[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
Why AI Is So Good at Scamming Humans
AI Governance Can't Wait
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
Indonesia Hit by Android Banking App-Cloning Campaign
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
Ars Technica
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
Why this month's Microsoft patch release is a doozy
OpenAI agents discussed ways to escape their sandbox on public wiki
“Trust, not features, is the real deficit”: VMware tries to appease SMBs
Once popular for attacking AI, ASCII smuggling is embraced by spammers
Confused about which VPN is right, US senator asks the NSA for guidance
VMware migration reduces Tottenham Hotspur's licensing fees by 85 percent
I rented a car, and within hours, my driver's license was for sale
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
CyberScoop
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
GitLab’s critical flaw is already drawing internet-wide probes
Conti ransomware crew member sentenced to four years in prison
Hawley probes OpenAI over Hugging Face breach
AI lets small actors run state-level hacking campaigns, Anthropic report finds
Governments ‘buying time’ in race between innovation, security, national cyber director says
Chinese espionage groups swarm to exploit triple-link chain of zero-days
FTC rescinds policy statement requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
InfoSecurity Magazine
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
CISA Updates Insider Threat Guide With New Mitigation Advice
MantaxOtax Android Malware Combines Ransomware With Spyware
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Anthropic Reveals Yet Another Cybersecurity Incident
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
Gigabud Uses Android App Cloning to Evade Fraud Detection
ClickFix Moves into the Browser to Steal Cryptocurrency
SecurityWeek
Phishing Research Challenges Conventional Security Awareness Testing
GitLab Vulnerability Exploited One Day After Disclosure
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Check Point Patches Critical VPN Vulnerabilities
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Surfshark Systems Targeted by Hackers
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
PaperCut Flaws Exploited in AI-Powered Attacks
ZDNet
The Hacker News
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
BleepingComputer
Hackers abused Claude to extract secrets from 1.8M Android apps
Florida confirms DMV database breached via stolen police account
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Artifactory flaws chained in attacks deploying backdoor malware
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
GitLab urges users to patch max severity path traversal flaw
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Conti ransomware gang member sentenced to 4 years in prison
New Android malware encrypts files, steals data, and harasses victims
gbhackers
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages
Cybersecurity Dive
State authorities warn they lack resources to address cyber threat to critical sectors
Accountability, oversight and AI: Inside Microsoft’s security transformation
Threat groups enhance cyberattack capabilities with AI
White House sees water cybersecurity partnership in Texas as national blueprint
CISA is on the verge of filling hundreds of critical vacancies
How AI anxieties dominated the summer’s big cybersecurity conference
CISOs are feeling the security burden of accelerated AI use
New FBI cyber strategy promises increase in adversary disruptions
N-able issues patch for zero-day flaw
Don’t let AI distract from cybersecurity basics, officials and executives warn
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
More JFrog Artifactory bugs under attack, and all 3 have patches
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research
Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
ShinyHunters expose 6.4M in attack on medical supplier McKesson
Dental contractor set up secret account with access to 4,000 patient records then left the company
Anthropic reveals fourth likely crime committed by its AI
Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits
VentureBeat
Security vendors use AI to rank Patch Tuesday CVEs — and rarely tell customers
Anthropic's safety monitor missed a live cyberattack because Mythos 5's reasoning said everything was fine
Agents identifying as OpenAI systems wrote 17,000 posts to a wiki no one was supposed to write to
Most security teams don't know how many AI agents they're running. Falcon Guardian found 18,000 at one company that had approved only 300.
MCP's new spec turns a planted prompt into a stolen credential
China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using
Google’s Gemini 3.8 Flash is built for agents, while its Cyber twin hunts vulnerabilities
TechCrunch
Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AI
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms
Sequoia doubles down on Cymphony as AI agents create new enterprise security risks
Chrome is now shipping updates every 2 weeks as AI changes the security landscape
A hacker stole $340M in a crypto heist, then returned most of it
OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure
US military disabled ad tracking on troops’ devices following reports of targeted attacks
Abliteration.ai is making a business out of removing AI guardrails
Network World Security
Broadcom hampers VMware migration by blocking downloads of key SDK
Nvidia will use Palantir to gain insight its supply chain
The race to 1.6T: Ethernet and coherent optics tackle AI’s bandwidth crunch
Network complexity is outpacing NetOps teams: How AI can help
Nvidia invests $3.5B in MediaTek to extend its grip on AI
MikroTik patches flaws currently being exploited to take over routers
Leap second proposal will keep software stacks in sync
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
BackBox brings AI to network automation but keeps humans in control
2026 network outage report and internet health check
Help Net Security
AI agents exploited PaperCut flaws to breach 395 organizations
IDScan confirms breach after 153 million driver’s licenses leak on dark web
Kiteworks expands runtime data governance with Bonfy.AI acquisition
Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Getting a stranger’s phone kicked off the cellular network costs a few dollars
Building a ransomware decision tree before the call comes in
Companies may be measuring phishing resilience the wrong way
AI is changing what Salesforce security needs to govern
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
New infosec products of the week: September 11, 2026
SC Magazine
Max severity GitLab path traversal flaw under active reconnaissance
9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615
Check Point patches two critical VPN gateway bugs
Dead drops in public: What the AI agent stashed on Hugging Face
Anthropic finds 4th real-world attack by Claude agent, details models’ ‘biased reasoning’
AI governance needs to become part of the CISO’s GRC program
Ping YOUniverse: How to classify and manage AI agents
How coding agents are changing application risk
It's More Secure When It's Disabled - PSW #943
When English becomes exploit code: The hidden risk inside MCP servers
© 2026 RiskDiscovery | Sponsored by:
Deception Logic