Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Archives for Kirsten Doyle - Page 9

Kirsten Doyle

Kirsten Doyle

Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

Substack Discloses Major Data Breach

Kirsten DoyleFebruary 9, 20265 Mins Read

Media platform Substack has disclosed a data breach that exposed email addresses, phone numbers, and internal metadata of an unknown number of users. Credit card numbers, passwords, and financial information were not accessed. In an email, Substack CEO Chris Best informed affected users that on 3 February, the company found evidence pointing to a third party having exploited an unspecified weakness in its systems. The breach happened in October 2025, meaning user data remained exposed for about four months before discovery. Best added that the company is conducting a thorough investigation, and is “taking steps to improve our systems and processes to prevent this…

Read More

The Winter Olympics Are Back, and So Are Attackers

Kirsten DoyleFebruary 6, 20264 Mins Read

The Olympics have traditionally been a major attack vector for cyber disruption, espionage, and financially motivated attacks. The 2018 Winter Olympic Games in PyeongChang saw the Olympic Destroyer malware used to disrupt Wi-Fi, ticket, and venue systems during the opening ceremony of the games. During the Paris 2024 event, there was an increase in scanning, DDoS, and other attempts targeting Olympic-related systems.  The Milan-Cortina 2026 event kicks off today, promising to be the most geographically distributed Winter Olympics on record. This will see the attack surface expand even further, spanning multiple cities, suppliers, digital platforms, and temporary networks. Security leaders…

Read More

Microsoft: Python-Powered Infostealers Are Now Targeting macOS at Scale

Kirsten DoyleFebruary 5, 20265 Mins Read

Microsoft has warned that information-stealing attacks are rapidly expanding beyond Windows to target Apple macOS environments using cross-platform languages such as Python. The software giant’s Defender Security Research Team has observed macOS-targeted infostealer campaigns using social engineering techniques like ClickFix since late 2025 to distribute disk image (DMG) installers that deploy stealer malware families like Atomic macOS Stealer (AMOS), MacSync, and DigitStealer. The campaigns have been using techniques like fileless execution, native macOS utilities, and AppleScript automation to facilitate data theft, including web browser credentials and session data, iCloud Keychain, and developer secrets. The basis for these attacks is usually a malicious ad, most often delivered via Google Ads, that tricks users searching…

Read More

Forescout’s 2025 Threat Roundup: 84% OT Surge Signals Expanding Cyber Chaos

Kirsten DoyleFebruary 5, 20264 Mins Read

In 2025, attackers didn’t only target traditional areas of vulnerability; they went after those with the least defense and the most rapid change. These include new AI technologies, web applications, and operational technology (OT) for industries such as healthcare, manufacturing, energy, government, and finance.   In fact, attacks against OT protocol rose by a whopping 84% with Modbus, Ethernet/IP, and BACnet at the forefront. IoT exploits increased to 19%, hitting cameras and video recorders the hardest, while network devices accounted for some 19% of all exploits. This is no surprise, because last year, IT, IoT, and OT saw broad expansion amid rapid infrastructure shifts. These were some of the findings of the recent 2025 Threat Roundup by Forescout Technologies – Vedere Labs. The research aims to…

Read More

Notepad++ Update Hijacked in Six-Month, State-Linked Supply-Chain Attack

Kirsten DoyleFebruary 3, 20266 Mins Read

Attackers have hijacked the update mechanism of Notepad++, one of the world’s most popular open-source text editors, delivering malware to targeted users over a period of six months. In an advisory, developer Don Ho discussed how bad actors weaponized his two-decade-old project between June and December last year. An update, said: “Multiple independent security researchers have assessed that the threat actor is likely a Chinese state-sponsored group, which would explain the highly selective targeting observed during the campaign.” The attack employed infrastructure-level compromise that enabled bad actors to intercept and redirect update traffic destined for notepad-plus-plus.org. “The exact technical mechanism remains under investigation, though the compromise occurred at the hosting provider level rather than through vulnerabilities in Notepad++ code itself. Traffic…

Read More

Attackers allege 1.4TB data breach at Iron Mountain

Kirsten DoyleFebruary 3, 20263 Mins Read

The Everest ransomware group has claimed responsibility for the breach against the global information management and storage firm Iron Mountain, stating that it stole approximately 1.4 terabytes of the firm’s internal and customer data. The claims were made through the group’s posts on the dark web forums. The images provided by the attackers reveal that the names of several directories contain the names of potential customer accounts and organizational documents. The ransom demand deadline is set for 11 February. Currently, no official statements have been provided by the firm regarding the breach or its potential extent. Iron Mountain manages various types of information, including physical and digital, for a broad…

Read More

Data Privacy Week 2026: Why Good Intentions Are No Longer Enough

Kirsten DoyleJanuary 30, 202613 Mins Read

It’s Data Privacy Week, the annual international awareness initiative from the National Cybersecurity Alliance (NCA) aimed at empowering individuals and businesses to value individual privacy, safeguard data, and build trust.  “Your online activities generate a treasure trove of data – from your interests to your purchases, as well as your online behaviors, and it is collected by websites, apps, devices, services, and companies across the globe, and can even include data about your physical self, such as health data,” the NCA says. The week, cybersecurity experts from many companies shared their data privacy and risk advice with us. Let’s hear what they had to say Are…

Read More

Expert Panel: Cyber Ready for 2026, Or Just Confident on Paper?

Kirsten DoyleJanuary 28, 202621 Mins Read

Many organizations entering 2026 do not feel they have fallen behind in their overall cyber-readiness. In fact, several believe they are doing everything right.   They now have a wide range of new tools, greater visibility into how their systems operate, an almost endless array of metrics to measure performance, and more compliance certifications than ever before. With all of this comes a great deal of confidence. Confidence, however, as this panel will demonstrate, is often used as a substitute for actual capability.  The same pattern of overestimating one’s cyber-readiness continues across various sectors and industries. Security estates that appear to be robust in design and implementation,…

Read More

Researchers Show How Calendar Invites Can Be Weaponized in Google Gemini

Kirsten DoyleJanuary 23, 20264 Mins Read

Security researchers at Miggo, have disclosed a vulnerability in Google’s Gemini assistant that allowed a standard calendar invitation to be used as an attack vector, exposing private meeting data through a form of prompt injection that relied entirely on natural language. The issue was discovered by a research team led by Liad Eliyahu, head of research, and was responsibly disclosed to Google. The company confirmed the findings and has since mitigated the vulnerability, they said. The exploit shines a light on the emerging risks that come with AI-powered applications that deeply integrate with user data and productivity tools. “As application security professionals, we’re trained to spot malicious patterns. But…

Read More

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

Kirsten DoyleJanuary 22, 20266 Mins Read

ReliaQuest has investigated a phishing campaign that exploited private messages in social media to deliver weaponized files via DLL sideloading, as well as a legitimate, open-source Python pen-testing script. The company says the aim was more than likely to deploy a remote access trojan (RAT).  This approach enables bad actors to bypass detection and scale their operations with little effort while maintaining persistent control over compromised systems. Once inside, malefactors can escalate privileges, move laterally across networks, and steal data. In the report, ReliaQuest threat intelligence analyst Emily Jia discussed an unusual tactic at the heart of this campaign: the execution of an open-source Python…

Read More
Previous 1 … 7 8 9 10 11 … 61 Next
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}