Install
Infosecurity Magazine is the award winning online magazine dedicated to the strategy, insight and technology of information security The award winning online magazine dedicated to the strategy, insight and technology of information security
- 80articles · 30d
- 2+ day agolatest article
- Aug 16, 2026earliest in window
- 98%with images
- 353avg words
- Science & Technology 50
- Crime & Law 34
- Computers & Electronics 27
- Software 20
- News 19
- Conflict, War & Peace 15
- Science & Nature 15
- Law & Government 9
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Outsider Phishing Kit Survives Takedown With 700 New Pages
1+ week, 3+ day ago (405+ words) A phishing-as-a-service (PaaS) operation has continued generating new campaigns despite a coordinated takedown effort, with more than 700 new phishing pages identified within a month of the disruption. Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by a…...
ZeroTokens Phishing Platform Steers Attacks in Real Time
2+ week, 5+ day ago (371+ words) A phishing platform dubbed ZeroTokens allows attackers live visibility into victim sessions and the ability to change subsequent prompts in real time, allowing attacks to adapt in real time while targeting credentials and financial information. The platform allowed an operator…...
NIST Warns of Unique Security Risks in Multi-Cloud Environments
2+ week, 6+ day ago (698+ words) The US government has warned organizations of the unique cybersecurity and compliance challenges presented by multi-cloud environments. The National Institute of Standards and Technology (NIST) highlighted how using multiple cloud service providers (CSPs) makes it more difficult for organizations to…...
Researchers Uncover Thousands of Leaked AWS Keys
2+ week, 6+ day ago (296+ words) Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights. Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging…...
New Agent Tesla Malware Variant Boosts Evasion Capabilities
3+ week, 2+ day ago (537+ words) A new version of the notorious Agent Telsa malware contains new features designed to evade detection and steal credentials, KnowBe4 research has identified. The cybersecurity firm provided a detailed analysis of the Agent Tesla version 4 infostealer, which was observed being dropped…...
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
3+ week, 3+ day ago (316+ words) Two vulnerabilities in JFrog Artifactory have been found which allow anonymous or low-privileged users to manipulate package metadata without modifying the underlying artifacts, creating a potential route to software supply chain compromise. Oligo Security reported the flaws to JFrog on…...
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
3+ week, 3+ day ago (330+ words) Security researchers have warned of a new variant of a prolific Android banking Trojan which substantially expands its potential victim count. ToxicPanda 2.0 was discovered by Zimperium’s zLabs team, the mobile security vendor wrote in a post on August 19. Most notable…...
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
3+ week, 4+ day ago (335+ words) A malware-as-a-service (MaaS) campaign has combined ClickFix social engineering with the ErrTraffic delivery service and Cruciferra loader, giving attackers a way to distribute malware while disabling endpoint security processes. In a new advisory published earlier today, eSentire’s Threat Response Unit…...
WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
3+ week, 6+ day ago (197+ words) Read more on WordPress plugin flaws: Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites The issue stems from a type confusion error in the plugin’s registration and automatic-login flow. Wordfence, a security plugin for WordPress, found that…...