Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 40

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

“Scallywag” Scheme Monetizing Piracy Through Browser Extensions

Kirsten DoyleApril 22, 20252 Mins Read

Researchers from HUMAN Security’s Satori Threat Intelligence and Research Team have uncovered a sophisticated ad fraud operation, dubbed “Scallywag,” which exploits WordPress extensions to profit from digital piracy.  The scheme targeted users wanting free access to premium content—a longstanding challenge in the digital world. Scallywag operators developed and distributed WordPress plugins promising access to pirated material — like movies, TV shows, and sporting events. Once installed on websites, these plugins covertly manipulated users’ browsing activities by inserting ad-heavy intermediary pages and redirecting traffic without user consent to generate illicit advertising revenue. According to the findings, Scallywag leveraged deceptive tactics categorized…

Read More

Researchers Warn of Critical Vulnerability in Erlang/OTP SSH

Kirsten DoyleApril 22, 20253 Mins Read

A team of researchers from Ruhr University Bochum — Fabian Bäumer, Marcus Brinkmann, Marcel Maehren, and Jörg Schwenk — have discovered a critical security vulnerability affecting the SSH implementation in Erlang/OTP. Tracked as CVE-2025-32433, the flaw has been assigned a CVSS v3.1 score of 10.0, the highest possible severity rating. The vulnerability enables a malicious actor with network access to an Erlang/OTP SSH server to execute arbitrary code without any prior authentication. According to the researchers, the issue stems from a flaw in the SSH protocol message handling, where connection protocol messages sent prior to authentication can be exploited. All…

Read More

Malicious PyPI Package Hijacks MEXC Orders, Steals Crypto Tokens

Kirsten DoyleApril 21, 20253 Mins Read

JFrog researchers have uncovered a new supply chain attack targeting cryptocurrency users through a malicious Python package uploaded to the PyPI repository. The package, named “ccxt-mexc-futures,” masqueraded as a legitimate tool for interacting with the MEXC cryptocurrency exchange but was designed to steal users’ crypto assets. According to JFrog, the package contained an “info-stealer” malware that harvested environment variables, hijacked cryptocurrency transactions, and exfiltrated sensitive data to an attacker-controlled server.   Specifically, it targeted users trading on MEXC by modifying withdrawal requests, rerouting tokens to wallets controlled by the threat actor. A Stealthy Operator The malware operated stealthily, making its malicious…

Read More

Leaking Apps: The Hidden Data Risks on Your Phone

Kirsten DoyleApril 21, 20254 Mins Read

Personally identifiable information (PII), financial data, medical records, account credentials, and intellectual property all require strict access controls to prevent unauthorized exposure. Unfortunately, mobile applications commonly used in both personal and professional settings can compromise this data, even when users believe they are following best security practices.   As mobile devices have become central to business operations, especially with widespread bring-your-own-device (BYOD) policies, they are increasingly serving as primary access points for digital services, they have also become a significant attack surface for data leaks and breaches. To investigate the risks associated with mobile applications, zLabs, the research team at Zimperium,…

Read More

Senators Push to Extend Key Cybersecurity Protections

Kirsten DoyleApril 17, 20255 Mins Read

Two senators have introduced a bipartisan bill to extend key cybersecurity protections that encourage businesses to share threat information with the federal government. The bill would renew provisions first signed into law under the Cybersecurity Information Sharing Act of 2015. Introduced by U.S. Senators Gary Peters (D-MI), Ranking Member of the Homeland Security and Governmental Affairs Committee, and Mike Rounds (R-SD), the bill incentivizes companies to voluntarily share cybersecurity threat indicators—like software vulnerabilities, malware, and malicious IP addresses—with the Department of Homeland Security (DHS). Protecting Americans’ Personal Data The goal is to better protect Americans’ personal data and strengthen collaboration…

Read More

4chan Reportedly Hacked, Moderator Information Potentially Exposed

Kirsten DoyleApril 17, 20253 Mins Read

The controversial internet forum 4chan appears to have been hacked, according to multiple online reports. Alleged leaks suggest that a hacker gained access to backend infrastructure and exposed personal details of the site’s moderators. The breach first came to light when a previously inactive section of 4chan suddenly reappeared, displaying a bold message: “U GOT HACKED,” as reported by by Wired. Cybersecurity experts, including Alon Gal, co-founder of Hudson Rock, have said the breach “looks legit,” citing widely shared screenshots that purportedly show internal systems. Adding weight to the claims, TechCrunch spoke with an unnamed 4chan moderator who stated there…

Read More

Chinese Threat Group UNC5174 Caught Using New Tools in Ongoing Cyber Campaign

Kirsten DoyleApril 17, 20253 Mins Read

After operating quietly for a year, a Chinese state-sponsored hacking group known as UNC5174 has launched a new cyber campaign, according to the Sysdig Threat Research Team (TRT). Sysdig researchers uncovered the campaign in late January 2025 when they spotted a malicious bash script downloading several files to maintain access on targeted systems. One of these files was a variant of the group’s known malware, SNOWLIGHT, which has been previously used in attacks on F5 devices and was recently mentioned in France’s 2025 Cyber Threat Overview report. In a new twist, UNC5174 is now using an open-source tool called VShell—a…

Read More

Trojan WhatsApp, Wallet Apps Found on Chinese Android Phones

Kirsten DoyleApril 17, 20255 Mins Read

A sophisticated campaign that pre-installs malware onto budget Android smartphones, targeting cryptocurrency users through a technique known as “clipping” has been discovered by Doctor Web’s virus lab.  Its findings reveal that malefactors have embedded a trojanized version of WhatsApp directly into the system partition of newly manufactured devices, exposing users to stealthy financial theft from the moment they activate their phones. Starting in June 2024, Dr Web began receiving reports from users who installed its Security Space antivirus on new Android devices. Investigations confirmed that these phones — usually sold under names resembling popular brands like “S23 Ultra,” “Note 13…

Read More

No Skills Needed: How AI Is Democratizing Document Fraud

Kirsten DoyleApril 16, 20256 Mins Read

Towards the end of March, OpenAI debuted image generation features for its ChatGPT-4o and ChatGPT-4o mini models. Less than a week later, the tool was made available for free to all users, and since then, users have reported that the feature can be used to create convincing fake documents—including receipts and passports. According to the 2025 Cato CTRL Threat Report, generative AI (GenAI) tools like ChatGPT are lowering the barrier to entry for malicious actors.   The report highlights the growing threat of so-called “zero-knowledge threat actors”—people with no technical expertise who are now able to carry out advanced fraud using…

Read More

OCC Reports Major Security Breach Involving Sensitive Emails

Kirsten DoyleApril 16, 20253 Mins Read

The Office of the Comptroller of the Currency (OCC) has alerted Congress to a “major information security incident” following unauthorized access to its email systems, including messages containing sensitive financial data. The breach was discovered on 11 February 2025, and confirmed the following day. According to the OCC, the incident involved unusual activity by a system administrator account accessing user mailboxes without authorization. Once detected, the OCC shut down the compromised accounts and activated its incident response protocols. The breach was reported to the Cybersecurity and Infrastructure Security Agency and publicly disclosed on 26 February. The investigation, involving internal teams…

Read More
Previous 1 … 38 39 40 41 42 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}