Infosec stories - Page 3
Small alert, big defense: Inside a SOC's early-morning response
Last week
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
Anthropic launches Project Glasswing for cyber defence
Last week
#
firewalls
#
hyperscale
#
network security
Anthropic enlists Amazon, Apple and Microsoft in Project Glasswing to use Claude Mythos Preview for hunting vulnerabilities in critical software.
Secureframe launches access review tool for compliance teams
Last week
#
data protection
#
pam
#
cloud security
Secureframe adds user access reviews to Comply platform to help compliance teams replace spreadsheets and email with a single audit-ready workflow.
Orca Security flags AI secrets & supply chain gaps
Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
iProov report warns of soaring iOS injection attacks
Last week
#
uc
#
data protection
#
devops
iProov warns iOS injection attacks surged 1,151% in late 2025 as generative AI fuels deepfake impersonation and identity fraud.
Abacus wins CREST approval for penetration testing
Last week
#
firewalls
#
data protection
#
devops
Abacus secures CREST accreditation for penetration testing, bolstering its pitch to regulated sectors as demand rises for verified cyber security assurance.
Arctic Wolf wins Gartner Customers' Choice for MDR
Last week
#
cloud security
#
cx
#
martech
Arctic Wolf earns a strong 2026 Gartner Peer Insights showing for managed detection and response, backed by 241 reviews and a 99% recommendation rate.
2N urges tougher cyber rules for access control devices
Last week
#
edutech
#
data protection
#
hyperscale
2N calls for tougher cyber rules on access control, urging stronger vulnerability reporting, tighter component sourcing and longer support lifecycles.
Dynatrace to buy Bindplane in telemetry pipeline push
Last week
#
devops
#
hybrid cloud
#
digital transformation
Dynatrace agrees to buy Bindplane to expand telemetry pipelines, aiming to cut ingest costs and give customers greater control over observability data.
Microsoft 365 EvilToken campaign hits hundreds daily
Last week
#
mfa
#
cloud security
#
phishing
Microsoft warns that 10 to 15 EvilToken phishing runs are launched daily, compromising hundreds of organisations through OAuth token abuse.
Qualys warns attackers exploit flaws before disclosure
Last week
#
firewalls
#
vpns
#
network security
Qualys says attackers are exploiting flaws before disclosure as remediation backlogs swell, with edge devices facing the highest risk.
TrendAI: Evolving the cybersecurity value proposition
Last week
#
hybrid cloud
#
digital transformation
#
cloud security
TrendAI urges stronger AI governance as it shifts cybersecurity from fear-based selling to platformised risk reduction for Australian firms.
Anthropic launches Project Glasswing for cyber defence
Last week
#
firewalls
#
hyperscale
#
network security
Anthropic expands a guarded AI pilot with Amazon, Apple, Microsoft and others, offering Claude Mythos Preview to hunt flaws in critical code and open source.
Building digital trust: Data quality provides a scalable path
Last week
#
data protection
#
fintech
#
cx
Data quality gives banks a scalable route to digital trust, cutting fraud and false positives while speeding onboarding, KYB and AI-driven checks.
China-aligned TA416 resumes spying on EU & Mideast
Last week
#
phishing
#
email security
#
cybersecurity
China-linked TA416 returns to spying on European diplomats and later expands attacks to Middle Eastern government targets after Iran conflict.
Commvault adds structured data controls for AI risk
Last week
#
data protection
#
dr
#
hybrid cloud
Commvault adds structured database controls to Commvault Cloud after Satori deal, aiming to curb AI-era exposure across live and backup data.
GigaOm names Check Point leader in app & API security
This month
#
firewalls
#
devops
#
hybrid cloud
GigaOm names Check Point a third-year application security leader as its WAF posts strong detection rates and low false positives.
Attackers turn trusted tools into cyber weapon
This month
#
malware
#
ransomware
#
advanced persistent threat protection
Attackers abuse trusted tools, remote support software and stolen SSO sessions to breach systems, ReliaQuest says.
ChatGPT flaw let hackers steal data via DNS queries
This month
#
firewalls
#
data protection
#
devops
ChatGPT flaw may have let attackers siphon sensitive user data via DNS queries, prompting OpenAI to issue a fix after researchers exposed the bug.
Upwind hires ex-Facebook security chief Joe Sullivan
This month
#
data protection
#
cloud security
#
socs
Upwind taps former Facebook security chief Joe Sullivan to bolster cloud and AI strategy as it eyes enterprise buyers and rapid growth.