Danny Palmer
dannyjpalmer@infosec.exchange
<p>Cybersecurity writer.</p>
Posts
-
Post #4195023
The average cost of a data breach has risen to almost $5m, analysis of the consequences of cyber incidents which took place during the last year has revealed. The figure was published in the 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, and based on source material from breaches experienced by 602 organizations around the world between March 2025 and February 2026. According to IBM, the global average breach cost climbed 12% during the last year, reaching a...
-
Post #4174980
Suddenly found myself with an urge to revist Half-Life...
-
Post #4063405
A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting routers used to provide public Wi-Fi to visitors to hotels, conference centers and other shared venues frequently visited by corporate employees. These compromised Wi-Fi gateways were id...
-
Post #4058204
Russian state-supported hackers are targeting organizations with a new attack technique using a Zero-Click method which doesnโt require users to interact with the phishing email. The campaign is designed to compromise networks and gain persistent access, a joint advisory from western cyber intelligence agencies including National Cyber Security Centre has warned. โThis phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursui...
-
Post #3985245
Want to read about how the Ferrari Formula 1 team deals with evolving cyber threats? Well, in this interview with Luca Pierro, Head of Enterprise Cybersecurity at Ferrari, you can! (Write-up by me) https://www.infosecurity-magazine.com/interviews/interview-ferrari-head-of/ #infosec #F1
-
Post #3884307
The Gentlemen have usurped Qilin as the most prolific ransomware gang of recent times, according to analysis of incidents which can be attributed to known ransomware threat groups (Write up by me. Picture, alas not in article...) https://www.infosecurity-magazine.com/news/the-gentlemen-most-prolific/ #infosecurity #ransomware
-
Post #3834153
I, for one, think it's a damning indictment on how the cybercriminal industry so rarely meets even the lowest levels of gender diversity quotas that seeing a wanted poster for female hacker is still quite surprising. smh. https://therecord.media/us-unseals-indictment-russians-bulletproof-hosting #cybersecurity #cybercrime
-
Post #816407
Big thanks to SDxCentral for commissioning two features from me for their new Cybersecurity Supplement! In the first piece - ๐ญ๐ฒ๐ฟ๐ผ ๐ง๐ฟ๐๐๐: ๐๐ฟ๐ผ๐บ ๐๐๐๐๐๐ผ๐ฟ๐ฑ ๐๐ผ ๐๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ - I examine the current status of Zero Trust and why even many of those organizations which are implementing it are yet to roll it out across their entire network. In the second piece - ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฎ๐ ๐ ๐ฎ๐ฐ๐ต๐ถ๐ป๐ฒ ๐ฆ๐ฝ๐ฒ๐ฒ๐ฑ - I take a look at the advantages and challenges around using agentic AI in the SOC to defend networks against ever-e...
-
Post #816406
This data breach is from before 2021, but I can&#39;t help but wonder what happens the next time there&#39;s inevitably some sort of breach and it involves people&#39;s identifiable information because government legislation means you need to verify your identity to access these sites now... https://www.theguardian.com/technology/2025/dec/17/hackers-access-pornhub-premium-users-viewing-habits-and-search-history
-
Post #816405
Well chuffed that @gcluley invited me back to guest on Smashing Security. Come for our discussion about research from Black Hat Europe, stay for me yammering on about playing Tomb Raider Remastered and what makes it different to the original I played as a kid back in the 90s - most important for me being, that unlike the original, this version didn&#39;t just crash to a black screen of death in the middle. Very serious business. https://open.spotify.com/episode/3JQ4Ul21LNU2W9kzxQN4xp?si=ef...
-
Post #816404
Well, I suppose it&#39;s time for one of those posts looking back at the working year, isn&#39;t it? Put simply, did I expect 2025 to be the year I went freelance? In all honesty, probably not, but circumstances pushed me down that path. (I got laid off by the company I worked for not long after they were bought by a private equity firm...) But, I think even though I&#39;m really still making my first tentative steps at making things work for myself and as my own, for want of a be...
