Kevin Poireault @leekthehack.bsky.social · 08/10/2026A critical vulnerability affecting eight @atlassian.bsky.social products is reportedly being exploited in the wild. www.infosecurity-magazine.com/news/critica... 000
Kevin Poireault @leekthehack.bsky.social · 08/10/2026🚨 UPDATE from ASOS: The UK fashion retailer emailed customers this morning, confirming the hack, stating that the threat actor had accessed personal and account data. However, the company confirmed that payment information was not compromised. 100
Kevin Poireault @leekthehack.bsky.social · 07/10/2026NEW: New findings from Group-IB show that the Telegram account linked to the alleged ASOS hack used to be active in a forum for gaming-item trading. www.infosecurity-magazine.com/news/telegra... 100
Kevin Poireault @leekthehack.bsky.social · 06/10/2026Red Hat’s open-source security initiative Lightwell has remediated over 400 novel vulnerabilities across foundational Java libraries since the projects launch in June. www.infosecurity-magazine.com/news/red-hat... 000
Kevin Poireault @leekthehack.bsky.social · 06/10/2026Today, customers of online fashion retailer ASOS received a strange mobile notification claiming the company has been hacked via a Snowflake compromise. Neither ASOS nor Snowflake have confirmed any compromise yet. www.infosecurity-magazine.com/news/asos-cu... 100
Kevin Poireault @leekthehack.bsky.social · 05/10/2026Google has suspended its open-source bug bounty program until 2027 in an effort to stem the flood of AI submissions. www.infosecurity-magazine.com/news/google-... 000
Kevin Poireault @leekthehack.bsky.social · 28/09/2026In the US, CISA is set to become a de facto enforcement agency, with new powers to compel organizations across critical infrastructure to report cyber incidents. www.infosecurity-magazine.com/news-feature... 000
Kevin Poireault @leekthehack.bsky.social · 04/09/2026The G7 is urging nations to accelerate the post-quantum cryptography transition. Two key priorities for governments: developing national strategies on transitioning to PQC and integrating PQC into cybersecurity requirements. www.infosecurity-magazine.com/news/g7-urge... 000
Kevin Poireault @leekthehack.bsky.social · 02/09/2026As AI finds vulnerabilities faster than ever, who will help open-source maintainers keep up? I explored the major new initiatives tackling this challenge in my latest article. www.infosecurity-magazine.com/news-feature... 010
Kevin Poireault @leekthehack.bsky.social · 26/08/2026You don't just want an AI agent to say: "Don't worry, I followed all the rules." You want proof of what they actually did. @linuxfoundation.org has introduced TRACE, a new open standard acting as a tamper-resistant receipt for an AI agent's activity. www.infosecurity-magazine.com/news/linux-f... 000
Kevin Poireault @leekthehack.bsky.social · 20/08/2026NEW: The Pentagon paused third-party audit mandates for US defense contractors. Now these contractors say they can’t trust their own cybersecurity scores. www.infosecurity-magazine.com/news/us-defe... 000
Kevin Poireault @leekthehack.bsky.social · 19/08/2026NEW: Akrites, an industry initiative hosted by @linuxfoundation.org and set up to defend critical open-source software against AI-enabled cyber threats, is expected to operationalize its vulnerability disclosure and remediation platform in September. www.infosecurity-magazine.com/news/linux-f... 000
Kevin Poireault @leekthehack.bsky.social · 14/08/2026Security researchers from Symantec and Carbon Black have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns. www.infosecurity-magazine.com/news/researc... 000
Kevin Poireault @leekthehack.bsky.social · 10/08/2026How quickly are countries moving toward post-quantum cryptography? 🌐🔐 This table provides a country-by-country overview of key PQC migration timelines and shows why organizations need to start preparing now. More in my Infosecurity Magazine feature: www.infosecurity-magazine.com/news-feature... 000
Kevin Poireault @leekthehack.bsky.social · 29/07/2026Just 1.3% of AI-discovered vulnerabilities in 2026 have been exploited in the wild - roughly matching the overall exploitation rate of all vulnerabilities, a new @vulncheck.bsky.social report found. www.infosecurity-magazine.com/news/one-per... 000
Kevin Poireault @leekthehack.bsky.social · 28/07/2026NEW: Microsoft goes big on AI security: unveiled Project Perception (agentic Red/Blue/Green defense system), MAI-Cyber-1-Flash, its first cyber-focused AI model and the new FORGE Lab led by DARPA AIxCC winners Team Atlanta. www.infosecurity-magazine.com/news/microso... 000
Kevin Poireault @leekthehack.bsky.social · 28/07/2026Cybersecurity industry body CREST has added additional standards to accredit AI penetration testing services. www.infosecurity-magazine.com/news/crest-a... 000
