Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 13

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Phishing Campaign “I Paid Twice” Targets Booking.com Hotels and Guests

Kirsten DoyleNovember 11, 20256 Mins Read

A new phishing campaign uncovered by analysts at sekoia.io is exploiting the hospitality industry at scale, targeting both Booking.com partners and their guests in a sophisticated, multi-stage fraud scheme. Codenamed “I Paid Twice,” the operation combines infostealing malware, social engineering, and payment fraud, effectively turning compromised hotel accounts into launchpads for attacks against unsuspecting travellers. Hotels as the First Breach Point The campaign, active since at least April 2025, begins with spearphishing emails sent from compromised Booking.com partner accounts. These messages, often referencing genuine reservation IDs or guest requests, are convincing because they draw directly on real booking data that…

Read More

Microsoft Uncovers New Side-Channel Attack That Can Reveal Encrypted AI Chat Topics

Kirsten DoyleNovember 11, 20253 Mins Read

Microsoft has identified a new kind of side-channel attack capable of exposing the topics of encrypted conversations with remote language models, even when protected by Transport Layer Security (TLS).  Dubbed a streaming inference attack, the method allows an observer with access to network traffic (such as an ISP, local network monitor, or malicious actor on public Wi-Fi) to infer what a user is talking about with an AI system. The discovery underscores the growing privacy stakes around AI-powered chatbots now woven into everything from customer service to legal and healthcare assistance.  Even with end-to-end encryption in place, network-level observers can…

Read More

The 2025 OWASP Top 10: What’s New and Rising in AppSec Today

Kirsten DoyleNovember 10, 20255 Mins Read

The OWASP Top 10, the benchmark list of the most critical web application security risks, is back for its 8th edition, and the 2025 update tells a story: the fundamentals still matter, but the ecosystem has changed. Broken Access Control once again takes the top spot. It’s the flaw behind countless breaches, users seeing or doing things they shouldn’t. Nearly 4% of tested applications had at least one such weakness. Security Misconfiguration jumps from #5 to #2, reflecting how modern apps increasingly rely on complex configurations that can be easily mismanaged. A single toggle or default left open can expose…

Read More

The Most Advanced ClickFix Page Yet: What It Signals About the Future of Malicious Copy-and-Paste Attacks

Kirsten DoyleNovember 10, 20256 Mins Read

ClickFix attacks have exploded over the last year, evolving into one of the most effective forms of social engineering seen in the wild. By convincing users to copy and run malicious code on their own devices, bad actors have turned one of the oldest trust mechanisms in computing (copy-and-paste) into a weapon.  At Push Security’s recent threat briefing in London, researchers showcased the most sophisticated ClickFix page observed to date. It’s a glimpse into how fast these attacks are developing, and how far they’ve come from crude proof-of-concepts just a year ago. A New Level of Deception The standout example…

Read More

Federated Threat: Scattered LAPSUS$ Hunters Marks New Era of Cybercrime Collaboration

Kirsten DoyleNovember 7, 20258 Mins Read

A new cybercrime alliance is taking shape. The emerging collective (combining three of the most notorious groups, Scattered Spider, LAPSUS$, and ShinyHunters) has launched no fewer than 16 Telegram channels since 8 August 8. In a new advisory, Trustwave SpiderLabs says the group, now dubbed Scattered LAPSUS$ Hunters (SLH), is positioning itself as a federated collective. It’s a shift from earlier hints of tactical cooperation to something a lot more structured and persistent. “Since its debut, the group’s Telegram channels have been removed and recreated at least 16 times under varying iterations of the original name – a recurring cycle…

Read More

Microsoft Teams Flaws Expose New Risks in Workplace Collaboration

Kirsten DoyleNovember 5, 20255 Mins Read

Trust has always been the glue of digital collaboration, but new research shows it can also be the weak link. Check Point Research has uncovered multiple vulnerabilities in Microsoft Teams that could allow bad actors to impersonate executives, alter chat history, and spoof notifications, all without detection. With over 320 million active users, Teams has become a key channel for business communication, powering meetings, decisions, and day-to-day teamwork across organizations. But these new findings highlight how attackers can exploit the very trust that makes these platforms work.  “Trust alone isn’t a security strategy,” the researchers warned. “Collaboration tools are now…

Read More

Google’s Enhanced Chrome Autofill Raises Both Convenience and Security Questions

Kirsten DoyleNovember 5, 20256 Mins Read

Google is rolling out an enhanced autofill feature for Chrome designed to make filling out online forms faster and easier, security experts are urging caution. According to Google’s announcement, the new version of autofill will go beyond storing basic data like names and addresses. Chrome will now be able to save and automatically populate sensitive details such as driver’s license numbers, passport information, and vehicle VINs, with Google emphasizing that privacy and control remain central. “We’ve designed enhanced autofill to be private and secure. When you enter relevant info into a form, Chrome will save this data only with your…

Read More

Threat actors weaponize judicial documents to deliver PureHVNC RAT

Kirsten DoyleNovember 4, 20253 Mins Read

Between August and October 2025, a tightly targeted phishing campaign tricked Colombian and other Spanish-speaking users into opening what looked like official court notices, Cyber Security News reports. The lure in this instance, is lawsuits and labor-court paperwork. The bait was believable, and the fallout was full system access. Victims received emails that masqueraded as messages from Colombia’s Attorney General’s office. Each message carried an SVG attachment. That file pointed to a Google Drive preview.   Click the preview and a download begins. The download is a password-protected ZIP. Inside sits an executable with a judiciary-themed name. It looks official, but…

Read More

MedImpact Confirms Ransomware Attack as Qilin Claims Responsibility

Kirsten DoyleOctober 30, 20253 Mins Read

US pharmacy benefit manager MedImpact confirmed that a ransomware attack was behind recent system outages, after the Qilin gang claimed responsibility and said it had exfiltrated company data.  The San Diego–based firm, which serves more than 50 million members and processes over a million healthcare claims each day, said it had identified “ransomware on certain systems” and immediately began “implementing containment and mitigation measures.” “MedImpact is currently working to restore impacted systems in a new environment that is segregated from the prior infrastructure and protected by multiple layers of defense,” the company said. It added that pharmacy claims for all…

Read More

Cybercriminals Claim to Leak HSBC USA Customer Data, Bank Denies Breach

Kirsten DoyleOctober 30, 20255 Mins Read

Cybercriminals have posted data online allegedly containing the personal and financial details of HSBC USA customers, including bank account numbers, transaction records, and Social Security numbers. Researchers at Cybernews say early indicators suggest the leak may be legitimate, HSBC insists its systems remain uncompromised. The attackers published the data on a well-known leak forum commonly used to trade or publicize stolen information. They claimed the database was obtained through a “coordinated effort.” The post includes a sample dataset that apparently lists customer names, addresses, birthdates, phone numbers, emails, stock orders, and account details. In response to the threat actor’s claims,…

Read More
Previous 1 … 11 12 13 14 15 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}