Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 44

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Thousands of Driver’s Licenses, Bank Records, and PII Exposed in Australian Fintech Data Leak

Kirsten DoyleMarch 28, 20256 Mins Read

Cybersecurity analyst Jeremiah Fowler has discovered an unprotected Amazon S3 database that wasn’t encrypted or password protected and contained some 27,000 records. The records included highly personal information such as driver’s licenses, Medicaid cards, work statements, and bank statements that held account numbers and partial credit card numbers. The name of the database and the internal files names suggest that the database was owned by Australian fintech company Vroom by YouX (formerly Drive IQ). In addition, Fowler discovered an internal screenshot that showed another instance of MongoDB storage with 3.2 million documents. However, he did not examine its content and…

Read More

WoW! A Ransomware Gang Just Took Over One of America’s Largest ISPs

Kirsten DoyleMarch 28, 20253 Mins Read

A new ransomware gang, Arkana Security, is claiming responsibility for an enormous breach at WideOpenWest (WoW), one of the largest cable operators and ISPs in the US. The malicious actors boasted they had full backend control and even put a music video montage together to illustrate exactly how much access they had. Threat researchers from Hudson Rock traced the origins or the attack to an infostealer infection back in September last year. It has allegedly compromised over 403,000 including names, emails, passwords and other data, and an additional file allegedly containing 2.2 million records. It has also given the malefactors…

Read More

Oracle’s Data Breach Denial Unravels as Leaked Info Checks Out

Kirsten DoyleMarch 28, 20252 Mins Read

Despite Oracle’s denial of a breach affecting its Oracle Cloud federated SSO login servers, Bleeping Computer has confirmed with multiple companies that data samples shared by the threat actor are authentic. Recently, a threat actor, “rose87168,” claimed to be selling six million records, including sensitive account data, on dark web forums. CloudSEK’s investigation suggests the breach may have exploited a known security flaw, possibly allowing unauthorized access and data exfiltration. The vulnerable Oracle Cloud subdomain, which has subsequently been removed.  Oracle dismissed the claims, although cybersecurity firm CloudSEK and independent researchers found evidence supporting the breach. As further proof, the…

Read More

New Cybercrime Tool ‘Atlantis AIO’ Amps Up Credential Stuffing Attacks

Kirsten DoyleMarch 27, 20253 Mins Read

A powerful new attack tool, Atlantis AIO, is making it easier than ever for cybercrooks to access online accounts. Designed to perform credential stuffing attacks automatically, Atlantis AIO enables hackers to test millions of stolen usernames and passwords in rapid succession. In new research, Abnormal Security has described how, by offering pre-configured modules to target a wide range of platforms—especially email providers—this tool allows attackers to take over accounts with minimal effort. Credential stuffing remains one of the most common cyber threats today. It exploits a common security vulnerability: people reusing the same passwords across multiple websites.   Cyber attackers exploit…

Read More

Critical Flaws in Appsmith Exposed Systems to Full Takeover

Kirsten DoyleMarch 27, 20253 Mins Read

Rhino Security researchers have identified multiple critical vulnerabilities in Appsmith, an open-source developer platform commonly used for building internal applications. The most severe of these is CVE-2024-55963, which enables unauthenticated attackers to execute arbitrary system commands on servers running default installations of Appsmith versions 1.20 through 1.51. Remote Code Execution as PostgreSQL User Appsmith ships with a local PostgreSQL database for practice and learning purposes, but the researchers discovered a critical misconfiguration in its default setup. The PostgreSQL authentication configuration file (pg_hba.conf) allowed any local user to connect as any PostgreSQL user without needing a password. The vulnerability became exploitable…

Read More

IngressNightmare: Critical Kubernetes Flaws Put 6,500+ Clusters at Risk

Kirsten DoyleMarch 27, 20255 Mins Read

Five critical security vulnerabilities have been found in the Ingress NGINX Controller for Kubernetes, potentially enabling unauthenticated remote code execution. This exposure puts over 6,500 clusters at immediate risk by making the component accessible via the public internet.  The vulnerabilities, CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974, are a series of unauthenticated Remote Code Execution vulnerabilities in Ingress NGINX Controller for Kubernetes, discovered by Wiz Research, who collectively named them “IngressNightmare.” According to the researchers, exploitation of these vulnerabilities could lead to “unauthorized access to all secrets stored across all namespaces in the Kubernetes cluster by attackers, which can result in cluster…

Read More

Even the Best Can Be Pwned —Troy Hunt’s Transparency Sets the Right Example

Kirsten DoyleMarch 26, 20253 Mins Read

Troy Hunt, a security consultant who runs the popular data-breach search service Have I Been Pwned?, has disclosed that he has become a victim of a phishing attack that exposed the email addresses of 16,000 subscribers to his blog troyhunt.com. “Every active subscriber on my list will shortly receive an email notification by virtue of this blog post going out,” he said. The export also included people who have unsubscribed, and Hunt questioned why Mailchimp would keep these in the first place. “I’ll need to work out how to handle those ones separately. I’ve been in touch with Mailchimp but don’t have a reply…

Read More

AI Agents Will Cut Account Exploitation Time by 50%

Kirsten DoyleMarch 26, 20256 Mins Read

By 2027, AI agents are expected to reduce the time required to exploit account exposures by 50%. This was revealed in Gartner’s new report, titled: “Predicts 2025: Navigating Imminent AI Turbulence for Cybersecurity.”  Jeremy D’Hoinne, VP Analyst at Gartner, says account takeover (ATO) is a persistent attack vector as weak authentication credentials, including passwords, are gathered in a slew of ways, including data breaches, phishing, social engineering, and malware. “Attackers then leverage bots to automate a barrage of login attempts across a variety of services in the hope that the credentials have been reused on multiple platforms.” According to the…

Read More

Critical Use-After-Free Vulnerability Found in Chrome’s Lens Component

Kirsten DoyleMarch 26, 20253 Mins Read

Google Chrome has confirmed in a statement on 20 March that a security researcher has discovered a critical vulnerability affecting all users across every platform—except, unsurprisingly, iOS. Full technical details have not been published to give users time to protect their systems, the severity of the issue is undeniable. CVE-2025-2476 is a critical-rated use-after-free memory issue in the Lens component of the Chrome browser. This, says the Vulners vulnerability database, could enable “remote attackers to exploit heap corruption via crafted HTML.” Simply said, a malicious web page could leave businesses open to attack. According to the MITRE Common Weakness Enumeration…

Read More

Cybersecurity Firm Uncovers Major Oracle Cloud Breach—Oracle Denies It

Kirsten DoyleMarch 25, 20255 Mins Read

Cybersecurity firm CloudSEK has identified a major data breach involving Oracle Cloud. A threat actor, known as “rose87168,” claims to be selling around 6 million records stolen from Oracle Cloud’s Single Sign-On (SSO) and Lightweight Directory Access Protocol (LDAP) servers. The compromised data includes Java KeyStore (JKS) files, encrypted SSO passwords, key files, and Enterprise Manager Java Platform Security (JPS) keys. These are now for sale Breach Forums and other dark web marketplaces. According to CloudSEK, the breach, discovered on 21 March, is believed to have originated from an undisclosed vulnerability in the Oracle Cloud login endpoint (login.[region-name].oraclecloud.com), allowing unsanctioned…

Read More
Previous 1 … 42 43 44 45 46 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}