Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 51

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

CISA, FBI Warn of Threats Exploiting Buffer Overflow Vulnerabilities

Kirsten DoyleFebruary 13, 20252 Mins Read

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a new Secure by Design Alert warning about the risks posed by buffer overflow vulnerabilities in software. The alert, titled “Eliminating Buffer Overflow Vulnerabilities,” highlights the need for secure software development practices to prevent malicious actors from exploiting these weaknesses. Buffer overflow vulnerabilities, a common flaw in software design, can be exploited to compromise systems, leading to data corruption, unauthorized code execution, program crashes, and sensitive information being exposed.   Threat actors often use these vulnerabilities as an entry point to infiltrate networks and move…

Read More

DeepSeek-R1: A Smorgasbord of Security Risks

Kirsten DoyleFebruary 12, 20254 Mins Read

In the short time since its debut, DeepSeek has made waves in the AI industry, garnering praise as well as scrutiny. The model’s meteoric rise has fueled debate over its claimed efficiency, intellectual property worries, and its general reliability and safety. A week ago, Information Security Buzz wrote about how a Qualys security analysis raised significant red flags about DeepSeek-RI’s risks, especially in enterprise and regulatory settings.  Now, fresh research from AppSOC has uncovered more alarming security risks associated with the DeepSeek-R1 model, raising critical questions about its suitability for enterprise use. Massive Security Failures The AppSOC Research Team conducted an…

Read More

UK and US refuse to sign international AI declaration 

Kirsten DoyleFebruary 12, 20253 Mins Read

The UK and the US have opted not to sign an international agreement on artificial intelligence (AI) at a global summit held in Paris. The declaration—endorsed by multiple countries including France, China, and India—commits to an “open,” “inclusive,” and “ethical” approach to AI development.  The UK government issued a brief statement explaining that it refrained from signing due to concerns over national security and “global governance.” Earlier, US Vice President JD Vance warned summit delegates that excessive regulation of AI could “kill a transformative industry just as it’s taking off.” Open, Transparent, Ethical The signed declaration stresses the importance of…

Read More

Bad Actors Target DeepSeek in LLMJacking Attacks

Kirsten DoyleFebruary 10, 20253 Mins Read

Cybercriminals are rapidly evolving their tactics for exploiting large language models (LLMs), with recent evidence showing a surge in LLMjacking incidents. Since Sysdig TRT first discovered LLMjacking in May 2024,  it says attackers have continuously adapted, targeting new models such as DeepSeek and monetizing stolen credentials through proxy services.  The rapid rise of DeepSeek, an advanced AI model, has not gone unnoticed by malefactors. Following the release of DeepSeek-V3 on 26 December 2024, attackers integrated it into OpenAI Reverse Proxy (ORP) instances within days. A similar pattern followed the launch of DeepSeek-R1 on 20 January this year, highlighting the speed…

Read More

Sectigo Debuts Post-Quantum Cryptography Testing Platform with Crypto4A

Kirsten DoyleFebruary 7, 20254 Mins Read

Sectigo has introduced Sectigo PQC Labs, a testing platform developed in collaboration with Crypto4A, a provider of quantum-safe Hardware Security Modules (HSMs).   The platform aims to help companies prepare for the transition to post-quantum cryptography (PQC) by offering a secure environment to test, validate, and implement quantum-resistant cryptographic certificates.  Start Planning for Postquantum Cryptography According to Gartner: “Security and risk management leaders need to begin planning for their move to postquantum cryptography (PQC) now, due to the wide and deep impact of replacing cryptographically dependent systems.” Sectigo PQC Labs enables entities to safely explore, test, validate and create postquantum cryptographic…

Read More

The RAT Pack Returns: ValleyRAT’s Devious Delivery Methods 

Kirsten DoyleFebruary 7, 20253 Mins Read

Morphisec Threat Labs has uncovered cunning new delivery techniques used by ValleyRAT, a sophisticated multi-stage malware attributed to the Silver Fox APT.   The malware, which primarily targets key roles in finance, accounting, and sales, has evolved with updated tactics, techniques, and procedures (TTPs), including the reuse of URLs and the exploitation of gaming binaries for payload injection. Targeted Attack Strategies The Silver Fox APT uses a host of distribution methods to achieve its nefarious goals, including phishing emails, malicious websites, and IM platforms. The latest attacks also reveal a strategic shift, by targeting more high-value roles within organizations to access…

Read More

Qualys Report Raises Red Flags in DeepSeek-RI Security

Kirsten DoyleFebruary 6, 20257 Mins Read

A recent security analysis conducted by Qualys, using its QualysTotalAI solution, has raised significant concerns about DeepSeek-RI’s risks, particularly in enterprise and regulatory settings.  The newly released large language model (LLM) has captured global attention with its promise of high efficiency and accessibility. Developed by the Chinese startup DeepSeek, the model promises competitive performance while draining fewer computational resources than its Western counterparts. DeepSeek-R1: A New AI Contender DeepSeek has introduced multiple distilled versions of DeepSeek-R1, leveraging Llama and Qwen as base models. These variations cater to different use cases, from lightweight models optimized for efficiency to larger, more powerful…

Read More

Credential-stealing malware surges in 2024 

Kirsten DoyleFebruary 6, 20253 Mins Read

Malware designed to steal credentials from password stores now accounts for 25% of all malware activity—a dramatic threefold increase in this type of threat.  This was one of the findings of Picus Security’s annual cybersecurity analysis, The Red Report 2025. This is the first time that credentials theft has ranked among the top 10 techniques in the MITRE ATT&CK framework. The report, based on an extensive review of over one million malware samples collected throughout 2024, also highlights how only 10 MITRE ATT&CK techniques were responsible for 93% of all malicious actions observed last year. “SneakThief” Malware Bad actors are…

Read More

2024: The Year Data Security Took a Beating

Kirsten DoyleFebruary 5, 20256 Mins Read

2024 was a brutal year for data security, with some of the world’s biggest companies suffering breaches that exposed millions of sensitive records.   The attacks were carried out by well-known cybercriminal groups, including Alphv/BlackCat, Qilin, and Rhysida, and shone a light on the ongoing vulnerabilities the industry faces every day – cloud platforms, financial institutions, healthcare systems – no one is safe. Here’s Arctic Wolf’s breakdown of the most significant breaches of the year and recommendations to avoid similar incidents in the future.   Ransomware Attack Impacts a Third of the US Population An affiliate of Alphv/BlackCat targeted Change Healthcare in…

Read More

Threat Actors Exploit DeepSeek’s Popularity to Distribute Infostealers on PyPI 

Kirsten DoyleFebruary 4, 20254 Mins Read

Malicious actors have exploited the rising popularity of DeepSeek AI to distribute two malicious infostealer packages through the Python Package Index (PyPI), impersonating legitimate developer tools for the AI platform.   Researchers at Positive Technologies discovered and reported the campaign, which targeted developers, machine learning engineers, and AI enthusiasts integrating DeepSeek AI into their systems. A Prime Target The malicious campaign was detected and mitigated by the Supply Chain Security team at the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC). PyPI serves as the default package repository for popular package managers such as pip, pipenv, and…

Read More
Previous 1 … 49 50 51 52 53 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}