Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 13

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Hackers Exploit Microsoft Entra Guest Invitations for Sophisticated TOAD Attacks

Kirsten DoyleNovember 19, 20253 Mins Read

A new wave of phishing attacks is exploiting Microsoft Entra’s guest user invitation system, turning a legitimate collaboration tool into a weapon for social engineering and credential theft, Cyber Security News reports.  Dubbed a TOAD (Telephone Oriented Attack Delivery) campaign, the attacks combine cloud-based account management with traditional phone scams, demonstrating a dangerous evolution in hybrid cybercrime tactics. Security researcher Michael Taggart uncovered the campaign after spotting multiple phishing operations abusing Entra’s guest invitation process. He said malefactors are weaponizing a trusted Microsoft service to bypass email security filters, combining cloud infrastructure abuse with classic phone scams, which makes detection extremely difficult. The campaign relies on Microsoft’s…

Read More

AI-Driven Espionage Campaign Disrupted After Abuse of Claude Code

Kirsten DoyleNovember 17, 20258 Mins Read

A Chinese state-sponsored cybercriminal group is believed to be behind what researchers say is the first documented cyber-espionage operation executed largely by AI rather than humans.   The campaign, detected in mid-September, used Anthropic’s Claude Code tool to probe and infiltrate around thirty organisations across tech, finance, chemicals, and government. According to Anthropic, the attackers leaned heavily on AI’s “agentic” features, using the model not as an assistant but as the primary operator of the campaign. The group broke Claude’s guardrails by feeding it fragmented, context-free prompts and posing as a legitimate cybersecurity firm conducting defensive testing.   Once jailbroken, the model performed reconnaissance, identified high-value data, wrote…

Read More

Clop Claims It Breached the NHS, But Offers No Proof and Even Less Detail

Kirsten DoyleNovember 17, 20254 Mins Read

Notorious ransomware gang Clop is back with another bold claim, this time insisting it hacked “the NHS,” The Register reports. Which part of the sprawling UK healthcare system? The gang doesn’t say. It listed only the NHS.uk domain on its leak site on November 11 and published no data. For a system made up of hundreds of trusts, agencies, and regional bodies, that’s not much to go on. The extortion crew has spent recent months exploiting an Oracle E-Business Suite zero-day to hit private organizations. Adding “the NHS” to its victim roster sounds dramatic, but the lack of specifics raises a simple question: Does Clop…

Read More

Endgame Shoots, it Scores: 1,025 Cybercrime Servers Taken Down

Kirsten DoyleNovember 14, 20253 Mins Read

Authorities have delivered another major hit to global cybercrime infrastructure, with more than 1,025 servers linked to three prolific malware operations taken down in the latest phase of Operation Endgame. Coordinated from Europol’s headquarters in The Hague between 10 and 13 November, the action targeted the infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium. All of these are key enablers behind large-scale international cyberattacks.   A suspect tied to VenomRAT was arrested earlier this month in Greece. Millions of Stolen Credentials Officials say the dismantled infrastructure had infected hundreds of thousands worldwide and had siphoned millions of stolen credentials. Investigators believe the main…

Read More

OpenAI Pushes Back Against Order to Hand Over 20 Million Chat Logs

Kirsten DoyleNovember 14, 20252 Mins Read

OpenAI is fighting a court order that would force it to hand over 20 million anonymized ChatGPT conversations as part of the New York Times’ copyright lawsuit, Reuters reports.  In a filing on Wednesday, the company warned that complying would expose private user chats that have nothing to do with the case, calling it a “speculative fishing expedition.” Reuters said OpenAI argued 99.99% of the requested logs bear no relevance to the copyright claims. The Times and other outlets say they need the chats to test whether their articles were reproduced and to counter OpenAI’s allegation that they “hacked” the model…

Read More

UK insurers pay nearly £200m to help businesses recover from cyber attacks

Kirsten DoyleNovember 12, 20252 Mins Read

UK insurers paid out nearly £200 million to help businesses recover from cyber incidents last year, according to new figures from the Association of British Insurers (ABI). This is a steep increase that highlights the growing impact of digital threats on the UK economy. The ABI’s latest data shows £197 million was paid out in 2024, a 230% increase year-on-year, with payouts up £138 million from 2023. More than half of all claims (51%) were linked to malware and ransomware, compared with 32% a year earlier, evidence of how increasingly sophisticated attacks are inflicting greater operational and financial damage.  The…

Read More

Quantum Route Redirect: The New One-Click Phishing Engine Targeting Microsoft 365 Users Worldwide

Kirsten DoyleNovember 12, 20254 Mins Read

Cybercrooks are getting an upgrade. KnowBe4 Threat Lab has uncovered Quantum Route Redirect, a new phishing platform that’s upping the ante by making sophisticated attacks almost effortless to launch.  The tool, now circulating globally, streamlines what was once a technically complex phishing setup into a single click. Attackers using it can automatically evade certain email security filters, impersonate trusted brands, and harvest Microsoft 365 credentials at scale. The Impact is Spreading Fast Analysts first detected Quantum Route Redirect in August through KnowBe4’s PhishER Plus and Defend platforms. Since then, it’s been linked to phishing campaigns spanning 90 countries. Most victims…

Read More

Phishing Campaign “I Paid Twice” Targets Booking.com Hotels and Guests

Kirsten DoyleNovember 11, 20256 Mins Read

A new phishing campaign uncovered by analysts at sekoia.io is exploiting the hospitality industry at scale, targeting both Booking.com partners and their guests in a sophisticated, multi-stage fraud scheme. Codenamed “I Paid Twice,” the operation combines infostealing malware, social engineering, and payment fraud, effectively turning compromised hotel accounts into launchpads for attacks against unsuspecting travellers. Hotels as the First Breach Point The campaign, active since at least April 2025, begins with spearphishing emails sent from compromised Booking.com partner accounts. These messages, often referencing genuine reservation IDs or guest requests, are convincing because they draw directly on real booking data that…

Read More

Microsoft Uncovers New Side-Channel Attack That Can Reveal Encrypted AI Chat Topics

Kirsten DoyleNovember 11, 20253 Mins Read

Microsoft has identified a new kind of side-channel attack capable of exposing the topics of encrypted conversations with remote language models, even when protected by Transport Layer Security (TLS).  Dubbed a streaming inference attack, the method allows an observer with access to network traffic (such as an ISP, local network monitor, or malicious actor on public Wi-Fi) to infer what a user is talking about with an AI system. The discovery underscores the growing privacy stakes around AI-powered chatbots now woven into everything from customer service to legal and healthcare assistance.  Even with end-to-end encryption in place, network-level observers can…

Read More

The 2025 OWASP Top 10: What’s New and Rising in AppSec Today

Kirsten DoyleNovember 10, 20255 Mins Read

The OWASP Top 10, the benchmark list of the most critical web application security risks, is back for its 8th edition, and the 2025 update tells a story: the fundamentals still matter, but the ecosystem has changed. Broken Access Control once again takes the top spot. It’s the flaw behind countless breaches, users seeing or doing things they shouldn’t. Nearly 4% of tested applications had at least one such weakness. Security Misconfiguration jumps from #5 to #2, reflecting how modern apps increasingly rely on complex configurations that can be easily mismanaged. A single toggle or default left open can expose…

Read More
Previous 1 … 11 12 13 14 15 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}