Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 21

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Patching for Persistence: DripDropper Malware Secures the Door It Broke Open

Kirsten DoyleAugust 21, 20256 Mins Read

It sounds counterintuitive. An adversary exploits a system, gains access, and then patches the very hole they used to break in. Yet that is exactly what Red Canary researchers observed in a recent campaign targeting cloud-based Linux servers. The logic is simple. By fixing the exploited vulnerability, a malefactor can lock out rivals and mask their method of entry. What looks like remediation is, in reality, persistence. The Red Canary Threat Intelligence team tracked a cluster of activity exploiting CVE-2023-46604 in Apache ActiveMQ, a widely deployed open-source message broker. Once inside, the adversary moved quickly. “It’s a great way to…

Read More

Britain Drops Apple ‘Backdoor’ Demand After U.S. Pushback

Kirsten DoyleAugust 20, 20253 Mins Read

Britain has abandoned its demand that Apple build a “backdoor” into its encryption systems. The change follows months of quiet talks between London and Washington, Reuters reports. In a statement posted on X, U.S. Director of National Intelligence Tulsi Gabbard, said: “As a result, the UK has agreed to drop its mandate for Apple to provide a ‘backdoor’ that would have enabled access to the protected encrypted data of American citizens and encroached on our civil liberties.” She added that the U.S. government had been working with Britain “to ensure that Americans’ civil liberties are protected.” The discussions involved President…

Read More

Colt Technology Services Battles Cyberattack, Faces Ongoing Outage

Kirsten DoyleAugust 20, 20253 Mins Read

Colt Technology Services has been dealing with a cyberattack that has disrupted parts of its business for more than a week. The UK-based telecommunications firm, which operates in 30 countries and runs nearly 50,000 miles of fiber connecting 900 data centers, confirmed that several internal support systems remain offline.   The incident began on 12 August, when Colt detected unusual activity and took systems down as a protective measure. The move cut access to Colt Online, its Voice API platform, and hosting and porting services.  Customers who normally use web portals have been told to rely on phone or email instead,…

Read More

Workday Confirms Data Breach After Social-Engineering Attack on Third‑Party CRM

Kirsten DoyleAugust 19, 20255 Mins Read

Workday, a cloud-based platform used for human capital managment and financial management, has disclosed a data breach after attackers gained access to a third-party CRM platform in a recent social engineering attack.  The company said bad actors contacted employees by text or phone, pretending to be from HR or IT. Their goal was to fool staff members into giving up account access or their personal information. “We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform. There is no indication of access to customer tenants or the data…

Read More

SAP NetWeaver: CVE-2025-31324 Now Exploitable at Scale

Kirsten DoyleAugust 19, 20254 Mins Read

In April 2025, SAP patched a critical vulnerability in NetWeaver AS Java Visual Composer. The flaw, tracked as CVE-2025-31324, allows unauthenticated remote code execution through the Visual Composer “metadata uploader” endpoint. Within weeks, proof-of-concept code appeared in public forums. Now, the exploit is no longer theoretical. Full tooling has been released. Source code is out in the open, easy to download and run. It takes little skill to weaponize. With AI assistance, even non-specialists can cause damage to systems that remain unpatched. Pathlock researchers examined the leaked exploit code. Their analysis confirms that the attack chain is simple. An attacker…

Read More

UK Businesses Hit by Wave of Breaches Caused by Insecure Code

Kirsten DoyleAugust 19, 20253 Mins Read

A new survey has revealed the extent to which poor coding practices are leaving UK businesses exposed. Two-thirds of senior technology leaders admitted their organisations suffered at least one breach or serious security incident in the past year. The common cause: insecure code. SecureFlag’s research found that of the 100 executives surveyed, nearly half reported facing more than one incident in twelve months. Despite the scale of the problem, 40 percent of organisations still do not require their developers to undergo regular secure coding training. “This should be a wake-up call for every business that develops software,” said Andrea Scaduto, CEO and…

Read More

Massive PayPal Credential Dump Surfaces on Dark Web Forums

Kirsten DoyleAugust 19, 20253 Mins Read

A threat actor is selling secrets. Big ones. Operating under the alias Chucky_BF, the attacker has surfaced on underground forums with a staggering claim: over 15.8 million PayPal credentials for sale. The haul includes email addresses, plaintext passwords, and direct URLs to PayPal services. It’s being marketed as the “Global PayPal Credential Dump 2025.” Hackread first reported this development. The numbers are staggering. The dataset spans 1.1GB and covers accounts from email providers worldwide. But size isn’t everything here. What makes this leak particularly dangerous is its laser focus on PayPal infrastructure.  These aren’t just random credentials. The records include…

Read More

KawaLocker Ransomware Emerges in New Attack

Kirsten DoyleAugust 18, 20253 Mins Read

Huntress analysts have tracked a fresh ransomware incident involving KawaLocker, also known as KAWA4096. The variant is new, but the method is familiar. Attackers gained access, disabled defenses, and moved to encrypt files. Ransomware families surface often. A year ago, Huntress reported on ReadText34. Just last month, a never-before-seen strain called Crux appeared. KawaLocker joins the list. According to Trustwave SpiderLabs, KawaLocker first appeared in June 2025. Its ransom note echoes Qilin. Its leak site resembles Akira. Analysts believe the similarities are meant to draw attention, not signal collaboration. The attack began on 8 August. Threat actors entered a victim’s…

Read More

Canadian Parliament Hit by Cyberattack, Investigation Underway

Kirsten DoyleAugust 15, 20253 Mins Read

The House of Commons and Canada’s cybersecurity agency are investigating a significant breach of parliamentary employee data, CBC News reports. An internal email to CBC staff on Monday 11 August said a malicious actor exploited a recent Microsoft vulnerability to gain unauthorized access to a database used to manage computers and mobile devices. The data included names, job titles, office locations, email addresses, and technical details about House-managed equipment. Some of the information was not publicly available. The email warned employees and members of Parliament to remain vigilant, as stolen details could be used in scams or to impersonate parliamentarians.…

Read More

Credential Theft and Data Exfiltration Lead Modern Ransomware Threats

Kirsten DoyleAugust 15, 20258 Mins Read

Ransomware and infostealer threats are evolving faster than most organizations can keep pace.   Security teams have invested heavily in backup and recovery systems, yet today’s most damaging attacks often bypass encryption altogether.   Picus Security’s Blue Report 2025 uncovered a shift: threat actors are targeting credential theft, data exfiltration, and lateral movement, founded on stealth and persistence rather than noise.  The numbers are a wake-up call. In nearly half the environments tested, at least one password hash was successfully cracked. Attempts at preventing data exfiltration fell to a low of 3%, a steep decline from 9% in 2024.  One stolen credential…

Read More
Previous 1 … 19 20 21 22 23 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}