Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 29

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

North Korean APT Impersonates Zoom to Breach Canadian Gambling Firm

Kirsten DoyleJune 24, 20252 Mins Read

A Canadian online gambling provider has fallen victim to a highly targeted cyberattack involving a fake Zoom support tool, part of a broader social engineering campaign orchestrated by BlueNoroff, a financially motivated North Korean APT subgroup tied to the Lazarus Group. Investigators from Field Effect Analysis revealed that the incident began on 28 May 2025, during what appeared to be a routine Zoom call between the victim and a known contact. When audio issues arose, the victim was urged to run a so-called Zoom audio repair script, actually a malicious payload disguised to blend seamlessly into the victim’s workflow. The…

Read More

Oxford City Council hit by cyberattack

Kirsten DoyleJune 23, 20252 Mins Read

Oxford City Council has confirmed it was the target of a cyberattack that led to the unauthorised access of personal information belonging to individuals involved in council-run elections over the past two decades. The breach was quickly detected by the council’s automated security systems. It triggered an immediate response that limited the threat attackers’ access. “Unfortunately, the attackers were able to access some historic data on legacy systems,” the Council said in a statement. “We have now identified that people who worked on Oxford City Council-administered elections between 2001 and 2022, including poll station workers and ballot counters, may…

Read More

Aflac Confirms Breach Amid Surge in Attacks on Insurance Sector

Kirsten DoyleJune 23, 20253 Mins Read

American insurance giant Aflac has disclosed a cyberattack on its U.S. network, part of what it describes as a broader campaign targeting the insurance sector. The intrusion was detected on 12 June and stopped within hours, with no ransomware deployed and no disruption to operations. The company says it remains fully operational and continues to underwrite policies and process claims. However, preliminary findings suggest that a sophisticated cybercrime group used social engineering tactics to gain access. Aflac says it has engaged external cybersecurity experts to support its response and containment efforts. While the investigation is still in its early stages,…

Read More

Krispy Kreme Confirms Breach Impact: 161,676 Individuals Affected

Kirsten DoyleJune 20, 20254 Mins Read

Krispy Kreme has disclosed that its November 2024 data breach affected 161,676 people.  In a breach notification shared this week, the company said exposed data varies by person, but the list is long and deeply personal. It includes names, Social Security numbers, dates of birth, and driver’s license or state ID numbers. In some cases, it extends to financial account details, login credentials, debit and credit card data (including security codes), passport numbers, digital signatures, and biometric identifiers. Also potentially compromised: military ID numbers, USCIS or Alien Registration Numbers, and sensitive health or insurance information. The disclosure comes months after…

Read More

Cybercrooks Use Musk-Trump Feud to Launch Wave of Malicious Domains

Kirsten DoyleJune 20, 20253 Mins Read

As the public feud between Elon Musk and Donald Trump heats up online, cybercrooks are wasting no time cashing in on this clash of egos. According to new findings from BforeAI’s PreCrime Labs, at least 39 malicious domains were registered within 48 hours of Musk’s widely publicized 4 June remarks criticizing Trump’s proposed trade legislation.   These domains are designed to impersonate betting sites, fake giveaways, and crypto multipliers, all under the guise of the Musk vs. Trump rivalry. The tactic isn’t new. Threat actors have long exploited celebrity disputes and political theater to bait users into scams. But this campaign…

Read More

Cyberattack on Swiss Vendor Exposes UBS and Pictet Employee Data

Kirsten DoyleJune 20, 20254 Mins Read

Swiss banks UBS and Pictet confirmed this week that a third-party cyberattack led to a leak of internal company data, highlighting the growing threat of supply chain vulnerabilities in financial services.  The breach stemmed from an attack on Chain IQ, a Baar-based procurement services provider. Chain IQ said it was one of 20 organisations targeted in a sophisticated intrusion that leveraged techniques “never before seen on a global scale.” UBS moved quickly to reassure stakeholders. “A cyber attack at an external supplier has led to information about UBS and several other companies being stolen. No client data has been affected,”…

Read More

Security’s Blind Spot: Shadow AI Creeps Into the SOC

Kirsten DoyleJune 19, 20254 Mins Read

Even the guardians are breaking the rules. A new survey by Mindgard has revealed a troubling shift in cybersecurity: security professionals themselves are turning to generative AI tools without approval. More than half admit to it. Others suspect it’s happening. This isn’t happening in the marketing department. It’s happening in the security operations center. Over 500 cybersecurity professionals were surveyed at RSA Conference and Infosecurity Europe 2025. The results show a profession at odds with itself, embracing AI while sidestepping its own safeguards.  The Watchers Are Watching Less They call it Shadow AI. Like Shadow IT before it, it’s the…

Read More

Phishing with a Badge: EU Survey Platform Abused in Credential Theft Campaign

Kirsten DoyleJune 19, 20253 Mins Read

Between May 5 and 7, 2025, bad actors launched a subtle but smart phishing campaign using the European Commission’s own survey platform. The attack wasn’t broad, but it was sharp, leveraging the credibility of an EU-linked domain to slip past defenses and harvest credentials. KnowBe4 Threat Lab spotted it early. The phishing emails came from a legitimate sender: [email protected]. That’s not a spoof, but a real domain tied to EUSurvey, a platform used for public consultation and research. This is what made it so dangerous. The Setup: Real Sender, Fake Intent By creating an account on EUSurvey, attackers sent phishing…

Read More

A New Breed of Mobile Threat: GodFather Malware Goes Virtual

Kirsten DoyleJune 19, 20254 Mins Read

Zimperium’s zLabs team has exposed a troubling evolution in mobile banking malware. The latest variant of GodFather doesn’t just spoof screens or steal passwords. It builds a world of its own, inside your phone. This version uses on-device virtualization to hijack real banking and crypto apps. It’s not overlay, it’s not mimicry, it’s full control. At the heart of the attack is a malicious host app. Once installed, it spins up a virtual environment, downloading a copy of the actual targeted app. When the user opens their banking or crypto app, they’re redirected to this sandbox. Everything appears normal, but…

Read More

Taiwan Targeted in Sophisticated Malware Campaign Disguised as Tax Emails

Kirsten DoyleJune 18, 20254 Mins Read

A persistent malware campaign is targeting Microsoft Windows users in Taiwan. Disguised as correspondence from Taiwan’s National Taxation Bureau, the threat actors are deploying a phishing campaign laced with winos 4.0 malware. Fortinet’s FortiGuard Labs traced the operation back to January 2025. Over the months that followed, the campaign evolved, adopting more sophisticated tools and techniques, most notably a variant of the HoldingHands remote access trojan (RAT).  Its objective is simple: establish stealthy, long-term access for further attacks. The method, however, is anything but. The Hook: Official-Looking Emails Initial infection starts with phishing emails purporting to come from government entities.…

Read More
Previous 1 … 27 28 29 30 31 … 60 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}