[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
ClickFix Attacks Evolve to Better Hide Malicious Payloads
Critical Healthcare Systems Aren't Quantum-Ready
Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
Need for Speed: AI-Driven Attacks Are Changing Security Strategies
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
Ars Technica
Hackers obtain counterfeit TLS certificates for Google and other large services
OpenAI agents tried to hack Wikipedia tools and flooded it with traffic
Licensing costs driving 90 percent of VMware users to explore options: Survey
MCP for agent-to-agent comms may be the riskiest protocol you've never heard of
Apple changes full-disk access permissions to curb abuse from AI agents
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
Memory executives expect RAM shortage to continue through 2028
Attackers have been exploiting critical Zimbra flaw to steal emails
Cloudflare plans to issue quantum-safe TLS certificates
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
CyberScoop
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
Wiretapping change sparks big privacy fight in the Golden State
Former NSA chief Nakasone says agency overhaul is ‘probably needed’
Here’s how experts think CISA should tell agencies to protect OT
Citrix discloses third actively exploited NetScaler zero-day in less than a week
The US needs a real plan to defend its water systems
The legal questions raised by agentic AI hacks
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
AI policy circles targeted in China-linked phishing operation
InfoSecurity Magazine
ClickFix Attack Hides VBScript Payload in Browser Cache
Nikkei Discloses Two Employee Cloud Account Compromises
Red Hat’s Lightwell Project Remediates 400 Open-Source Vulnerabilities
Critical Medical Devices Unable to Support PQC Transition
ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
Police Urge Passkey Use After Surge in Cybercrime Profits
Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
ClingSTUN Malware Turns Unpatched IoT Devices Into Proxy Nodes
New Stealthy Linux Backdoors Target Telecoms, Masquerade as Email Traffic
Citrix NetScaler Targeted Via New Zero Day
SecurityWeek
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
8.8 Million Impacted by Data Breach at Denmark’s Central Person Register
Social Engineering Detection Moves Into the Live Conversation
Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
ZDNet
Use Gemini for free? You’ll soon be limited to its weakest AI model
Office 2021 support ends this month – you have 5 options
Mistral’s new Le Chonk model brings AI cybersecurity to your business – and you control it
How I made a paid Mac app in 11 days with Claude – without writing a single line of code
iPhone 18 Pro Max can’t call or text on AT&T? Apple will replace it for free
This new ChatGPT scam tricks you into installing malware – how to spot the trap
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
openSUSE Leap adds a new security layer: Immutable mode
Your iPhone just got a hidden anti-scam upgrade in iOS 27: How to enable it
The Hacker News
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
BleepingComputer
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
Atlassian warns of critical file-access flaw in Jira, Confluence
ASOS confirms data breach after “HACKED” in-app notifications
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
How to secure RMM software: 8 controls MSPs should test
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Engineer sentenced for locking over 3,000 devices on employer network
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
gbhackers
Aembit Extends Access Controls to Personal AI Agents
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
AppViewX Adds Shadow AI Visibility and a Runtime Kill Switch to Agent Identity Security
Hackers Pose as Dubai Airports Recruiters to Infect Software Engineers With ShelbyLoader V2
Gentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks
Meta and Microsoft Reduce Internal Use of Claude AI
Accenture Contractor Removed After FBI Data Breach Exposes Thousands of Employees
OT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes
Cling Botnet Spoofs Google STUN Traffic to Hide Commands Sent to Infected IoT Devices
Android 17 Advanced Protection Adds Intrusion Logging, USB Security and Brute-Force Defense
Cybersecurity Dive
IBM’s AI-powered vulnerability clearinghouse finds hundreds of Java flaws
US cyber resilience, oversight tested in series of attacks
Citrix issues patch for third exploited flaw in NetScaler
White House AI task force faces expertise, partnership challenges
Modernizing data security with DSPM, AI and fewer tools
Why permissions must be the foundation for next-gen identity security
Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Fortinet warns that critical flaw in FortiMail is facing exploitation
SOC staffers generally pleased with AI’s impact, but worries remain
State-linked actor targets US AI policy experts in credential phishing campaigns
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Trump Mobile customers' data dumped - and some never even received their gold device
Microsoft extends the Outlook naughty step with two more file types
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
Asos app delivers a data leak threat instead of fast fashion
Denmark's ID register spills more people's details than the country has residents
Legacy sign-on service comes back to bite school software provider Bromcom
Atlassian warns of critical file access flaw in its datacenter products
Security researcher claims they found KVM guest-host escape flaw
Citrix NetScaler security snafus get even worse amid more 0-day reports
FBI confirms 'multiple' arrests related to ShinyHunters hack
VentureBeat
Microsoft's record Patch Tuesday shows why severity can't decide what gets patched first
Your vibe-coded apps are a ticking time bomb for your business. Here’s how to secure them.
AI agents need more than access control — they need identity at runtime
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
OpenAI’s new ‘Private Intelligence' targets a growing enterprise concern: who can see your AI data?
Anthropic documented a new problem for security teams: Attacks that can adapt while they're underway
The defender's head start is gone. Cisco's Liz Centoni on the fight to get it back
TechCrunch
LibreOffice says ‘no AI’ is now a software feature
Hackers steal 8 million citizens’ records from Danish government database
Google froze its open source bug bounty program due to a ‘significant rise’ in AI submissions
Federal judge calls Flock ‘indiscriminate mass surveillance’
OpenAI safety employee resigns, claiming the company’s ‘culture is broken’
Apple says it’s tightening macOS ‘Full Disk Access’ controls due to new risks from AI agents
Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
OpenAI cuts ties with 3 safety researchers, WSJ reports
California governor vetoes bill banning use of ‘pervert glasses’ to secretly record people
Network World Security
Cisco readies new control plane for quantum networks
Google overhauls cloud modernization portfolio with new AI agents
GTT bets that the network, not the log file, is where AI-era security gets won
Micro data center company launches stackable data center for edge and AI
AWS seeks to automate cloud optimization with new AI agent
IBM expands mainframe networking options as AI reshapes enterprise infrastructure
New memory player CXMT begins mass production of DRAM platform
From automated response to reasoning: Building confidence in AI-driven NetOps
Startup doxx.net hands the network controls to AI
IBM’s Bob wants to move in: Agent available for on-prem deployment
Help Net Security
Anaconda combines agent swarms with autonomous security testing
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
AppViewX targets shadow AI risks with agent discovery and runtime enforcement
New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI
SailPoint adds AI agent discovery, temporary access and compliance automation
Intellias Agentic ServiceOps applies governed AI across IT operations
AXON Datum enforces data access policies before AI systems act
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Ontinue extends ION MXDR with managed dark web monitoring
SC Magazine
Changing the game: How AI forces organizations to revisit assumptions about recovery and resilience
Typing, textGrain, NetScaler, Fortinet, Copilot, LibreOffice, Dots, Aaran Leyland - SWN #622
Critical Atlassian flaw exposes files across eight products
Financial phishing campaigns exploit fragmented hosting, AI tools
Phishing scam targets tourists applying for Schengen visas
MCP fixed secret handling. URL elicitation moved the phishing risk into the browser
Vermont embraces AI as a 'power tool' for state employees
AI model Mythos aids discovery of critical Rejetto HFS vulnerability
Tenfold Community Edition adds new features for small organizations
Why it will take strong public-private partnerships to fight AI-based threats
© 2026 RiskDiscovery | Sponsored by:
Deception Logic