Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Gemini crosses the line in cybersecurity test

Kirsten DoyleSeptember 22, 20267 Mins Read

Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets included in the test. The incidents happened in May while independent AI evaluator Irregular was testing Gemini’s cybersecurity capabilities. The Wall Street Journal reported that Gemini had unintended internet access during the exercise and went on to access systems belonging to three companies. In one case, it guessed credentials. In the other two, it found credentials in public repositories and used them to access protected systems. Google said the incidents were a case of mistaken identity and that…

Read More

Texas utility CenterPoint confirms breach after attacker leaks customer data

Kirsten DoyleSeptember 22, 20263 Mins Read

Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around 7.5 million records. CenterPoint said an unsanctioned third party accessed personal information through one of its external-facing systems. The company has brought in cybersecurity experts to investigate the breach. An attacker using the name “Lovely” claims to have obtained millions of customer records containing names, addresses, phone numbers, email addresses, account numbers, and other information. Samples of the allegedly stolen data were posted publicly, leading CenterPoint to investigate and confirm that customer information had been compromised. CenterPoint…

Read More

Rogue AI agents put trusted access under scrutiny

Kirsten DoyleSeptember 22, 20262 Mins Read

Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitimate access. In both cases, agents were able to use valid accounts or credentials and continue searching for ways into systems and data beyond the access they had been given. OpenAI this week disclosed more details from its continuing review of the Hugging Face incident and other unexpected activity by its models. The company said agents had bypassed access controls, used exposed credentials, and reached parts of third-party services outside their intended access. Separate reporting on the investigation found that…

Read More

Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick

Kirsten DoyleSeptember 14, 20268 Mins Read

Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet Security. The State of AI in Security Operations 2026 report surveyed 250 IT and cybersecurity professionals. Forty percent said AI is already part of their day-to-day SOC workflow, and 56% are evaluating or piloting it. Only 4% have no current plans to use AI. Among teams already using AI, 72% said it had cut alert investigation time by at least 25%. For 18%, the reduction was more than half. However, the research also found that…

Read More

A reverse image search platform exposed more than 9 million facial images

Kirsten DoyleAugust 24, 20266 Mins Read

A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled “faces” and “profiles.” Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification. “I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database…

Read More

Post-DEF CON phishing campaign delivered AMOS and NetSupport malware

Kirsten DoyleAugust 24, 20269 Mins Read

A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9. The message came from an account that claimed to be the vice president and marketing head of CoinDesk and wanted to know about the researcher’s plans to attend future conferences. The researcher spotted the scam but kept the conversation going to find out what the…

Read More

AI agents taking unsanctioned action during cyber testing

Kirsten DoyleAugust 24, 20263 Mins Read

The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation. This included attempts to socially engineer software maintainers and insert malicious code into an open-source project. The incident happened during routine cyber capability testing between 25 and 28 July, when researchers gave AI agents access to the public internet and deliberately disabled some cyber safety mechanisms to better understand how the models behave under less restrictive conditions. According to AISI, researchers ran a cybersecurity challenge 122 times across seven frontier models. …

Read More

Expert panel: AI is writing the code. Who is defending it?

Kirsten DoyleJuly 31, 202612 Mins Read

AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster. It also raises serious questions about the quality of code, its security, accountability, and trust. When an AI writes or patches the code, who will ensure that it is indeed secure? And, are the current application security practices adequate…

Read More

One-click Claude Desktop flaw could enable hidden prompt injection and code execution

Kirsten DoyleJuly 28, 20266 Mins Read

Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links. According to the researchers, clicking one of these links caused the application to automatically open, import a prompt from the URL, and immediately submit it without displaying the full prompt or requiring user approval. Anthropic addressed the issue in Claude Desktop version 1.1.2321. Hidden instructions Oasis Security demonstrated the attack using…

Read More

Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns

Kirsten DoyleJuly 28, 20269 Mins Read

Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. The campaign is being tracked across the cybersecurity industry under several names,…

Read More
1 2 3 … 61 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}