[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
Calling on Cyber Pros to Help Defend City Hall
N-able Bug Exposes Password Vault Master Keys
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
'Grandoreiro' Malware Resurfaces With Mexico Campaign
No-Filter 'Kriminal' AI Platform Raises Cybercrime Concerns
Agentic AI Presents New Insider Threat Model for Orgs
SilkParasite Threatens Central Asian Orgs With Flurry of RATs
China-Linked Hacker Shows AI Capabilities in APAC Attack
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
Ars Technica
Grok exfiltrates user data when malicious instructions are encrypted
Microsoft Copilot reveals secret input that allowed it to be hacked
Nvidia discloses $21B stake in SpaceX
Vulnerability giving attackers full control of Macs is under active exploitation
PBS station fears losing 50TB of data after being ghosted by cloud storage provider
OpenAI and Anthropic in price war as Chinese AI rivals gain ground
Private security firms will soon be allowed to hack overseas cybercriminals
Terabytes of credentials leaked in massive supply-chain attack
DEF CON crowd suspected in fake-hotspot attack on Delta flight
Chrome adopts what may be the best protection yet against account takeovers
CyberScoop
Retail theft bill spurs ‘very large and very dangerous’ surveillance fears
The push to designate AI as the next critical infrastructure sector
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
A California county wants to hire Tina Peters to help run its elections
The long tail of Clop’s PTC hack is just beginning to emerge
Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
Details emerge on BlackFile’s recent attacks on financial companies
Irregular says ‘human oversight’ responsible for AI sandbox escape incidents
A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.
InfoSecurity Magazine
JFrog Artifactory Flaws Enable Software Supply Chain Attacks
NCSC Urges Stronger Controls for Agentic AI Systems
US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Def Con Attendees Targeted by Persistent Phishing Campaign
Exclusive: Linux Foundation's Akrites to Go Live in September
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
OpenAI Tightens AI Safeguards Following Hugging Face Incident
SecurityWeek
Hackers Target Zimbra Servers in Active Exploitation Campaign
Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
MLflow Vulnerability Exploited for Cloud Credential Theft
Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Critical GitLab Flaw Exploited Shortly After Disclosure
ZDNet
Apple's smart home springs a leak - here's everything we expect to see in September
Why replacing staff with AI backfires - and 5 ways smart leaders generate real value instead
Wispr Flow is better than your device's built-in voice text tool - how to try it for free
The LG C6 OLED TV is one of the most impressive TVs I've tested year - and it's on sale
Google will let you tailor your Discover feed using natural language now
Roborock Q7 M5+ review: A capable budget robot vacuum that nails the fundamentals
The Pixel Watch 5 could help me lift heavy - and replace my top strength training app
The best and worst AI for your privacy, ranked - and how each handles your data
Yes, you can change your Messages backgrounds on iPhone - but there's a catch
You can earn your Google Al Professional Certificate for free - and I highly recommend it
The Hacker News
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Why "Shady AI" is Security's Next Big Governance Problem
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
BleepingComputer
Hackers poison arrayref Rust crate to push infostealer malware
Critical Elementor Pro bug exposes WordPress sites to RCE attacks
How MSPs can catch phishing attacks email filters miss
Citrix urges admins to patch new NetScaler flaws as soon as possible
CISA warns of hackers exploiting critical MLflow vulnerability
New Manic Android malware can exfiltrate data through nearby devices
Critical Zimbra RCE flaw now actively exploited in attacks
Microsoft says August Windows updates may cause gaming issues
OpenAI confirms ChatGPT is down as logins and signups fail
Rogue ransomware affiliate poses as recovery firm to steal payments
gbhackers
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments
OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Cybersecurity Dive
Fitch explains how water, healthcare organizations can keep strong credit ratings, despite cyberattacks
AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn
Ransomware disproportionately targets medium-sized firms, straining customer relationships
DOJ charges 17 people in Iran-backed hacking campaign against US
GitLab issues emergency patch for critical code-injection flaw
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
Critical flaw in SAP Commerce Cloud faces initial exploitation attempts
Major genetic-testing firm says hack compromised sensitive patient data
Why more security data has blurred companies’ view of risk
Researchers confirm breach claims by data-extortion group
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
Researcher tricks Apple’s Find My into sharing location data with Linux
Ransomware crook poses as recovery firm to steal payments from fellow extortionists
Grok chat duped into swallowing injected instructions
French tax authority says break-in exposed data of 600K, including some private messages
AI agent suggested installing a malware package. Engineer almost took its advice
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
ICE boss to agents: Leave the Meta spy glasses at home
Flock surveillance backlash mounts as fiendish Halloween plans circulate
Comcast gives its Wi-Fi motion detector a security makeover
VentureBeat
Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn't tell users what they'd done
Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks
AWS Continuum integrates with OpenAI Codex and Anthropic Claude Code in major AI security push
AI agents are part of your team now. Here’s how to secure all of them.
The browser is where attacks land. Why is security still focused on the endpoint?
Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what enterprises should know
TechCrunch
AI data giant Alation confirms cyberattack
US says hackers are targeting vulnerable water systems with the help of AI
Researchers say OpenAI revoked their access to limited cyber program
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
CareCloud confirms 3.7M patients had their medical records stolen in data breach
OpenAI institutes new safeguards after Hugging Face breach
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
Bluesky says its recent outage was caused by another DDoS attack
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
Network World Security
Cerebras reimagines AI cluster design with switchless CS-4 architecture
IBM moves closer to fault-tolerant quantum computing with modular cryogenic systems
Reports: Google partnering with AMD for next-gen hybrid TPU
Why 6 GHz Wi-Fi will make or break the modern enterprise
Is your networking built for AI’s traffic patterns and data volumes?
IBM partners with OpenAI to drive enterprise AI deployment
It’s final! Judge says HPE’s Juniper acquisition is complete
Google, Microsoft and Nvidia back 800V DC standard for AI data centers
Five takeaways from Cisco’s Q4 and what they mean for IT pros
Cisco rides ‘networking supercycle’ for strong Q4
Help Net Security
Corero brings cloud-based AI threat analysis to SmartWall ONE
AWS limits AI agents’ data access, even when manipulated
Fake Gemini installer delivers Vidar infostealer via Google Colab lure
OpenAI previews privacy-focused system for detecting AI misuse
US agencies warn of AI-powered attacks on Siemens industrial controllers
Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation
US charges 17 Iranian hackers over 31-terabyte academic data theft
AI is making fraud harder to spot and identity harder to prove
Researchers find a loophole that lets expired credit cards make unauthorized payments
8,539 reasons to rethink how vulnerabilities get patched
SC Magazine
Unspecified actors making AI-assisted attacks on critical infrastructure
Inside the fourth wave of the Shai-Hulud npm worm
Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure
A ‘kill switch’ law only makes sense for a worst-case scenario
The CISO Doesn't Own the Outcome: A Shared-Accountability Model for Security Decisions
Medusa ransomware group attacked more than 500 victims since 2021
Perspective and lessons learned from mergers and acquisitions
Geekom admits malware found in legacy mini PC driver download
Microsoft removes WMIC tool from Windows 11
Critical vulnerability in Ray framework allows remote code execution
© 2026 RiskDiscovery | Sponsored by:
Deception Logic