Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 46

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

GitHub Leak Puts Software Supply Chains at Risk: Thousands of Secrets Exposed

Kirsten DoyleMarch 18, 20255 Mins Read

Over 23,000 organizations may be at risk following a supply chain attack affecting tj-actions/changed-files GitHub Action, say researchers at StepSecurity. GitHub Actions is a CI/CD service that allows developers to automate software builds and testing. Workflows run in response to specific events, such as committing new code to a repository. With adoption in over 23,000 repositories, tj-actions/changed-files is a GitHub Action designed to retrieve all files and directories. Last Friday, a malicious commit in the Action was uncovered whereby bad actors modified its code and retroactively updated multiple version tags to reference the malicious commit. The supply chain compromise has…

Read More

The API Security Illusion: IT Leaders May Be Overconfident

Kirsten DoyleMarch 18, 20255 Mins Read

As APIs become more integral to both everyday digital services and complex AI systems, concerns over their security are growing — and not without good reason. APIs are the connective tissue of modern software, but without strong governance, they can also represent serious vulnerabilities. Recent research by Kong, called “API Security Perspectives 2025”, highlights that API security is increasingly seen as a critical concern for IT teams, as AI-enhanced threats push the boundaries of traditional cybersecurity defenses. Kong also forecasts a staggering 548% increase in API attacks by 2030, underscoring that API security risks are expected to accelerate significantly in…

Read More

FCC Chairman Establishes New National Security Council to Tackle Tech Threats

Kirsten DoyleMarch 18, 20253 Mins Read

FCC Chairman Brendan Carr has announced the creation of a new Council on National Security within the agency, which he says aims at strengthening US defenses against foreign technology threats — particularly those from China. According to the FCC, the Council will use the full scope of the FCC’s regulatory, investigatory, and enforcement powers to protect US networks, technology, and supply chains. Carr also appointed Adam Chan, his National Security Counsel, as the first Director of the Council. “Today, the country faces a persistent and constant threat from foreign adversaries, particularly the CCP,” said Carr. “These bad actors are always…

Read More

New AI “Agents” Could Help Bad Actors Launch Attacks

Kirsten DoyleMarch 18, 20255 Mins Read

The next generation of artificial intelligence (AI), known as “agents,” may open the door to new cyber threats, experts are warning.  AI agents are advanced tools that can carry out tasks on their own, such as browsing the internet, writing emails, or even interacting with websites. While they are designed to help people automate mundane jobs, they can also be used by malicious actors to carry out cyberattacks more easily. A New Tool for Malefactors? Until now, threat actors have used AI to help craft convincing phishing emails or write malicious code, but these tools needed people to operate them…

Read More

CISA Flags Critical Ivanti Vulnerabilities Actively Exploited in the Wild

Kirsten DoyleMarch 17, 20253 Mins Read

The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged three newly discovered Ivanti Endpoint Manager (EPM) vulnerabilities—CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161—to its Known Exploited Vulnerabilities (KEV) Catalog, warning federal agencies and entities of active exploitation attempts. The flaws stem from absolute path traversal weaknesses that allow remote, unauthenticated attackers to fully compromise vulnerable Ivanti EPM servers. The vulnerabilities were first reported in October 2023 by Horizon3.ai researcher Zach Hanley and patched by Ivanti on 13 January. However, just over a month later, Horizon3.ai released proof-of-concept (PoC) exploits demonstrating how these vulnerabilities could be used in relay attacks to coerce Ivanti…

Read More

Arctic Wolf Warns of Ongoing Attacks Targeting FortiGate Firewall Management Interfaces

Kirsten DoyleMarch 17, 20253 Mins Read

Arctic Wolf has warned the industry about ongoing malicious activity targeting the management interfaces of FortiGate firewall devices, which are exposed to the public internet. According to the company, bad actors have been actively exploiting these interfaces since early December last year. While the total extent of the attacks is still being investigated, entities that use these products should review and tighten their security practices immediately. Management interfaces on firewalls are a known target for malicious actors trying to gain initial access to company networks. They often lead to ransomware and other malicious acts. Arctic Wolf stressed that similar attack…

Read More

AsyncRAT Surges in Global Malware Rankings

Kirsten DoyleMarch 17, 20253 Mins Read

The latest Global Threat Index from Check Point Software Technologies has revealed a sharp rise in AsyncRAT attacks, pushing this stealthy remote access Trojan (RAT) into the top four most prevalent malware strains worldwide.   This is a concerning trend: malicious actors are increasingly eyeing and exploiting trusted platforms to slip through security nets and gain a toehold in company networks. A Growing Global Menace According to researchers, AsyncRAT is being deployed in sophisticated phishing campaigns, often disguised behind Dropbox and TryCloudflare links to bypass conventional security solutions. Once a user clicks, a multi-stage infection chain unfolds, involving LNK, JavaScript, and…

Read More

Microsoft Uncovers New XCSSET macOS Malware Variant Targeting Xcode Projects

Kirsten DoyleMarch 14, 20254 Mins Read

Microsoft Threat Intelligence has discovered a new variant of XCSSET, a sophisticated modular macOS malware that targets Xcode projects. The malware was found in the wild during routine threat hunting and is the first known XCSSET variant to surface since 2022. This new version of XCSSET features stronger obfuscation methods, updated techniques to maintain persistence on infected machines, and new ways of infecting systems. These improvements help the malware steal and exfiltrate files, as well as sensitive system and user information, including digital wallet data and personal notes. XCSSET is designed to infect Xcode projects and executes when a developer…

Read More

DeepSeek Can Be Abused to Create Malware

Kirsten DoyleMarch 14, 20256 Mins Read

In a recent investigation, Tenable researchers explored how DeepSeek, a large language model (LLM) built by a Chinese company, can be exploited to generate malware, including keyloggers and ransomware, despite its initial refusal to engage in harmful activities. Unlike popular AI models like GPT-4 or Claude, DeepSeek is fully open-source, so anyone can download and use it for free. It’s trained on large datasets, including code, making it very powerful — yet potentially dangerous.  From Guardrails to Jailbreaks Mainstream GenAI platforms like ChatGPT and Gemini also have well-documented protections against malicious use. Reports like OpenAI’s “Disrupting malicious uses of AI…

Read More

OpenAI Pushes for Federal-Only AI Regulation

Kirsten DoyleMarch 14, 20254 Mins Read

OpenAI has officially called on US lawmakers to exempt it from complying with state-level AI regulations, instead urging a unified approach under federal AI rules. It argues that a consistent, nationwide framework is critical to maintain US leadership in AI development and deployment. In a newly released policy proposal, the company outlines what it calls a “freedom-focused” strategy, emphasizing that only a national approach will allow American innovation to flourish without being slowed by fragmented, state-specific requirements. Key Elements of OpenAI’s Policy Proposal: Shaping the Future Regulatory Landscape If these proposals are adopted, they could shape the future regulatory landscape.…

Read More
Previous 1 … 44 45 46 47 48 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}