Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 47

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Volt Typhoon Found Inside Massachusetts Electric Utility for Nearly a Year

Kirsten DoyleMarch 14, 20256 Mins Read

Industrial cybersecurity firm Dragos has revealed that a small electric and water utility in Massachusetts was breached by a sophisticated Chinese advanced persistent threat (APT) group for over 300 days.  The attack targeted Littleton Electric Light and Water Departments (LELWD), which serves the towns of Littleton and Boxborough. According to a Dragos case study, the APT group, known as Volt Typhoon, had been inside LELWD’s network since February 2023 but was only discovered in November 2023, just before Thanksgiving. Volt Typhoon, a group linked to the Chinese government, was first publicly identified by Microsoft in May 2023. Since then, the…

Read More

NHS Investigates Alleged API Flaw That May Have Exposed Patient Data

Kirsten DoyleMarch 14, 20257 Mins Read

The NHS is investigating claims made by a whistleblower regarding a security flaw at Medefer, an online healthcare provider working with the NHS. The whistleblower alleged that a flaw in the company’s application programming interface (API) exposed NHS patient data. Medefer, however, has denied the claims and insists that the vulnerability has been addressed.   When a patient is referred to Medefer for an online appointment, the company receives patient data from the NHS’s e-referral system (e-RS) or the NHS Spine, which is then made available to medical professionals for consultations. The whistleblower, a software testing contractor, claimed that in November…

Read More

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

Kirsten DoyleMarch 13, 20254 Mins Read

In a joint advisory, US federal agencies have issued a cybersecurity warning about a sharp increase in attacks by Medusa ransomware, urging business leaders and IT teams to act immediately to protect their organizations.  The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) released the advisory as part of the national #StopRansomware initiative, which focuses on helping entities defend against ransomware threats. The Impact on Critical Infrastructure and Business Operations Medusa ransomware is a Ransomware-as-a-Service (RaaS) operation first detected in 2021. Since then, Medusa has been used to…

Read More

Google Uncovers China-Linked Espionage Campaign Targeting Juniper Routers 

Kirsten DoyleMarch 13, 20253 Mins Read

Google’s Threat Analysis Group (TAG) and Mandiant have uncovered a sophisticated espionage campaign linked to China-nexus threat actors, targeting vulnerable Juniper routers used in enterprise and government networks worldwide. This discovery highlights the ongoing risks posed by state-sponsored attacks against aging network infrastructure.  The malicious actors honed in on end-of-life and unpatched Juniper routers, exploiting known vulnerabilities to gain a foothold in networks. Many of these devices are still in active use despite lacking security updates, making them compelling targets.  After exploiting the routers, the actors behind the campaign deployed custom-built malware frameworks to maintain persistent access—tools that allowed them…

Read More

New Bill Aims to Strengthen Cybersecurity for Federal Contractors

Kirsten DoyleMarch 13, 20256 Mins Read

The House of Representatives has passed a bill that mandates contractors working with the federal government implement vulnerability disclosure policies (VDPs) in alignment with NIST guidelines.    The Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, introduced by Chairwoman Nancy Mace (R-S.C.) and Ranking Member Shontel Brown (D-Ohio), directs the Office of Management and Budget (OMB) to work with CISA, the National Cyber Director’s Office, NIST, and other agencies. The bill also asks the Defense Department to ensure defense contractors adopt similar policies. The Office of Management and Budget and the Department of Defense will be required to update federal acquisition…

Read More

Confidence Gap in Cybersecurity Leaves Businesses at Risk

Kirsten DoyleMarch 13, 20254 Mins Read

New research has revealed that although 86% of employees believe they can confidently identify phishing emails, nearly half have fallen for scams. The study, conducted by KnowBe4, surveyed professionals in the UK, USA, Germany, France, Netherlands, and South Africa and revealed a growing chasm between confidence and competence in identifying cyber threats. Interestingly, South Africa leads with both the highest confidence levels and the highest scam victimization rate, suggesting that confidence is unwarranted and fuels a false sense of security, leaving workers more susceptible to advanced cyber threats. Fluctuating Confidence Levels Across all demographics, confidence levels depended largely on the…

Read More

Gone in 120 Seconds: TRUMP Coin Phishing Lure Delivers RAT

Kirsten DoyleMarch 12, 20253 Mins Read

A phishing email pretending to be from Binance, offering people the chance to claim newly created TRUMP coins, has turned out to be a phishing lure. Cofense is warning that if victims follow the email’s instructions and download what is called “Binance Desktop,” they actually install a remote access tool that gives malicious actors control of their computers within two minutes. To make the scam more convincing, the attackers used “Binance” as the sender’s name and included a fake “risk warning” to make the email seem trustworthy. They also fashioned a fake website that closely resembles the Binance site to…

Read More

X Under Siege: Massive Cyberattack Sparks Widespread Outages as Experts Call Musk’s Ukraine Claims ‘Garbage’

Kirsten DoyleMarch 12, 20253 Mins Read

Elon Musk confirmed yesterday that social media platform X was hit by a “massive cyberattack” affecting users since Monday, causing issues like the inability to view posts or profiles properly. “There was (still is) a massive cyberattack against ,” he said. “We get attacked every day, but this was done with a lot of resources. Either a large, coordinated group and/or a country is involved.” DownDetector reported multiple waves of attacks, with tens of thousands of users experiencing outages. Speaking to Fox Business, Musk said the attack involved IP addresses from the Ukraine area and suggested it may have been…

Read More

Typosquatted Go Packages Distribute Malware Loader Targeting Linux and macOS

Kirsten DoyleMarch 6, 20254 Mins Read

Researchers from Socket have identified an ongoing campaign involving at least seven typosquatted Go packages. These packages impersonate well-known Go libraries and are designed to deploy loader malware on Linux and macOS systems. Typosquatted packages are malicious software components designed to mimic the names of popular, legitimate packages. In the context of Go programming, these packages are created with names that are very similar to widely used Go libraries. The goal is to deceive developers into installing these malicious packages instead of the genuine ones.  According to Socket: “In February 2025, the threat actor released four malicious packages on the…

Read More

Silk Typhoon Targets IT Supply Chain in Evolving Cyber Campaign

Kirsten DoyleMarch 6, 20255 Mins Read

Microsoft Threat Intelligence has warned of a shift in tactics by Silk Typhoon, a Chinese espionage group that is now exploiting vulnerabilities in common IT solutions—including remote management tools and cloud applications—to gain initial access to target entities. The software giant says it has not observed direct attacks against its cloud services, but has seen the group exploiting unpatched applications to escalate access and conduct malicious activities within compromised networks. Once inside, Silk Typhoon uses stolen credentials to get a foothold in customer environments, abusing a range of deployed applications—including Microsoft services—for cyberespionage.  A Well-Resourced and Expansive Threat Silk Typhoon…

Read More
Previous 1 … 45 46 47 48 49 … 61 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}