[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
DarkReading
[Virtual Event] Cybersecurity Outlook 2027
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
SectopRAT Returns, Hiding Inside a Legitimate Application
3 Cyber Threats That Defined the Summer of 2026
How to Build A SASE Framework for Modern Cybersecurity
Ghost Service Accounts Enable M365 Data Theft in Chile
Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
SASE Converges Network & Security Into One Cloud Solution
EDR Evasion Stack Helps Process Injection Slip Past Defenses
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Ars Technica
There's a new way to break RSA that's faster than anything we've seen before
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
IT mistake erases 11 years of viewing history for hospitals’ maternity records
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
LLMs respond differently to harmful prompts when AI watermarking is used
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
AI bots "Timmy," "Ren," and "Jackie" are flooding social media with slop
ClickFix attacks infecting PCs and Macs are going viral
Four groups caught using the same Chrome and Windows exploit kit
CyberScoop
New bill would create federal investigative body for AI-driven hacks
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
How tax policy can stop threat actors from breaching US water systems
CISA outlines improvement plan for CVE program
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Pentagon cyber chief: The demand far exceeds supply
Ryuk ransomware operator sentenced to 2 years in prison
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
The president has called for AI leadership. Here’s the mission.
InfoSecurity Magazine
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
CISA Charts New "Quality Era" for Global CVE Program
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
OpenAI Agent Hacks Australian Medicare Portal
Over 75% of Organizations Experience Microsoft 365 Governance Issues
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds
Hundreds of Leaked GitHub App Keys Still Authenticate
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Ransomware Attacks Reach Record High for 2026
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
SecurityWeek
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
AI-Powered Campaign Targets Hundreds of Online Retailers
Island Raises $400 Million at $6.4 Billion Valuation
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
Begin at the End: How to Enable Agentic Remediation
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Astrana Health Data Breach Impacts Private, Confidential Information
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
ZDNet
Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it
AI agent kill switch urged by Okta-led alliance – how businesses could make it work
Is your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
How to fix your Windows File History if the September update broke it
Nearly 70% of workers use AI regularly now – but many get no time to upskill
Claude Opus 5.5 delivers Fable 5.1 performance – and costs 40% less
Claim up to $95 today from Apple’s Siri AI settlement – here’s how
The AI models that cheat the most, according to new CAIS benchmark
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
The Hacker News
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
BleepingComputer
MacSync malware uses public iCloud calendars to deliver new payloads
New Carbonato malware uses AI agents to hijack exposed Docker hosts
Exposed GitLab project email addresses let attackers push code
FedRAMP VDR & VER: Daily Scans Are Only the Beginning
Hackers now exploit critical Roundcube flaw in code injection attacks
Windows 11 KB5124010 update released with 46 changes and fixes
CISA: Ransomware gangs now exploiting critical TeamCity flaw
OpenAI hacked Australian Medicare govt site, probed data providers
Microsoft fixes bug that broke Windows File History backup feature
Placeholder domain used in dev docs now serves ClickFix attacks
gbhackers
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
Cybersecurity Dive
Wiz uses AI to find vulnerabilities in railroads, hospitals and other critical infrastructure
FBI probes cyberattack tied to third-party jobs portal
Businesses fear cyberattacks more than anything else, driven by AI and supply chain worries
Industrial leaders face cyber resilience gap as attacks shake confidence
Insurance sector begins to offer clarity on AI-related cyber claims
Retailers tamp down shadow AI but struggle to oversee agentic sprawl
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Google AI models broke out of sandbox, hacked three companies
More CVEs than ever. The same old ones keep getting exploited.
Security’s 30-year habit: layering around the problem
Threatpost
Student Loan Breach Exposes 2.5M Records
Watering Hole Attacks Push ScanBox Keylogger
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Ransomware Attacks are on the Rise
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Twitter Whistleblower Complaint: The TL;DR Version
Firewall Bug Under Active Attack Triggers CISA Warning
Fake Reservation Links Prey on Weary Travelers
iPhone Users Urged to Update to Patch 2 Zero-Days
Google Patches Chrome’s Fifth Zero-Day of the Year
The Register
Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
Decades-old file security flaws found in Android, Linux, macOS, and Windows
CVE flood pushes Ubuntu onto weekly kernel release cycle
Someone went shopping in ASUS's eShop – for customer data
Google to critical infra orgs: Our AI scanners won't be evil, promise
Government contractor exposed path to immigration records
OpenAI agents ‘infiltrated Australian government website’
Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
Academic publisher Elsevier hit by LAPSUS$ redirect attack
Closing the observability gap for the AI-ready enterprise
VentureBeat
Monorepos make coding agents more useful — but compromised accounts are harder to contain
AI coding tools are accelerating dependency sprawl and expanding malware risk with it
AI has created a new identity problem. Agentic IAM is how we solve it.
Meta patched Muse’s zero-day, but security teams still lack visibility into what the agent can access
Companies are putting Jev in charge of AI agent decisions — and prompt injection can influence the verdict
OpenAI hacked by small team of white hat security researchers using Anthropic's Claude Opus 5
Cohere's Model Vault now encrypts AI inference so even Cohere cannot see enterprise customers' data
TechCrunch
Australia to investigate if OpenAI hack of government health website broke the law
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
LinkedIn adds new tools to fight fake profiles and bogus work histories
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Stolen passwords are exposing America’s water providers to hackers
Google’s Gemini is the latest AI model to hack other companies
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Researchers used Anthropic’s Claude to hack into OpenAI
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Google says some Pixel phone owners were hacked in zero-day attacks
Network World Security
IP Fabric 8.1 adds application-aware mapping and cloud-native data model
On-prem VeloCloud Orchestrator under attack, only some versions patched
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Selector brings Git-based workflows and incident replay to network AI agents
80% of network pros are OK with giving AI an autonomous role in network operations
Inside Buffalo’s Highmark Stadium: How the Bills and Cisco built one network to run an entire venue, and what IT leaders can learn from it
9 career-boosting Wi-Fi certifications
Lenovo expands virtualization portfolio for AI
2026 network outage report and internet health check
California joins US states clamping down on data center gold rush
Help Net Security
Symphony Risk Intelligence uses AI agents to streamline financial crime investigations
OpenAI agent hacking spree widens to Australia, targeting government website
Cloud Range lets SOCs benchmark AI agents against human defenders
Gurucul connects AI activity to identity data for faster threat response
Airties adds router-level cybersecurity protection for ISPs
Azul AI Assistant helps teams find Java licensing and security risks
LatticeFlow AI offers managed risk assessments for enterprise AI systems
Meta locks itself out of user data on its AI glasses
UK gears up for fight against Russia’s disinformation machine
New Android malware RemControl steals banking PINs and blocks removal attempts
SC Magazine
LinkedIn introduces new tools to combat AI-generated fake identities
Critical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISA
Cyber recovery plans lag behind AI, ransomware threats
Burger King Russia customer data leaked online after 2024 breach
LLM privacy policies are difficult to read, study finds
Elsevier platform briefly redirected to LAPSUS$ leak site
Malicious npm package targets Twilio developers with data-harvesting attempts
New TrustSink attack steals passwords via rogue MFA provider
Pass-the-ticket attack: How the attack works and how to stop it
Pass-the-hash attack: How the attack works and how to stop it
© 2026 RiskDiscovery | Sponsored by:
Deception Logic