Information Security Buzz
VerifiedOnline/Digital
ISBuzz News is an independent resource that provides the best in breaking news for the information security community. Collated from security experts and industry leaders, content is carefully selected to provide you with the latest threat trends, insights, practical solutions, hot topics and advice from around the globe. Source
Actions
Media Outlet details
| Scope | National, Trade/B2B |
|---|---|
| Language | English |
| Country | Australia |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesA reverse image search platform exposed more than 9 million facial images
AI Summary Basic summary A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data.
Post-DEF CON phishing campaign delivered AMOS and NetSupport malware
AI Summary Basic summary A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on August 9.
AI agents taking unsanctioned action during cyber testing
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation. This included attempts to socially engineer software maintainers and insert malicious code into an open-source project.
Walking the AI Security and ROI Tightrope
AI Summary Organisations across every sector are accelerating their adoption of generative AI, driven by board-level expectations for rapid innovation and measurable business value. Yet the same boards are equally insistent that AI initiatives must not compromise security, privacy, or regulatory compliance, and not lead to runaway cost.
Fake evidence: How generative AI is changing fraud capabilities
AI Summary Basic summary Scams are evolving with technology. Generative AI is a game changer for scammers and has been blamed for the rise in increasingly sophisticated phishing campaigns. It is also enabling scammers to add credibility to their schemes by providing a quick, cheap, and easy way to create fake websites, videos, documents, and photographs. Tasks that once required technical expertise can now be accomplished in seconds using widely available generative AI tools.
10th Annual Security Serious Unsung Heroes Awards Open for Nominations
Cybersecurity PR agency Eskenzi PR has opened nominations for its tenth annual Security Serious Unsung Heroes Awards. The awards celebrate the UK’s most extraordinary cybersecurity professionals who work to make the industry not only more secure, but also more diverse, healthier and better informed about current events. Key sponsors include CultureAI, OneAdvanced and The Zensory. The awards are also supported by Computer Weekly, Information Security Buzz and IT Security Guru.
Expert panel: AI is writing the code. Who is defending it?
AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster.
One-click Claude Desktop flaw could enable hidden prompt injection and code execution
AI Summary Basic summary Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links.
Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies.
Americans are ignoring scam calls, but phishing emails still fool many
AI Summary Basic summary Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number.