Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 23

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Behind the Seams: Chanel Joins List of Luxury Brands Hit by Data Breaches

Kirsten DoyleAugust 6, 20253 Mins Read

Chanel has confirmed a data breach that affected its U.S. client care database. The news first came from WWD on Friday. The incident happened on July 25 and involved unauthorized access to a database managed by a third-party provider.  A company spokeswoman confirmed the incident, saying: “The investigation indicates that there was unauthorized access to this database. There was no malware deployed to our systems, and our operations remain unaffected.”  She added that Chanel immediately activated their incident response protocols and brought cybersecurity experts on board to aid their investigation.  The information exposed was limited. Names, emails, mailing addresses, and…

Read More

“FraudOnTok” Scam Is Stealing from TikTok Shop Users Worldwide

Kirsten DoyleAugust 6, 20253 Mins Read

In August, cybersecurity firm CTM360 uncovered a large-scale scam targeting TikTok Shop users. Called “FraudOnTok,” this campaign combines phishing with malware. It uses a complex web of fake sites and apps to trick victims into handing over their credentials, and their money. The bad actors set up more than 15,000 lookalike domains. They mimic TikTok Shop, TikTok Wholesale, and TikTok Mall, using cheap domain extensions like .top, .shop, and .icu. These sites fool users into believing they’re on the official platform. Once there, victims are hit with phishing pages that steal login info, and are prompted to download trojanized apps…

Read More

User Profiling and Data Brokers: The Quiet Machine Behind the Digital Economy

Kirsten DoyleAugust 5, 20254 Mins Read

By 2024, AI had done more than disrupt industries. It had quietly supercharged one: data brokerage. Few consumers ever meet a data broker and even fewer understand what they do. But their work touches nearly every person with a smartphone, a loyalty card, or an internet connection.  The Invisible Harvest Data brokers operate in silence. They gather, compile, and sort.  According to vpnMentor: “They often do this indirectly and without explicit consent, instead maximizing public records, traceable online activity, or other openly accessible channels.  Names, phone numbers, IP addresses. Birthdays, income brackets, voter registrations, browsing habits, shopping carts, and app…

Read More

Menlo Security Warns of 68% Surge in Shadow AI Use as GenAI Threats Rise

Kirsten DoyleAugust 5, 20254 Mins Read

New research from browser security firm Menlo Security reveals an alarming rise in unsanctioned generative AI (GenAI) use across enterprises, with growing concerns over data leakage, phishing, and regulatory compliance. According to The 2025 Report: How AI is Shaping the Modern Workspace, web traffic to GenAI sites spiked by 50% in under a year, culminating in 10.53 billion visits in January 2025 alone. At the heart of the findings is a sharp increase in what Menlo terms Shadow AI, or the use of unsanctioned GenAI tools by employees, often without their organization’s knowledge or oversight. AI Adoption Accelerates, Security Gaps…

Read More

Inside Storm-2603: The Ransomware Operator Behind ToolShell’s Shadow

Kirsten DoyleAugust 4, 20254 Mins Read

A new name surfaced in Microsoft’s analysis of the ToolShell exploitation campaign earlier this year. Storm-2603. There was no history or track record. Just a cluster of activity, loosely linked to ransomware. Now, Check Point Research has filled in some of the blanks. Storm-2603, it turns out, was not born with ToolShell. It had been busy long before, targeting entities in Latin America and APAC. Its methods are like the hybrid DNA of advanced persistent threats and criminal ransomware crews. It moves with precision, using open-source tools and custom malware. It doesn’t bluff.  An Unknown Name, Familiar Footsteps ToolShell is…

Read More

UK VPN Usage Spikes as Online Safety Act Takes Effect

Kirsten DoyleAugust 1, 20253 Mins Read

The UK has seen a steep rise in VPN usage following the enforcement of the Online Safety Act.   On 25 July, Ofcom began implementing new age-verification rules designed to keep children away from adult content. In response, many users started using VPNs. Traffic spiked. So did downloads.  Researchers at vpnMentor tracked a whopping 6,430% increase in VPN demand in the hours after the law came into effect. “It remained as such for almost two hours before it started dropping at the end of the day, but with spikes of 900% up to 4000% the following days,” researchers said.  Several VPN…

Read More

Governments Face Rising Tide of Ransomware Attacks in First Half of 2025

Kirsten DoyleAugust 1, 20254 Mins Read

Ransomware groups are ramping up pressure on the public sector. In the first half of 2025, 208 attacks were recorded against government entities worldwide. That’s a 65% increase over the same period in 2024, and a 25 percent rise from the second half of last year. These were some of the findings from Comparitech’s Map of worldwide ransomware attacks that is updated daily. Half of the incidents were confirmed by the targeted agencies. The rest remain unresolved or unacknowledged. This level of transparency is rare outside the public sector. In education, only 31% of incidents were confirmed. Healthcare: 32%. In…

Read More

NIST Sharpens Focus on Software Security

Kirsten DoyleJuly 31, 20254 Mins Read

A new draft from NIST, developed in collaboration with 14 industry partners, outlines how to build software with security baked in, not bolted on. This is part of a broader push to protect the software supply chain, and it’s open for public comment until 12 September 2025.  The guidelines are a response to Executive Order 14306, issued in June, which called for sustained action to strengthen national cybersecurity. NIST’s National Cybersecurity Center of Excellence (NCCoE) is leading the work through a newly formed Software Supply Chain and DevOps Security Practices Consortium. The goal is simple, if ambitious: help organizations build,…

Read More

Lazarus Group Weaponizes Open Source in Global Espionage Campaign

Kirsten DoyleJuly 31, 20254 Mins Read

An investigation from Sonatype has exposed a cyber-espionage campaign by North Korea’s infamous Lazarus Group, this time targeting the tools developers rely on every day.   Between January and July 2025, Sonatype blocked 234 unique malware-laden packages across the npm and PyPI ecosystems; a calculated assault on the trust that underpins open-source software. Disguised as popular developer utilities, these poisoned packages carried espionage implants designed to exfiltrate credentials, profile systems, and establish long-term backdoors. At last count, the campaign may have reached over 36,000 victims, and it’s still ongoing. “Open source has become the new attack surface,” Sonatype warns. “It’s not…

Read More

JSCEAL: The Quiet Malware Campaign Draining Crypto Wallets

Kirsten DoyleJuly 30, 20253 Mins Read

It starts with an ad. The branding looks familiar; Coinbase, Binance, OKX. The ad promises fast trading, high returns, or access to a new crypto platform. Click it, and you’re sent through a maze of redirects. At the end is a download: a Windows installer in .msi format. Behind this is JSCEAL, a malware campaign that’s been quietly active since March last year. It doesn’t use zero-days because it doesn’t need to. It hides in plain sight, behind sponsored ads and familiar logos. Check Point Research uncovered the campaign after tracking a spike in crypto-related malware infections across Europe. Their…

Read More
Previous 1 … 21 22 23 24 25 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}