-
Post #816403
A new Cyber Unit to coordinate responses to cyber threats across the public sector and an ambassador scheme to help encourage secure software development have been announced as part of the UK governmentโs new Cyber Action plan. While the plan has broadly been welcomed by cybersecurity leaders โ although there concerns that the budget of ยฃ210m isnโt enough to have a significant impact. (Also, I&#39;m Deputy Editor of Infosecurity Magazine now...) https://www.infosecurity-magazine.com/news/...
-
Post #816402
The rising use of generative AI tools like LLMs in the workplace is increasing the risk of cyber-security violations as organizations struggle to keep tabs on how employees are using them - especially if they&#39;re using their personal accounts. (By me) https://www.infosecurity-magazine.com/news/personal-llm-accounts-drive-shadow/ #cybersecurity #AI
-
Post #816401
A surge in phishing attacks which exploit email routing settings and misconfigured domain spoofing protections to spoof domains and make malicious emails appear as if they were sent from within the organization are targeting Microsoft 365 accounts. Microsoft Threat Intelligence has warned that the attacks are themed around phoney messages from HR departments and IT security teams and are being deployed in attempts to steal login credentials. While the attack vector isnโt new, Microsoft said th...
-
Post #816400
Phishing attacks and cyber fraud have overtaken ransomware as the top cybersecurity concern of business leaders, according to the World Economic Forumโs Global Cybersecurity Outlook for 2026. ๐ โAs cyber risks become more interconnected and consequential, cyber-enabled fraud has emerged as one of the most disruptive forces in the digital economy, undermining trust, distorting markets and directly affecting peopleโs lives,โ said Jeremy Jurgens, managing director, World Economic Forum. (Write-up...
-
Post #816399
A quick one from me on what Trellix describes as surge in browser-in-the-browser attacks to steal Facebook passwords. No, I&#39;m not quite sure why one of the phishing lures claims that YOU have infringed copyright by sharing the music of *checks paper* Lewis Capaldi either. https://www.infosecurity-magazine.com/news/phishing-scams-exploit-browser/ #cybersecurity
-
Post #816398
The Microsoft Digital Crimes Unit has just announced the take down and seizure of infrastructure used by RedVDS, which has been used to conduct phishing and BEC attacks which have cost victims millions. One thing I find particularly interesting about this announcement is how Microsoft praises the victims of some of these campaigns for coming forward: therefore helping the investigation and disruption of the cybercriminal infrastructure. โTheir cooperation made this action possible and will hel...
-
Post #816397
Are cybercriminals shifting towards cutting out the middle-man in ransomware attacks? That is, why bother encrypting a whole network when you can just steal the data and demand payment from that alone? An increasing number of cybercriminals are relying on data theft alone to extort ransom payments out of victims, a new research paper by Symantec has warned. Analysis of data leak sites suggests that there were almost 1500 incidents that relied on data theft alone for extortion attacks in 2025....
-
Post #816396
So, about VoidLink, the sophisticated Linux malware which came to light last week. Researchers have spent more time examining it and they&#39;ve concluded that rather than being developed by a crack team of cyber criminals... it was developed largely by AI. (Helped along with prompts from one person.) &quot;VoidLink demonstrates that the long-awaited era of sophisticated AI-generated malware has likely begun,โ said the Check Point Software Research. โIn the hands of individual experi...
-
Post #816395
Analysis by Symantec and Carbon Black Threat Hunter Team has concluded that the cybercriminals behind PureRAT are using AI tools to write scripts and code. One of the reasons for this conclusion is that sections of the code powering PureRAT contain emojis. โMany AIs have a tendency to insert emojis in code comments because theyโve been trained using data from social platforms such as Reddit,โ researchers said. (Write-up by me for Infosecurity Magazine) https://www.infosecurity-magazine.com/ne...
-
Post #816394
The National Cyber Security Centre has issued an alert to critical national infrastructure providers, urging them to act now to protect against โsevereโ cyber threats. The alert comes following coordinated cyber-attacks which targeted Polandโs energy infrastructure with malware in December. Jonathon Ellison OBE has urged CNI operators that they must act now to ensure they can respond to any similar campaigns targeting the UK. โCyber-attacks disrupting everyday essential services may sound far...