InfoSec News Nuggets 12/04/2025

Fintech firm Marquis notifies affected business after ransomware breach Texas based fintech firm Marquis is notifying U.S. banks and credit unions after a ransomware attack in August allowed an intruder to exploit a SonicWall firewall vulnerability and access internal files. Regulatory filings say the exposed data may include names, contact details, dates of birth, Social Security and taxpayer IDs, and limited financial account information belonging to customers of Marquis’ clients. The company is now sending…
Read More

InfoSec News Nuggets 10/14/2025

JPMorgan to Invest up to $10 Billion in US Companies with Crucial Ties to National Security The investment plan revealed Monday will focus on four areas: supply chain and advanced manufacturing in critical minerals, pharmaceutical precursors and robotics; defense and aerospace; energy independence, with investments in battery storage and grid resilience; and strategic technologies, including artificial intelligence, cybersecurity and quantum computing. The investment is part of the bank’s Security and Resiliency Initiative, a $1.5 trillion, 10-year…
Read More

InfoSec News Nuggets 1/23/2025

The Internet is (once again) awash with IoT botnets delivering record DDoSes We’re only three weeks into 2025, and it’s already shaping up to be the year of Internet of Things-driven DDoSes. Reports are rolling in of threat actors infecting thousands of home and office routers, web cameras, and other Internet-connected devices. Here is a sampling of research released since the first of the year. A post on Tuesday from content-delivery network Cloudflare reported on a recent…
Read More

InfoSec News Nuggets 2/28/2024

Most Commercial Code Contains High-Risk Open Source Bugs Three-quarters (74%) of commercial codebases contain open source components featuring “high-risk” vulnerabilities, according to a new study from Synopsys. The chip design tool company’s ninth annual Open Source Security and Risk Analysis (OSSRA) report analyzed anonymized findings from over 1000 commercial codebase audits in 17 industries. It found that the share featuring high-risk open source bugs – that is, ones that have been actively exploited, have documented proof-of-concept exploits or are…
Read More

InfoSec News Nuggets 04/12/2023

Did someone really hack into the Oldsmar, Florida, water treatment plant? New details suggest maybe not.  It was the kind of doomsday scenario cybersecurity experts had been warning about for years: hackers infiltrate a small water utility and try to poison the local population. And that’s exactly what appeared to happen in February 2021 in Oldsmar, Florida. News of hackers remotely tampering with levels of lye at the local water treatment facility alarmed officials, shocked the…
Read More

InfoSec News Nuggets 09/20/2022

Eyeglass Reflections Can Leak Information During Video Calls A group of academic researchers have devised a method of reconstructing text exposed via participants’ eyeglasses and other reflective objects during video conferences. Zoom and other video conferencing tools, which have been widely adopted over the past couple of years as a result of the Covid-19 pandemic, may be used by attackers to leak information unintentionally reflected in objects such as eyeglasses, the researchers say. “Using mathematical…
Read More