Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 49

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Eight Cloud Security Best Practice Fundamentals for Microsoft Azure

Kirsten DoyleFebruary 18, 20255 Mins Read

As entities of every sector move more apps and workloads to the cloud, security is becoming a top priority. Microsoft Azure, one of the world’s most popular cloud platforms, provides a range of security tools and best practices to help businesses protect their assets stored in their environments.   However, securing an Azure environment is about more than just enabling default protections—it’s about helping users maintain compliance, too. This takes a forward-thinking approach to identity management, network security, logging, and monitoring. To strengthen security, Microsoft has made several key changes, including mandatory Multi-Factor Authentication, new AI-driven security integrations, and enhancements to…

Read More

Massive Data Exposure at Mars Hydro Highlights IoT Security Risks

Kirsten DoyleFebruary 17, 20254 Mins Read

Jeremiah Fowler, an experienced cybersecurity researcher at vpnMentor and co-founder of Security Discovery, has uncovered a massive data exposure involving nearly 2.7 billion records linked to Mars Hydro, a China-based manufacturer of IoT-enabled grow lights. The breach, which included sensitive Wi-Fi credentials, IP addresses, and device details, underscores ongoing concerns about IoT security and data privacy.  Fowler discovered the unprotected database and reported it to vpnMentor. The publicly accessible trove contained 2,734,819,501 records totaling 1.17 terabytes of data, exposing logging, monitoring, and error records for IoT devices sold globally. The records included: The database appeared to belong to LG-LED SOLUTIONS…

Read More

eSentire Uncovers EarthKapre/RedCurl Attack Targeting Law Firms

Kirsten DoyleFebruary 17, 20252 Mins Read

eSentire’s Threat Response Unit (TRU) has uncovered a new cyber espionage campaign leveraging a legitimate Adobe executable to sideload the EarthKapre/RedCurl loader. The attack specifically targeted a firm in the Legal Services industry, highlighting the group’s persistent focus on corporate espionage. A Sophisticated Attack Chain The TRU team said the initial foothold was gained through a phishing campaign, where targets received a PDF file masquerading as an Indeed job application. The PDF contained links to a ZIP archive with an ISO image. Once the victim opened the image file, they encountered what appeared to be a CV file (“CV Applicant…

Read More

Espionage Tools Associated with China Used in Ransomware Attacks

Kirsten DoyleFebruary 14, 20254 Mins Read

Espionage actors linked to China may be diversifying their operations, as new evidence points to the use of espionage tools in a recent ransomware attack against a South Asian software and services company.   Symantec Threat Intelligence reports that the attack, involving the RA World ransomware, stands out due to the distinct toolset typically associated with China-based espionage groups, raising questions about the motivations behind this cross-over from traditional espionage to financially driven cybercrime. Espionage Toolsets Deployed In late 2024, a cyberattack targeting an Asian software company saw the deployment of tools historically used by China-linked espionage actors. These tools, usually…

Read More

From Sweethearts to Swindlers: Valentine’s Day Fraud Surges

Kirsten DoyleFebruary 14, 20256 Mins Read

As people celebrate Valentine’s Day today, malicious actors are jumping on the love bandwagon in an opportunity to exploit heightened emotions and consumer spending with a wave of scam emails. According to the latest findings from Bitdefender Antispam Lab, a whopping 50% of all Valentine’s Day-themed spam emails between 13 January 13 and 7 February this year, were classified as scams—a steep rise from 25% in 2024. Similarly, new data from KnowBe4 revealed a 34.8% spike in Valentine’s Day-related phishing attacks compared to February 2024. Love Is in the Air—and So Are Phishing Scams Bitdefender’s research highlights a growing trend…

Read More

Russia-Linked Seashell Blizzard Intensifies Cyber Operations Against Critical Sectors

Kirsten DoyleFebruary 13, 20254 Mins Read

The Russia-linked threat actor known as Seashell Blizzard has assigned one of its subgroups to gain initial access to internet-facing infrastructure and establish long-term persistence within targeted entity, a Microsoft report has revealed. Also dubbed APT44, BlackEnergy Lite, Sandworm, Telebots, and Voodoo Bear, Seashell Blizzard has been active since at least 2009 and is believed to be linked to Russia’s General Staff Main Intelligence Directorate (GRU) military unit 74455. Targeting Critical Sectors Observed activities following initial access suggest that this campaign allowed Seashell Blizzard to infiltrate global targets across critical sectors, including energy, oil and gas, telecommunications, shipping, arms manufacturing,…

Read More

CISA, FBI Warn of Threats Exploiting Buffer Overflow Vulnerabilities

Kirsten DoyleFebruary 13, 20252 Mins Read

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a new Secure by Design Alert warning about the risks posed by buffer overflow vulnerabilities in software. The alert, titled “Eliminating Buffer Overflow Vulnerabilities,” highlights the need for secure software development practices to prevent malicious actors from exploiting these weaknesses. Buffer overflow vulnerabilities, a common flaw in software design, can be exploited to compromise systems, leading to data corruption, unauthorized code execution, program crashes, and sensitive information being exposed.   Threat actors often use these vulnerabilities as an entry point to infiltrate networks and move…

Read More

DeepSeek-R1: A Smorgasbord of Security Risks

Kirsten DoyleFebruary 12, 20254 Mins Read

In the short time since its debut, DeepSeek has made waves in the AI industry, garnering praise as well as scrutiny. The model’s meteoric rise has fueled debate over its claimed efficiency, intellectual property worries, and its general reliability and safety. A week ago, Information Security Buzz wrote about how a Qualys security analysis raised significant red flags about DeepSeek-RI’s risks, especially in enterprise and regulatory settings.  Now, fresh research from AppSOC has uncovered more alarming security risks associated with the DeepSeek-R1 model, raising critical questions about its suitability for enterprise use. Massive Security Failures The AppSOC Research Team conducted an…

Read More

UK and US refuse to sign international AI declaration 

Kirsten DoyleFebruary 12, 20253 Mins Read

The UK and the US have opted not to sign an international agreement on artificial intelligence (AI) at a global summit held in Paris. The declaration—endorsed by multiple countries including France, China, and India—commits to an “open,” “inclusive,” and “ethical” approach to AI development.  The UK government issued a brief statement explaining that it refrained from signing due to concerns over national security and “global governance.” Earlier, US Vice President JD Vance warned summit delegates that excessive regulation of AI could “kill a transformative industry just as it’s taking off.” Open, Transparent, Ethical The signed declaration stresses the importance of…

Read More

Bad Actors Target DeepSeek in LLMJacking Attacks

Kirsten DoyleFebruary 10, 20253 Mins Read

Cybercriminals are rapidly evolving their tactics for exploiting large language models (LLMs), with recent evidence showing a surge in LLMjacking incidents. Since Sysdig TRT first discovered LLMjacking in May 2024,  it says attackers have continuously adapted, targeting new models such as DeepSeek and monetizing stolen credentials through proxy services.  The rapid rise of DeepSeek, an advanced AI model, has not gone unnoticed by malefactors. Following the release of DeepSeek-V3 on 26 December 2024, attackers integrated it into OpenAI Reverse Proxy (ORP) instances within days. A similar pattern followed the launch of DeepSeek-R1 on 20 January this year, highlighting the speed…

Read More
Previous 1 … 47 48 49 50 51 … 60 Next
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}