Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 38

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Dropbox, OneDrive Abused in Massive Southeast Asia Cyber-Espionage Operation

Kirsten DoyleApril 29, 20253 Mins Read

An advanced persistent threat (APT) group dubbed Earth Kurma is behind a stealthy, multi-year cyber-espionage campaign targeting government and telecommunications organizations across Southeast Asia. According to Trend Micro researchers Nick Dai and Sunny Lu, the campaign has been active since at least 2020. Sophisticated Toolsets and Cloud Abuse Earth Kurma has shown a high level of operational maturity, blending advanced malware with living-off-the-land binaries and trusted infrastructure. It uses a custom suite of malware, including TESDAT, DMLOADER, SIMPOBOXSPY, and KRNRAT, which facilitate stealthy data collection, persistence, and communication with command-and-control (C&C) servers. The malicious actors leverage public cloud platforms to…

Read More

Verizon’s 2025 Data Breach Investigations Report: Third Party Attacks Surge

Kirsten DoyleApril 25, 20254 Mins Read

Verizon has unveiled its 2025 Data Breach Investigations Report (DBIR), which revealed a dramatic increase in cyberattacks. The report showed that third-party breaches have doubled to 30%. Also, exploitation of vulnerabilities has increased by 34%. This creates a serious threat for businesses worldwide. The latest report shows a steep rise in zero-day exploits and ransomware—bad news for the cybersecurity landscape. Human error, weak credentials, and the abuse of GenAI continues to be major vulnerabilities. Unfortunately, bad actors only grow more cunning. The report analyzed over 22,000 security incidents, including 12,195 confirmed data breaches. It discovered that credential abuse (22%) and the exploitation of vulnerabilities (20%) remain the leading initial attack vectors,…

Read More

Android Spyware Targets Russian Military via Trojanized Mapping App

Kirsten DoyleApril 25, 20252 Mins Read

A new Android spyware campaign is targeting Russian military personnel by hiding malicious code inside a popular mapping app, says cybersecurity firm Doctor Web. The spyware, identified as Android.Spy.1292.origin, is embedded in a modified version of the Alpine Quest mapping application. It is being distributed through unofficial app sources, including a Russian Android app catalog and a fake Telegram channel posing as the app’s developer. Alpine Quest is widely used for topographic mapping in both online and offline modes. While it’s popular among outdoor enthusiasts, it’s often used by Russian soldiers in active combat zones, too. The attackers appear to…

Read More

Pope Francis’ Passing Triggers Surge of Phishing, SEO Poisoning, and Fake Images

Kirsten DoyleApril 25, 20254 Mins Read

Proving there are no depths they won’t plum, cybercriminals have begun exploiting the news of Pope Francis’s passing in a range of malicious campaigns. This tactic has been popular for some time. Bad actors are the first to jump on the bandwagon during major world events—from global disasters to the deaths of famous people. From disinformation and scams, to malware, there is no tragedy they won’t take advantage of. According to Check Point Research, “They typically begin with disinformation campaigns on social media platforms like Instagram, TikTok, or Facebook, uploading fake images generated by AI.” These campaigns aim to grab…

Read More

Max Severity Commvault Command Center Flaw Allows Attackers to Execute Code Remotely

Kirsten DoyleApril 25, 20253 Mins Read

A critical security vulnerability has been discovered in the Commvault Command Center, that could enable malicious actors to remotely to execute arbitrary code without authentication,” Commvault said in an advisory. “This vulnerability could lead to a complete compromise of the Command Center environment. Fortunately, other installations within the same system are not affected by this vulnerability,” the advisory added. The vulnerability, tracked as CVE-2025-34028, carries a CVSS score of 10.0 – the highest possible. A researcher from watchTowr Labs, Sonny Macdonald, is credited with discovering and reporting the flaw on 7 April. He said it could be exploited to achieve…

Read More

Cybersecurity’s Diversity Deficit: What the Experts Are Saying

Kirsten DoyleApril 25, 202514 Mins Read

At this year’s RSA Conference, the theme “Many Voices. One Community” is a reminder that cybersecurity isn’t just about technology—it’s about people. In a field driven by constant innovation and rapid response, the strength of our defenses often depends on the breadth of perspectives behind them.   We asked our panel of cybersecurity experts two key questions: Is the community doing enough to elevate individual voices and welcome diverse perspectives? And how can we create more space for those who aren’t always heard? Their candid responses highlight both the progress we’ve made—and the opportunities still ahead.  Identifying Gaps in Security Cybersecurity…

Read More

SAP NetWeaver Flaw Puts Businesses at Risk, ReliaQuest Reports

Kirsten DoyleApril 24, 20252 Mins Read

ReliaQuest has uncovered a serious vulnerability in SAP NetWeaver, a popular software platform used by many businesses around the world. In April 2025, the company investigated several customer incidents involving SAP NetWeaver, a technology integration platform. Bad actors were able to upload unauthorized files and run malicious programs. ReliaQuest found that attackers had placed “JSP webshells” into public directories, similar to what happens with a remote file inclusion (RFI) vulnerability. Notably, many of the affected systems were already up-to-date with the latest SAP service packs and patches. This, said ReliaQuest, posed the questions, if attackers were exploiting an old vulnerability…

Read More

Internet Crime Surges in 2024: FBI Reports Record-Breaking $16.6 Billion in Losses

Kirsten DoyleApril 24, 20254 Mins Read

In 2024 alone, the FBI’s Internet Crime Complaint Center (IC3) received a staggering 859,532 complaints, with reported losses surging to an all-time high of $16.6 billion—a 33% increase over 2023. Of those complaints, more than 256,000 involved actual financial losses, with an average loss of $19,372 per incident. These were some of the findings from the IC3’s 2024 Internet Crime Report—the agency’s 25th report that tracks cyber-enabled crime across the US. Its message is clear: online crime is more pervasive, more damaging, and more sophisticated than ever before. “The criminals Americans face today may look different than in years past,…

Read More

CISA Issues Five New Alerts for Critical ICS Vulnerabilities

Kirsten DoyleApril 24, 20254 Mins Read

CISA has published five advisories alerting of critical vulnerabilities in Industrial Control Systems (ICS) manufactured by Siemens, Schneider Electric, and ABB.   The advisories detail high-severity flaws that could enable malicious actors to access sensitive systems, disrupt industrial operations, or execute malicious code Firstly, CISA warns that multiple SQL injection vulnerabilities have been discovered in Siemens’ TeleControl Server Basic SQL, with the potential to grant attackers unauthorized database access and code execution capabilities. Affected internal methods include: Each vulnerability could allow bad actors to bypass authorization mechanisms and manipulate backend databases, threatening the integrity of industrial systems. Another advisory details a…

Read More

Marks & Spencer Confirms Cyberattack, Investigates Impact as Stores Remain Open

Kirsten DoyleApril 23, 20253 Mins Read

Marks & Spencer (M&S) has confirmed it is managing a cyber incident that has caused minor disruptions to its store operations in the last few days. Despite the security breach, the British retailer reassured customers that all stores remain open and that its website and mobile app are operating as normal. In a statement released today, M&S said: “As soon as we became aware of the incident, it was necessary to make some minor, temporary changes to our store operations to protect customers and the business and we are sorry for any inconvenience experienced. Importantly, our stores remain open and…

Read More
Previous 1 … 36 37 38 39 40 … 60 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}