Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 38

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Unprotected Database Exposes Over 500,000 Records from Ticket Resale Platform

Kirsten DoyleMay 5, 20253 Mins Read

Cybersecurity researcher Jeremiah Fowler has uncovered a publicly accessible database containing over half a million records linked to an online ticket resale service. He reported the discovery to vpnMentor. The database was neither password-protected nor encrypted and contained 520,054 records totalling approximately 200 GB. Based on file and folder names, the data appeared to belong to “Ticket to Cash,” a resale platform for event tickets. Fowler reviewed a small sample of the documents, which included concert and event tickets, ticket transfers, receipts, and user-uploaded screenshots. Some files contained personally identifiable information (PII), such as partial credit card numbers, full names,…

Read More

StealC V2: A Sharper, Stealthier Infostealer Emerges

Kirsten DoyleMay 5, 20253 Mins Read

An enhanced version of the StealC infostealer has been found in the wild, featuring a slew of upgrades that improve its stealth, payload control, and data exfiltration capabilities.   Dubbed StealC V2, this latest variant shows how malware authors are rapidly evolving commodity stealers into sophisticated, modular tools that are able to evade modern detection techniques. Researchers from Zscaler ThreatLabz identified and analyzed multiple recent samples of StealC V2, and discoverd that it has adopted RC4 encryption, PowerShell-based execution, and a redesigned command-and-control (C2) protocol. Also, this scourge now features a modular control panel that allows bad actors to customize the…

Read More

25 Years Since ILOVEYOU: The Email Virus That Changed Cybersecurity Forever

Kirsten DoyleMay 5, 20253 Mins Read

Twenty-five years ago today, the world was introduced to one of the most infamous computer viruses in history: ILOVEYOU. Disguised as a love letter in a simple email attachment, the worm spread like wildfire across inboxes on 4 May 2000, infecting an estimated 45 million systems within days. It caused billions in damages and forced global businesses, governments, and individuals to rethink how they handled email security. ILOVEYOU marked a turning point in cybersecurity. Unlike earlier viruses that relied on floppy disks or infected executables, ILOVEYOU exploited the human element, such as curiosity, trust, and a desire for connection. It…

Read More

The Password Is Dead – Or Is It? Experts Weigh In on the Future of Authentication

Kirsten DoyleMay 1, 202515 Mins Read

World Password Day, observed on the first Thursday of May, is a global reminder of just how critical strong password habits are in today’s digital world. With cyber threats continuing to evolve, this day encourages everyone, from individuals to large organizations, to take a closer look at how they protect their online identities.   To mark the occasion, several cybersecurity experts shared their insights on the current state of password security, the challenges we face, and what steps we can all take to stay safer online. Tony Ball, President, Payment & Identity, at Entrust For decades, passwords have been the weak…

Read More

“Shadow Role” Vulnerability in AWS Services Could Lead to Full Account Takeover

Kirsten DoyleApril 30, 20253 Mins Read

Aqua Security’s Team Nautilus has discovered a critical vulnerability in six popular AWS services that could allow bad actors to gain control over cloud environments. The flaw, rooted in how AWS automatically creates default IAM roles in new regions, could be exploited without user interaction. It could endanger organizations using Glue, SageMaker, EMR, CloudFormation, Redshift, and CodeBuild. The attack vector, termed “Shadow Role”, takes advantage of AWS’s behavior of silently creating IAM roles with predefined trust policies when specific services are used in a new region. These roles are designed to allow specific AWS services to assume them on behalf…

Read More

Google Report: Fewer Zero-Day Attacks in 2024, But Enterprise Tech Now in the Crosshairs

Kirsten DoyleApril 30, 20254 Mins Read

Seventy-five zero-day vulnerabilities were actively exploited in 2024 — down from 98 in 2023, but still higher than the 63 reported in 2022. These vulnerabilities were split between consumer-facing platforms like browsers and mobile devices, and enterprise-level technologies such as security software and networking appliances. This was one of the findings of Google Threat Intelligence Group’s (GTIG’s) annual report on zero-day vulnerabilities exploited in the wild. It revealed an interesting shift in attacker priorities despite a drop in total cases. “While individual year counts have fluctuated, the average trendline indicates that the rate of zero-day exploitation continues to grow at…

Read More

Uyghur Activists Targeted by Sophisticated Malware Campaign

Kirsten DoyleApril 29, 20253 Mins Read

A trusted Uyghur-language text editor has been weaponized to target exiled Uyghur activists, says a new investigation by Citizen Lab. In this campaign, threat actors are exploiting culturally significant software to conduct digital surveillance against the Uyghur diaspora, a community already under intense pressure from the Chinese government. This incident is the latest in a series of digital attacks against Uyghur, Tibetan, and other diaspora communities. For years, Chinese state-aligned actors have used malware, phishing, and spyware, often hidden in culturally relevant apps, to monitor, intimidate, and silence critics abroad.  Spearphishing Attack Targets World Uyghur Congress The attack began with…

Read More

Dropbox, OneDrive Abused in Massive Southeast Asia Cyber-Espionage Operation

Kirsten DoyleApril 29, 20253 Mins Read

An advanced persistent threat (APT) group dubbed Earth Kurma is behind a stealthy, multi-year cyber-espionage campaign targeting government and telecommunications organizations across Southeast Asia. According to Trend Micro researchers Nick Dai and Sunny Lu, the campaign has been active since at least 2020. Sophisticated Toolsets and Cloud Abuse Earth Kurma has shown a high level of operational maturity, blending advanced malware with living-off-the-land binaries and trusted infrastructure. It uses a custom suite of malware, including TESDAT, DMLOADER, SIMPOBOXSPY, and KRNRAT, which facilitate stealthy data collection, persistence, and communication with command-and-control (C&C) servers. The malicious actors leverage public cloud platforms to…

Read More

Verizon’s 2025 Data Breach Investigations Report: Third Party Attacks Surge

Kirsten DoyleApril 25, 20254 Mins Read

Verizon has unveiled its 2025 Data Breach Investigations Report (DBIR), which revealed a dramatic increase in cyberattacks. The report showed that third-party breaches have doubled to 30%. Also, exploitation of vulnerabilities has increased by 34%. This creates a serious threat for businesses worldwide. The latest report shows a steep rise in zero-day exploits and ransomware—bad news for the cybersecurity landscape. Human error, weak credentials, and the abuse of GenAI continues to be major vulnerabilities. Unfortunately, bad actors only grow more cunning. The report analyzed over 22,000 security incidents, including 12,195 confirmed data breaches. It discovered that credential abuse (22%) and the exploitation of vulnerabilities (20%) remain the leading initial attack vectors,…

Read More

Android Spyware Targets Russian Military via Trojanized Mapping App

Kirsten DoyleApril 25, 20252 Mins Read

A new Android spyware campaign is targeting Russian military personnel by hiding malicious code inside a popular mapping app, says cybersecurity firm Doctor Web. The spyware, identified as Android.Spy.1292.origin, is embedded in a modified version of the Alpine Quest mapping application. It is being distributed through unofficial app sources, including a Russian Android app catalog and a fake Telegram channel posing as the app’s developer. Alpine Quest is widely used for topographic mapping in both online and offline modes. While it’s popular among outdoor enthusiasts, it’s often used by Russian soldiers in active combat zones, too. The attackers appear to…

Read More
Previous 1 … 36 37 38 39 40 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}