A Chinese state-sponsored hacker group called RedNovember has conducted a global espionage campaign targeting critical infrastructure between June 2024 and July 2025,…
News
XWorm campaign shows a shift toward fileless malware and in-memory evasion tactics
In a newly disclosed multi-stage threat campaign, attackers were seen skipping disk and leaning on in-memory tricks to deliver the XWorm remote…
Agentic AI in IT security: Where expectations meet reality
Agentic AI has quickly shifted from lab demos to real-world security operations centers (SOC) deployments. Unlike traditional automation scripts, autonomous software agents…
Coherence: Insider risk strategy’s new core principle
I have been addressing insiders and insider risks for the better part of 40 years. Different names, same issue: Those breaking trust…
Junge Onliner tappen oft in Phishing-Fallen
Laut einer Umfrage fällt die jüngere Generation leichter auf Phishing herein. janews – shutterstock.com Obwohl sie digital versierter sind als jede andere…
6 Mittel gegen Security-Tool-Wildwuchs
loading=”lazy” width=”400px”>Viel hilft nicht immer viel. Roman Samborskyi | shutterstock.com Auf der Suche nach Möglichkeiten, sich vor ständig wachsenden Cyberbedrohungen zu schützen,…
CSO30 Awards 2025 celebrate Australia’s top cybersecurity leaders
Australia’s top cybersecurity leaders and their teams have been recognised at this year’s CSO30 Awards. Held in conjunction with the CIO50, the CSO30 Australia Awards is…
Meet LockBit 5.0: Faster ESXi drive encryption, better at evading detection
The LockBit gang has released a new version of its ransomware with improved ESXi drive encryption speed. However, a security researcher who…
Identity Management and Information Security News for the Week of September 26th: Okta, Delinea, Rubrik, and More
The editors at Solutions Review have curated this list of the most noteworthy Identity Management and Information Security news from the week…
Trust in MCP takes first in-the-wild hit via squatted Postmark connector
In a newly disclosed supply-chain attack, an npm package “postmark-mcp” was weaponized to stealthily exfiltrate emails, marking the first reported in-the-wild abuse…