Kevin Poireault @leekthehack.bsky.social · 20/07/2026NEW: Adam Kues from Searchlight Cyber has used OpenAI’s GPT5.6 Sol Ultra to successfully develop a full exploit chain for two critical WordPress Core vulnerabilities. www.infosecurity-magazine.com/news/researc... 000
Kevin Poireault @leekthehack.bsky.social · 20/07/2026Following the sentencing of two young men for the 2024 Transport for London hack, senior police officers have said the case makes a compelling argument for tougher legal powers in the UK, namely Cybercrime Risk Orders. www.infosecurity-magazine.com/news/police-... 000
Kevin Poireault @leekthehack.bsky.social · 16/07/2026Two young men have been sentenced to five years and six months in prison each for the 2024 cyber-attack against Transport for London after the judge found their actions were motivated in part by “selfish bravado” rather than purely financial gain. www.infosecurity-magazine.com/news/selfish... 000
Kevin Poireault @leekthehack.bsky.social · 09/07/2026A new global anti-fraud operation against cybercrime, dubbed Operation First Light, has led to the arrest of over 5800 people and the interception of almost $300m in illicit assets. @interpol.int www.infosecurity-magazine.com/news/china-i... 000
Kevin Poireault @leekthehack.bsky.social · 09/07/2026NEW: Over 70 cybersecurity organizations have signed the CREST AI Charter, vowing a responsible use of AI for cybersecurity purposes. www.infosecurity-magazine.com/news/crest-a... 000
Kevin Poireault @leekthehack.bsky.social · 08/07/2026NEW: A new cyber-attack targets consumers and SMEs worldwide to steal sensitive cryptocurrency data with the Vidar infostealer and mine Monero, a decentralized cryptocurrency focused on private, untraceable transactions. www.infosecurity-magazine.com/news/new-cam... 000
Kevin Poireault @leekthehack.bsky.social · 07/07/2026INTERVIEW: In his very first interview since assuming the role of Google Cloud's CISO, Chris Betz shared his vision on the role generative AI will play in defending global enterprises. www.infosecurity-magazine.com/interviews/g... 000
Kevin Poireault @leekthehack.bsky.social · 02/07/2026EXCLUSIVE: I spoke with the pseudonymous researcher who dumped over 30 proof-of-concept exploits (the ‘Exploitarium' repo on @github.com) without disclosing the vulnerabilities first. www.infosecurity-magazine.com/news/researc... 000
Kevin Poireault @leekthehack.bsky.social · 01/07/2026Anthropic’s latest frontier LLMs, Claude Mythos 5 and Claude Fable 5, are available again – but with added security limitations. www.infosecurity-magazine.com/news/anthrop... 000
Kevin Poireault @leekthehack.bsky.social · 24/06/2026NEW: Two infamous infostealers, StealC and Amadey, have been taken down by Operation Endgame, an international law enforcement effort. @europol.europa.eu @microsoft.com www.infosecurity-magazine.com/news/operati... 000
Kevin Poireault @leekthehack.bsky.social · 23/06/2026US federal agencies will have to complete their post-quantum cryptography migration by 2030 or 2031 at the latest depending on use cases. www.infosecurity-magazine.com/news/trump-e... 000
Kevin Poireault @leekthehack.bsky.social · 18/06/202675% of cyber incidents affecting UK critical infrastructure organizations over the past year originated from hostile states such as Russia, China and Iran, said Richard Horne, CEO of @ncsc.gov.uk at a @rusi.bsky.social event. www.infosecurity-magazine.com/news/hostile... 000
Kevin Poireault @leekthehack.bsky.social · 17/06/2026Ukraine is now part of the EU Cybersecurity Reserve 🇺🇦🇪🇺 The Ukrainian government can now activate emergency EU cyber support to respond to large-scale cyber-attacks and cyber incidents affecting its organizations and businesses. www.infosecurity-magazine.com/news/ukraine... 000
Kevin Poireault @leekthehack.bsky.social · 01/06/2026NEW: @owasp.org org to launch Agentic Research Council at Infosecurity Europe 2026 to bridge AI security research gaps. Announcement: June 4. www.infosecurity-magazine.com/news/owasp-n... 030
Kevin Poireault @leekthehack.bsky.social · 19/05/2026NEW: @threatintel.microsoft.com has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks. It is now working with the FBI and @europol.europa.eu to uncover the identity of people behind the group. www.infosecurity-magazine.com/news/microso... 020
Kevin Poireault @leekthehack.bsky.social · 18/05/2026NEW: @interpol.int has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa that led to 201 arrests. www.infosecurity-magazine.com/news/interpo... 000
Kevin Poireault @leekthehack.bsky.social · 30/04/2026NEW: UK government survey shows the British public education sector has faced a significant increase in cyber breaches over the past year, despite stable threat levels recorded in the UK. www.infosecurity-magazine.com/news/uk-educ... 000
Kevin Poireault @leekthehack.bsky.social · 21/04/2026In this new episode of the Infosecurity Magazine podcast, we speak with Allie Mellen, author of 𝐶𝑜𝑑𝑒 𝑊𝑎𝑟, about the rising threat of nation-state cyber operations 🇺🇸🇷🇺🇨🇳 www.infosecurity-magazine.com/podcasts/ins... 000
