence,…

Read More

ShinyHunters targets Oracle PeopleSoft customers through critical zero-day

Kirsten DoyleJune 19, 20263 Mins Read

Oracle has issued a security alert to customers about a critical vulnerability affecting PeopleSoft environments after the notorious threat actor ShinyHunters claimed it used a previously unknown flaw to compromise over 100 entities. The vulnerability CVE-2026-35273 is in Oracle PeopleSoft PeopleTools, and has a CVSS score of 9.8/10. “Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability. This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution,” the alert read. ShinyHunters said they exploited a zero-day vulnerability in Oracle PeopleSoft systems to gain access to customer environments and steal…

Read More

SIG report: AI-generated code is linked to twice the security risk and rising technical debt

Kirsten DoyleJune 11, 20264 Mins Read

AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG) 2026 State of Software report, which analyzed more than 30,000 software systems and more than 400 billion lines of code. In other words, even though artificial intelligence is helping businesses to develop software more rapidly, software governance and quality management processes lag behind. The report revealed that 90% of IT workers currently use AI on their jobs, with AI-produced code…

Read More
1 2 3 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}