Kevin Poireault @leekthehack.bsky.social · 17/04/2026As Vulncon was coming to a close, I sat down with Chris Gibson, the CEO of FIRST, to talk about the state of vulnerability research, Anthropic's and OpenAI's new "cyber" models and the relief of seeing ENISA & CISA team up in the CVE program. www.infosecurity-magazine.com/interviews/f... 020
Kevin Poireault @leekthehack.bsky.social · 16/04/2026INTERVIEW - Walt Powell, Lead Field CISO at CDW, explains what one skill modern CISOs should prioritize: mastering risk quantification to secure the board buy-in and and budget needs. www.infosecurity-magazine.com/interviews/c... 000
Kevin Poireault @leekthehack.bsky.social · 16/04/2026Faced with an explosion of vulnerability reporting, NIST's NVD is taking a new risk-based approach to enriching CVEs. This implies bold moves, including the NVD dropping enrichment for all vulnerabilities reported before March 1, 2026. www.infosecurity-magazine.com/news/nvd-enr... 000
Kevin Poireault @leekthehack.bsky.social · 15/04/2026NEW - ENISA is strengthening its ties with US-funded @cveprogram.bsky.social. The European agency is being onboarded by CISA to become a Top-Level Root CVE Numbering Authority (TL-Root CNA). www.infosecurity-magazine.com/news/enisa-e... 010
Kevin Poireault @leekthehack.bsky.social · 15/04/2026NEW - AI companies like OpenAI and Anthropic should play a bigger role in software vulnerability disclosures and the CVE program in the future, according to CISA. @firstdotorg.bsky.social #VulnCon26 www.infosecurity-magazine.com/news/ai-comp... 272
Kevin Poireault @leekthehack.bsky.social · 09/04/2026Three high-profile journalists in Egypt and Lebanon have been targeted by a spear-phishing campaign likely tied to Bitter, a South Asian cyber espionage group also known as T-APT-17 and APT-C-08. www.infosecurity-magazine.com/news/middle-... 000
Kevin Poireault @leekthehack.bsky.social · 08/04/2026NEW - A large-scale network of internet routers compromised by Russian hacking group APT28 to harvest credentials from victims of intelligence value has been taken down in the US. @thejusticedept.govmirrors.com @threatintel.microsoft.com www.infosecurity-magazine.com/news/us-thwa... 000
Kevin Poireault @leekthehack.bsky.social · 07/04/2026‘Vibe coding’ is accelerating dev speeds, but it’s also opening new security backdoors 🚀💻 I spoke with experts from @aikidosecurity.bsky.social, Neural Trust and more for Infosecurity Magazine to break down how CISOs can secure AI-assisted engineering. www.infosecurity-magazine.com/news-feature... 120
Kevin Poireault @leekthehack.bsky.social · 30/03/2026🚨 A critical vulnerability in Citrix's NetScaler Application Delivery Controller (ADC) and NetScaler Gateway is being exploited in the wild, security researchers from watchTowr and Defused have confirmed. www.infosecurity-magazine.com 000
Kevin Poireault @leekthehack.bsky.social · 27/03/2026VulnWatch Friday: CVE-2026-32628 🔓 Aviral Srivastava has discovered a high-severity vulnerability in Mintplex Labs' AnythingLLM, an application that turns pieces of content into context that any LLM can use as references during chatting. 🔧 Fix: github.com/Mintplex-Lab... 000
Kevin Poireault @leekthehack.bsky.social · 27/03/2026The UK government has sanctioned Chinese-based company Xinbi, described as one of the largest illicit online cryptocurrency marketplaces as well a associated entities and individuals accused of links with scam compounds in Southeast Asia. www.infosecurity-magazine.com/news/uk-sanc... 000
Kevin Poireault @leekthehack.bsky.social · 26/03/2026𝐍𝐄𝐖 - Vibe coding tools are flooding software with new vulnerabilities, @georgiatechai.bsky.social researchers have warned. I spoke to Hanqing Zhao, founder of the Vibe Security Radar, about the future of AI coding tool-induced vulnerabilities. www.infosecurity-magazine.com/news/ai-gene... 030
Kevin Poireault @leekthehack.bsky.social · 26/03/2026𝐍𝐄𝐖 - OpenAI has launched a new Safety Bug Bounty program to encourage disclosures of issues in its products that pose “meaningful abuse and safety risks, even if they don’t meet the criteria for a security vulnerability.” @bugcrowd.com www.infosecurity-magazine.com/news/openai-... 000
Kevin Poireault @leekthehack.bsky.social · 25/03/2026The US Federal Communications Commission bans foreign-made internet routers over national security concerns. The ban means that all such routers made in foreign countries, not just a few select Chinese vendors, are now placed on the FCC’s covered list. www.infosecurity-magazine.com/news/us-fcc-... 000
Kevin Poireault @leekthehack.bsky.social · 24/03/2026At @rsaconference.bsky.social, the head of the @ncsc.gov.uk urged the cybersecurity industry to develop vibe coding safeguards. www.infosecurity-magazine.com/news/rsac-uk... 220